Google should send this guy a request to be hired. Clearly he's as good as their internal engineering team and his write up was great.
This would not improve his odds.
101–110 of 164 posts
Google should send this guy a request to be hired. Clearly he's as good as their internal engineering team and his write up was great.
This would not improve his odds.
It would be no skin of Google’s back to multiply these bug bounties by 10, and they should.
But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.
Why's that? It's not retirement money. 400k (salary+stock) is one year of compensation for some Google engineers.
Earlier quoted context omitted.
I understand. I did in fact believe that this applies to any highest reward RCE vulnerability, thanks for pointing out that this may not be the case. As for the black market price - I don't consider my security background sufficient for my guess to be anywhere near educated enough, so I'm bowing out.
No problem. You've been a good sport, thanks! (I'm still interested in seeing someone take a crack at this.)
And not to spoil the game, but the subset of vulns that fetch good money has only narrowed in the last years as exploit mitigation has improved. The true unicorn 0days of yesteryear are almost always multiple hard earned bugs these days. Bugs in one vendor's project, even Google, it is cool they have such a high end reward, let alone 36k. Unless you crossed a line and exfiltrated data (high risk), I can't imagine getting this much money anywhere else.
Amusingly, 36k does look very similar to ~3wks of boutique infosec consulting, though, so for Google the price while generous probably makes sense.
Google should send this guy a request to be hired. Clearly he's as good as their internal engineering team and his write up was great.
As has been discussed to death here, Google’s hiring process doesn’t care what you did last week, or last year (eg Max Howell). This would not improve his odds.
Earlier quoted context omitted.
But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.
> That's a great way to never be able to hire him. Why's that? It's not retirement money. 400k (salary+stock) is one year of compensation for some Google engineers.
And very, very few Google engineers make that kind of money.
Earlier quoted context omitted.
As someone who worked in a bug bounty program, the skill and age of this individual isn't what sets them apart. It's the write up.
As someone who has been on the other end of receiving incoherent and inaccurate bug bounty reports, this! To find the bug is impressive. To write about it so well is truly exceptional.
Earlier quoted context omitted.
But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.
I suspect the bug bounties are much more about deterring the sale of exploits to bad actors than about recruiting employees.
Earlier quoted context omitted.
* Grab nearly all of googles source code (no extra auth required for that, since so many libraries read config etc from the source code repo) * Make the right requests to one endpoint he found and retrieve company financials, number of hits to every google service, the name of every application running in every datacenter, etc. * With the above two things, you know the location of services and every RPC endpoint on t…
Wow, that is quite significant. 36k is not a small bounty for an RCE, but I feel like this is more critical to Google than the highest Android payout, for which they pay up to 200k for: https://www.google.com/about/appsecurity/android-rewards/
Cute base amount, $31337... :)
He was about 2 API calls from being able to grab nearly all of googles source code from Google3 there...