Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

101–110 of 164 posts

Re: $36k Google App Engine RCE

#101

Google should send this guy a request to be hired. Clearly he's as good as their internal engineering team and his write up was great.

As has been discussed to death here, Google’s hiring process doesn’t care what you did last week, or last year (eg Max Howell).

This would not improve his odds.

Re: $36k Google App Engine RCE

#102
post #46

It would be no skin of Google’s back to multiply these bug bounties by 10, and they should.

But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.

> That's a great way to never be able to hire him.

Why's that? It's not retirement money. 400k (salary+stock) is one year of compensation for some Google engineers.

Re: $36k Google App Engine RCE

#103
post #78
post #75

Earlier quoted context omitted.

I understand. I did in fact believe that this applies to any highest reward RCE vulnerability, thanks for pointing out that this may not be the case. As for the black market price - I don't consider my security background sufficient for my guess to be anywhere near educated enough, so I'm bowing out.

No problem. You've been a good sport, thanks! (I'm still interested in seeing someone take a crack at this.)

Hah. As soon as I saw your initial setup I knew it was Wargames. The only winning move is not to play. I think you are right. When you add in all of the conditions required to sell a bug like this it becomes obvious (to me) that Google is offering more than you can get anywhere else without a lot of effort and or risk on the sellers part.

And not to spoil the game, but the subset of vulns that fetch good money has only narrowed in the last years as exploit mitigation has improved. The true unicorn 0days of yesteryear are almost always multiple hard earned bugs these days. Bugs in one vendor's project, even Google, it is cool they have such a high end reward, let alone 36k. Unless you crossed a line and exfiltrated data (high risk), I can't imagine getting this much money anywhere else.

Amusingly, 36k does look very similar to ~3wks of boutique infosec consulting, though, so for Google the price while generous probably makes sense.

Re: $36k Google App Engine RCE

#104

Google should send this guy a request to be hired. Clearly he's as good as their internal engineering team and his write up was great.

As has been discussed to death here, Google’s hiring process doesn’t care what you did last week, or last year (eg Max Howell). This would not improve his odds.

Anecdotal, but I got my job at Google through participating in their bug bounty program. The first set of interviews you have that ask general CS questions might not care what you did last week or last year, but when you talk with the team who wants to hire you they certainly do care.

Re: $36k Google App Engine RCE

#105
post #102

Earlier quoted context omitted.

But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.

> That's a great way to never be able to hire him. Why's that? It's not retirement money. 400k (salary+stock) is one year of compensation for some Google engineers.

Dude has cashed out a $10k and $30k bug bounty at the age of 18. Either he's lucky or he's very good. If he's the latter that $400k turns into an annual bounty.

And very, very few Google engineers make that kind of money.

Re: $36k Google App Engine RCE

#106
post #24

Earlier quoted context omitted.

As someone who worked in a bug bounty program, the skill and age of this individual isn't what sets them apart. It's the write up.

As someone who has been on the other end of receiving incoherent and inaccurate bug bounty reports, this! To find the bug is impressive. To write about it so well is truly exceptional.

I always "joke" to people we are professional writers. Actually professional infosec consultants, but our life blood is coherently documenting everything we find and making pretty executive summaries. It is hard to overstate how much I have seen the reporting differentiate infosec consulting firms over then years. Which is not to say we don't value the hard technical skills, but writing is really, really important too.

Re: $36k Google App Engine RCE

#107

Earlier quoted context omitted.

But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.

I suspect the bug bounties are much more about deterring the sale of exploits to bad actors than about recruiting employees.

It's both. You could do the former by throwing huge sums of money at the problem.

Re: $36k Google App Engine RCE

#108

Earlier quoted context omitted.

* Grab nearly all of googles source code (no extra auth required for that, since so many libraries read config etc from the source code repo) * Make the right requests to one endpoint he found and retrieve company financials, number of hits to every google service, the name of every application running in every datacenter, etc. * With the above two things, you know the location of services and every RPC endpoint on t…

Wow, that is quite significant. 36k is not a small bounty for an RCE, but I feel like this is more critical to Google than the highest Android payout, for which they pay up to 200k for: https://www.google.com/about/appsecurity/android-rewards/

Android is probably one of those markets that are more liquid than most for "black market" sources (as talked about elsewhere in the comments for this)
Post reply on HN