The Digital and Population Data Services Agency's bug bounty program expands to Suomi.fi Messages

‘At worst, the vulnerabilities of digital services lead to a successful data breach.It is very useful to carry out long-term communal testing, such as the bug bounty program, on services that are open to the Internet,’ says Pekka Ristimäki, Head of Information Security at the Digital and Population Data Services Agency.
Hacking during the program does not compromise the security of the systems. On the contrary, a large group of testers enables more extensive testing and efficient identification of potential vulnerabilities.
How does hacker collaboration work?
Professional and amateur hackers are invited to participate in the bug bounty program to carry out information security research on the services targeted by the program. The programs are communal vulnerability security tests in which external testers, i.e. hackers, are given the opportunity to test organisations’ digital services within the agreed principles and limitations.
‘We have engaged in similar cooperation with hackers in the past, and the experiences have been good. The bug bounty program complements our standard application testing. At the same time, talented hackers are given the opportunity to test their skills with permission and make some money on the side,’ says Pekka Ristimäki.
Hackers register for testing and commit to following the established rules. If vulnerabilities are found, the person who finds them will be paid a fee in proportion to the significance of the finding. The fees range between €100 and €30,000.
The bug bounty program is produced by Hackrfi Oy, a company specialising in the management of communal vulnerability coordination and information security testing. The Digital and Population Data Services Agency's bug bounty program takes place from 31 October 2022 to 30 April 2023. Participants will be invited on the basis of an application.
Read more about the Digital and Population Data Services Agency's bug bounty program and apply to it on the website of Hackrfi Oy: https://www.hackr.fi/ohjelmat/DVV-BB.html
On 31 October 2022, the Digital and Population Data Services Agency launched the bug bounty program, which looks for possible information security vulnerabilities in Suomi.fi services. The program tests the Suomi.fi Web Service as well as the Suomi.fi e-Identification, Suomi.fi e-Authorizations and Suomi.fi Messages interface.
Suomi.fi is an online service that collects public services and guidelines for people at different stages of their lives. You can also use Suomi.fi to check your own data in the registers of different authorities, receive official mail electronically and grant and request rights to act on behalf of another person or company. Suomi.fi is developed by the Digital and Population Data Services Agency.
Keywords
Contacts
Digital and Population Data Services Agency, Head of Information Security Pekka Ristimäki, tel. +358 295 535 048, firstname.lastname[at]dvv.fi
Images
About Digi- ja väestötietovirasto
Digital and Population Data Services Agency (The Finnish Digital Agency)
Digital and Population Data Services Agency (The Finnish Digital Agency) promotes the digitalisation of society, secures the availability of information and provides services related to customers’ life events.
The Digital and Population Data Services Agency (The Finnish Digital Agency) sees to the maintenance of the Population Information System, which is the foundation for our society, and to the digitalisation of society. The agency’s tasks include civil marriages, name and address changes, guardianship and administrative guardianship, maintenance of the Population Information System, development of solutions for electronic identification, as well as the development and maintenance of centralised support services for e-services. E-service support services include the Suomi.fi Web Service, electronic messages from authorities (Suomi.fi Messages) as well as authorisation for acting on behalf of another party (Suomi.fi e-Authorization).
Subscribe to releases from Digi- ja väestötietovirasto
Subscribe to all the latest releases from Digi- ja väestötietovirasto by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Digi- ja väestötietovirasto
Reform of the Digital and Population Data Services Agency's service location in Lahti will be postponed5.6.2023 06:00:00 EEST | Press release
In Lahti, the Digital and Population Data Services Agency is moving to new customer service facilities, in the same property.
Förnyelsen av Myndigheten för digitalisering och befolkningsdatas serviceställe i Lahtis flyttas5.6.2023 06:00:00 EEST | Tiedote
Myndigheten för digitalisering och befolkningsdata håller på att flytta till nya kundservicelokaler i samma fastighet i Lahtis.
Digi- ja väestötietoviraston Lahden palvelupaikan uudistus siirtyy5.6.2023 06:00:00 EEST | Tiedote
Digi- ja väestötietovirasto on siirtymässä Lahdessa uusiin asiakaspalvelutiloihin samassa kiinteistössä.
Digital and Population Data Services Agency’s service locations in Lahti and Lappeenranta are being reformed – exceptions to opening hours in June25.5.2023 15:15:00 EEST | Press release
The Digital and Population Data Services Agency’s service locations in Lahti and Lappeenranta will be reformed into joint service points in June 2023. The operations will continue in the same facilities as before, but several government agencies will serve in the same customer service facilities in the future.
Myndigheten för digitalisering och befolkningsdatas serviceställen i Lahtis och Villmanstrand förnyas – avvikelser i öppettiderna i juni25.5.2023 15:15:00 EEST | Tiedote
Myndigheten för digitalisering och befolkningsdatas verksamhetsställen i Lahtis och Villmanstrand förnyas i juni 2023 till statens gemensamma serviceställen. Verksamheten fortsätter i samma fastighet som tidigare, men i fortsättningen betjänar flera statliga ämbetsverk i samma kundservicelokaler.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom