Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

161–164 of 164 posts

Re: $36k Google App Engine RCE

#161
post #104

Earlier quoted context omitted.

As has been discussed to death here, Google’s hiring process doesn’t care what you did last week, or last year (eg Max Howell). This would not improve his odds.

Anecdotal, but I got my job at Google through participating in their bug bounty program. The first set of interviews you have that ask general CS questions might not care what you did last week or last year, but when you talk with the team who wants to hire you they certainly do care.

That's the thing, he might get rejected from the screening questions...

Re: $36k Google App Engine RCE

#162
post #45

Earlier quoted context omitted.

I’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.

His bounty is equivalent to a year's salary for a very good senior developer in here. So I believe his point stands.

There's been a bit of salary inflation here, but yes, it's a very good payout and probably a year's salary for a mid-level developer (I'm a developer in Uruguay).

He'll have to pay taxes on it though (if he has no other income it won't be that bad, maybe 20%).

Re: $36k Google App Engine RCE

#163
post #50

Earlier quoted context omitted.

You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/

First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'…

Any third parties reading this should take anything tptacek says with a grain of salt -- he's a well-known security contractor and his business model specifically consists of convincing his clients that they can't protect themselves by offering bug bounties.
Post reply on HN