HACKERS BOOST MINDEF CYBER DEFENCES

21feb18_news-1 https://www.defencepioneer.sg/images/default-source/_migrated_english/21feb18_news-1.jpg?sfvrsn=5090e0f9_2 https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
https://www.defencepioneer.sg/pioneer-articles/HACKERS-BOOST-MINDEF-CYBER-DEFENCES
HACKERS BOOST MINDEF CYBER DEFENCES
21 Feb 2018 | TECHNOLOGY

HACKERS BOOST MINDEF CYBER DEFENCES

// STORY Thrina Tham
// PHOTOS Tan Yong Quan

A total of 35 vulnerabilities, or bugs, were uncovered across eight of its major Internet-facing systems, with a total bounty payout of US$14,750 (S$19,500).

"Hackers are very innovative, so MINDEF has to be equally innovative in defending our systems. That's why we ran the Bug Bounty Programme," said Defence Cyber Chief David Koh, who announced programme's results on 21 Feb.

"The programme has met our intended objectives and allowed MINDEF to find previously unidentified vulnerabilities quickly and effectively, and consequently strengthen our defence systems," he added.

The three-week programme saw 264 white hat hackers invited to look for security flaws in MINDEF's systems including the MINDEF, Central Manpower Base, and Defence Science and Technology Agency websites, as well as NS Portal.

These ethical hackers are from around the world, hailing from countries such as India, Romania, Russia, Sweden and the United States. They also included 100 hackers from the local white hat community in Singapore.

Held from 15 Jan to 4 Feb, the programme saw the first vulnerability report submitted 83 minutes after its launch. At the end of the three-week hackathon, a total of 34 participants had reported 97 vulnerabilities, of which 35 were valid.

The initiative is a first for a government agency in Asia, according to HackerOne, the international bug bounty company engaged to run the programme. In a statement, HackerOne said that MINDEF responded quickly to the vulnerability reports, responding within five hours on average. The company has run similar programmes for the US Department of Defence, as well as tech giants Google and Twitter.

Explaining the process, Mr Koh said that each reported bug has to meet certain criteria before it is further verified by MINDEF.

"(Each time a vulnerability is found), we fix the vulnerability immediately (to) mitigate the risk as quickly as possible," he said.

Of all the validated bugs reported, no critical vulnerabilities were found. Two were of high severity, 10 were medium and 23 were low.

The biggest bounty of US$2,000 went to local white hat hacker Mr Darrel for uncovering one of the high-severity bugs.

The cyber security manager at consultancy firm Ernst & Young said that participating in the programme helped him sharpen his skills.

Going by the moniker Shivadagger, he said: "For this programme, you're expected to have a foolproof report they want to know that you can actually go in and exploit (the vulnerability)."

Mr Darrel reported 14 vulnerabilities, of which nine were deemed valid - earning him a total bounty of US$5,000.

The Bug Bounty Programme is part of MINDEF's continuous efforts to build up its capabilities in the cyber arena, which includes the setting up of the Cyber Test and Evaluation Centre (CyTEC) where servicemen train against simulated cyber attacks.

Suggested Reading
INSPIRED TO LEAD, COMMITTED TO SERVE
PEOPLE
13 Sep 2025

Teamwork, discipline and resilience: These values were instilled in 2LT Nithira and 2LT Dylan Loo in sport and at school, and continue to guide them as newly minted SAF officers.

Cover story
EX FORGING SABRE RAMPS UP USE OF UNMANNED ASSETS IN INTEGRATED STRIKE OPERATIONS
OPS & TRAINING
12 Sep 2025

In this 10th edition of Exercise Forging Sabre, the SAF sharpened its cutting edge for the dynamic modern battlefield, with expanded integration between manned and unmanned platforms.

Feature
CHIEF, SAILOR, BROTHER
PEOPLE
03 Sep 2025

If the heart of a ship is its engine, then ME3 Malcolm Tan is the man who keeps its pulse healthy: he makes sure both vessel and crew are in top shape.

BACK FROM GAZA AID AIRDROP MISSION
OPS & TRAINING
02 Sep 2025

On 25 Aug, the Republic of Singapore Air Force (RSAF) C-130 transport aircraft returned to Singapore after completing the Singapore Armed Forces’ (SAF’s) delivery of the ninth tranche of humanitarian aid to Gaza. This was also the second airdrop operation to send aid to the region.

Feature
MENTOR & ROLE MODEL
PEOPLE
01 Sep 2025

Seeing his trainees become stronger and more confident brings him joy in his work. Meet Air Warfare School instructor CPT Louis Lee.

Feature
SHAPING UP SOLDIERS
PEOPLE
29 Aug 2025

Guardsman 3WO Muhammad Aliff is passionate about making an impact on the growth and development of the soldiers under his charge.

Cover story
TRAINING WITH PURPOSE
PEOPLE
27 Aug 2025

MSG Nathanial Ng displays a quiet steely dedication towards imparting the right knowledge and skills to new Army Deployment Force (ADF) operators.

Cover story
OPERATING OVER SKIES & SEAS
TECHNOLOGY
22 Aug 2025

This gear is designed to help a Sensor Supervisor survive emergencies in the air and at sea.

BECOMING SPECIALIST LEADERS
PEOPLE
21 Aug 2025

3SG Defred Lau and 3SG Danish celebrate a milestone in their NS journeys as they earn their specialist ranks.

Cover story
Geared up against chemical threats
TECHNOLOGY
18 Aug 2025

How do our soldiers keep safe when rescuing casualties of chemical or biological weapons?