Earlier quoted context omitted.
Sounds like the conclusion is that the bounty programs needs to work closer together with the product teams if it wants to be more effective. Phrased differently, internal organizational challenges should never be a valid reason why a bug is disqualified. It’s completely irrelevant from an outsider’s perspective.
I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. The challenge, however, is constructing a sustainable model to incentivize product teams to reciprocate this closer working relationship. I would say all but the smallest of companies running bug bounties also have an internal security function that is already doing reporting on vulnerabilities, time…
Google launches new vulnerability reward platform
61–70 of 109 posts
Re: Google launches new vulnerability reward platform
#62Earlier quoted context omitted.
I downvoted because "cybersec researchers" do not in fact routinely make 7 figures. For strong pentester types reporting the typical (real) vulnerability the VRP handles, the median is probably in the low 6's.
6 figures from breaking systems and reporting them responsibly? Sounds amazing, what's the catch?
Re: Google launches new vulnerability reward platform
#63> Total bugs rewarded: 11,055
> Number of rewarded researchers: 2,022
So each person found an average of 5.5 bugs? That seems really high, no?
Re: Google launches new vulnerability reward platform
#64I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…
*Not a Google employee but have worked for a bug bounty* I agree everything you've stated would be desirable, and if there was a strong culture and policy of supporting bounty programs from the CEO on down, this could potentially be achievable. However: dupes - On the bounty side dupes are extremely common and buddies telling buddies about their finds is going to drive fraud up quite a bit. In my triage work I saw ve…
wouldn't looking at the logs of when the reports were taken pretty much clearly show the first person to make the report? how is this a thing that gets confused to be an issue?
Re: Google launches new vulnerability reward platform
#65Earlier quoted context omitted.
I think there are two separate issues, though: * properly qualifying a bug bounty submission * actually fixing the thing From what I understood from your original comment, was that sometimes things get qualified as “wontfix” because of internal struggles. I understand that these struggles exist, as with any large org with conflicting priorities, especially when the issues are not 0day severity. I think, however, from…
Your points are totally valid and I agree with them in principle, I just see them as existing on a spectrum. One pretty interesting example is GitLab's bounty program because you can see both sides, both the reported issues and how they are tracked on the engineering side: https://hackerone.com/gitlab/hacktivity?type=team https://gitlab.com/gitlab-org/gitlab/-/issues?label_name=Hac... There's very good organizational…
Thanks a lot for your insights, they were very valuable.
Re: Google launches new vulnerability reward platform
#66Whoa, this kind of impressed me (linked from the blog post) https://bughunters.google.com/about/patch-rewards Payouts for security-positive improvements to security-critical OSS projects: * $20,000 for setting up continuous fuzzing with OSS-Fuzz * $10,000 for high-impact improvements that prevent major classes of vulnerabilities but the low end of the scale is kind of neat too: * "$1,337 for submissions of modest com…
> (Googler here, but I don't work on the VRP.)
The URL that you posted doesn't render correctly on Firefox 90 for Linux.
Re: Google launches new vulnerability reward platform
#67> To recap our progress on these goals, here is a snapshot of what VRP has accomplished with the community over the past 10 years: > Total bugs rewarded: 11,055 > Number of rewarded researchers: 2,022 So each person found an average of 5.5 bugs? That seems really high, no?
Re: Google launches new vulnerability reward platform
#68Re: Google launches new vulnerability reward platform
#69I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…
> I would like to see private issues shared with reporters when they are independently discovered. Other people have covered most of the rest of your comment, but there are things to say about this one specifically. The reporting platforms support it. It's a very frequent request from researchers who file duplicate reports. It's rare for a company to do this, because (1) it doesn't do anything to help with the issue…
Re: Google launches new vulnerability reward platform
#70Earlier quoted context omitted.
>If you've never worked triage on a bounty before, my guess is that you can't really imagine how terrible the median interaction is. I deleted three sentences about this very topic in my earlier comment because it turned into an ugly rant, lol. >Maybe the next evolution of these programs will be long-term contract relationships with trusted, successful vuln hunters I'm actually somewhat surprised that bounty programs…
For what it's worth, I think the argument that bounty participants are gig workers is pretty silly.
The refusal to pay while fixing the bug in 48 hours shows a power inbalance. I fear this is where we are headed in the future as AI pumps out most code all of the remaining work comes in the form of contests where thousands spends 80 hours a week and the company (in the best case) will award one person with a cash prize small enough to not hit minimum wage.