There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP. But they dont do this. I dont know why. Security throug…
Bug bounty prizes are set to encourage a certain quantity of bugs to be reported. If you offer 10x as much, your triage channels will get overwhelmed and you'll have to deal with a bunch of hostile researchers and development teams who hate your guts because you just blocked their next 2 sprints. If a bug bounty program is effective, then the payouts should trend up slowly over time as your security program becomes m…
Google Docs, Search, and Mail do little in 2021 that I need that they didn't do in 2016. There's a lot more churn than bona fide improvement. Most tech just doesn't change that much. Heck, I'd take an online version of WordPerfect 7 from 1996 if it was trustworthy. That's a quarter-century. There's nothing Google Docs does, aside from collaboration, that I need that WP7 didn't do.
On the other hand, I strongly distrust Google to maintain my data securely. As far as I can tell, aside from backwards compatibility/legacy reasons, the major reason people use Office 365, for better or worse, are issues like compliance and security.
Security bugs ought to be sold to Google, found, and fixed. They shouldn't be sold to a ransomware gang or a government.