Live data from Hacker News

Google launches new vulnerability reward platform

security.googleblog.com

41–50 of 109 posts

Re: Google launches new vulnerability reward platform

#41
post #25

There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP. But they dont do this. I dont know why. Security throug…

Bug bounty prizes are set to encourage a certain quantity of bugs to be reported. If you offer 10x as much, your triage channels will get overwhelmed and you'll have to deal with a bunch of hostile researchers and development teams who hate your guts because you just blocked their next 2 sprints. If a bug bounty program is effective, then the payouts should trend up slowly over time as your security program becomes m…

As a customer, I'd be okay with dev teams being blocked for their next 2 sprints if it meant security I can trust.

Google Docs, Search, and Mail do little in 2021 that I need that they didn't do in 2016. There's a lot more churn than bona fide improvement. Most tech just doesn't change that much. Heck, I'd take an online version of WordPerfect 7 from 1996 if it was trustworthy. That's a quarter-century. There's nothing Google Docs does, aside from collaboration, that I need that WP7 didn't do.

On the other hand, I strongly distrust Google to maintain my data securely. As far as I can tell, aside from backwards compatibility/legacy reasons, the major reason people use Office 365, for better or worse, are issues like compliance and security.

Security bugs ought to be sold to Google, found, and fixed. They shouldn't be sold to a ransomware gang or a government.

Re: Google launches new vulnerability reward platform

#42
post #40
post #34

Earlier quoted context omitted.

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

>If you've never worked triage on a bounty before, my guess is that you can't really imagine how terrible the median interaction is. I deleted three sentences about this very topic in my earlier comment because it turned into an ugly rant, lol. >Maybe the next evolution of these programs will be long-term contract relationships with trusted, successful vuln hunters I'm actually somewhat surprised that bounty programs…

For what it's worth, I think the argument that bounty participants are gig workers is pretty silly.

Re: Google launches new vulnerability reward platform

#43
post #24

Earlier quoted context omitted.

They need to mltiply these amounts by 50x. Cybersec researchers make 6-7 figures. 20k is almost nothing.

Not sure why you're downvoted, but the $3M/year total rewards payoff is likely smaller than the corporate administrative and developer time (for review) costs. I.e. if this was a charity it would pay out less than 50 cents on the dollar.

I downvoted because "cybersec researchers" do not in fact routinely make 7 figures. For strong pentester types reporting the typical (real) vulnerability the VRP handles, the median is probably in the low 6's.

Re: Google launches new vulnerability reward platform

#44
post #34

I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

@tptacek -- you're so awesome. I keep meaning to reply on some of these security threads but then I see you've made the relevant points of sanity in a well reasoned manner.

For what it's worth, when I was setting up the culture and values of Google's first bug bounty programs, I hammered "be magnanimous" into the reward committees. i.e. look for reasons to reward more, not less. Find the value in the information provided, even if the person is being a jerk. etc. I don't think this culture has changed. There are teams of people rooting for incoming reports to succeed, and they get excitement and joy from issuing large bounties (because this means Google security is getting stronger).

Re: Google launches new vulnerability reward platform

#45

Is it just me or does the graphic towards the end of the post misspell triage? I dont believe tirage fits at all for that use, but I could be wrong.

it was fixed but here's the one this person was referring to https://web.archive.org/web/20210727142303im_/https://lh4.go...

Re: Google launches new vulnerability reward platform

#47
post #34

I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

> there is essentially zero upside to screwing over bounty hunters.

Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.

Re: Google launches new vulnerability reward platform

#48
post #34

Earlier quoted context omitted.

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.

I'm not saying you shouldn't feel that way. I'm saying Google has no incentive to actually screw you over; that they have in fact the exact opposite incentive.

Re: Google launches new vulnerability reward platform

#49
post #25

There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP. But they dont do this. I dont know why. Security throug…

Third party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome...

You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qualms regarding such acts.

Re: Google launches new vulnerability reward platform

#50
post #42
post #40

Earlier quoted context omitted.

>If you've never worked triage on a bounty before, my guess is that you can't really imagine how terrible the median interaction is. I deleted three sentences about this very topic in my earlier comment because it turned into an ugly rant, lol. >Maybe the next evolution of these programs will be long-term contract relationships with trusted, successful vuln hunters I'm actually somewhat surprised that bounty programs…

For what it's worth, I think the argument that bounty participants are gig workers is pretty silly.

Totally agree FWIW :)
Post reply on HN