Earlier quoted context omitted.
It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…
> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.
Google launches new vulnerability reward platform
71–80 of 109 posts
Re: Google launches new vulnerability reward platform
#72Earlier quoted context omitted.
> I would like to see private issues shared with reporters when they are independently discovered. Other people have covered most of the rest of your comment, but there are things to say about this one specifically. The reporting platforms support it. It's a very frequent request from researchers who file duplicate reports. It's rare for a company to do this, because (1) it doesn't do anything to help with the issue…
Couldn't companies just publish a list of hashes of existing but not yet public disclosures? Seems as if that could solve the issue of doubt wrt timing.
The number of reports that eventually become fully public is nearly zero. Most don't become public at all, but of those that do, a lot of content is generally redacted.
Re: Google launches new vulnerability reward platform
#73Earlier quoted context omitted.
6 figures from breaking systems and reporting them responsibly? Sounds amazing, what's the catch?
There's no catch. You want a job as a pentester. That job is in high demand.
Re: Google launches new vulnerability reward platform
#74Earlier quoted context omitted.
For what it's worth, I think the argument that bounty participants are gig workers is pretty silly.
They are gig workers. Security gets outsourced to these workers where normally the company would need to pay a salary. The refusal to pay while fixing the bug in 48 hours shows a power inbalance. I fear this is where we are headed in the future as AI pumps out most code all of the remaining work comes in the form of contests where thousands spends 80 hours a week and the company (in the best case) will award one pers…
Here's the "20 factor test" (condensed from Oregon's condensed version) the IRS uses for employee classification:
* Does the company direct where, when, and how the work is done? (You can hunt for bugs from any country in the world, whenever you want, using whichever tools you like.)
* Does the company require company-provided training to provide the service? (The first contact Google has from a bounty hunter can be the bug they submit, and Google will pay).
* Is the service directly integrated into the business the company provides? (No: Google doesn't provide bug bounty services to other companies, and is not in fact a bug bounty with a small search engine attached.)
* Does the company insist on a particular named person to do the work? (No; in fact, until they're actually paid, many bounty hunters are psueodonymous.)
* Does the company control who the provider hires to assist in the work? (Nope, you can hire your own team of people to assist with your bountying, and Google does not care.)
* Does the company maintain a continuous relationship with the service provider? (Nope, you can submit a bug in June and then come back next April with another one, or come back never).
* Does the company determine the schedule on which the work is done, or is the schedule flexible? (Google does not even slightly care what schedule you find bugs on, or even the timeline you use to report bugs on once you find them.)
* Does the company demand full-time hours? (Google doesn't set any hours for bounty hunters whatsoever.)
* Does the company demand that the service be provided on-site? (Bounty hunters work exclusively from their own facilities.)
* Does the company demand that the work be performed in a specific order or sequence? (No, you can look for any combination of bugs in any set of services using whichever set of tests you want to use, be they fuzzing or mitmproxying or scanning, in any order you like.)
* Does the company require regular periodic written or oral reports? (Indeed they do not.)
* Does the company pay hourly, weekly, or monthly, rather than by the project? (Bounties are paid by the bug.)
* Does the company defray expenses for the work? (Nope.)
* Does the company provide the tools and materials needed for the work? (Nope, bounty hunters BYO laptops and Burp Suites.)
* Does the company provide facilities, office space, etc for the work? (Google doesn't provide even so much as a Slack account for bug hunters.)
* Are the earnings from the work predetermined, or can the workers realize greater or lesser profits from the amount of work they put on? (Regardless of the hours committed to bug-hunting, bug hunters earn revenue based on the value of the assets they generate; if you come up with a technique to find dozens of XSS vulnerabilities in a couple hours, you'll make a zillion dollars per hour.)
* Is the relationship exclusive? (Of course not, bounty hunters work with multiple companies as a rule.)
* Can the worker make similar services available to the public? (Not only can they, but independent consulting is the norm for this kind of work.)
* (This is 2 bullets, condensed) Can either party terminate the relationship independently? (Yep.)
Bug bounty participants are not, as a general rule, classifiable as employees. People make noise about it because there's drama about Uber --- where the company exerts substantial control over how employees do the work, when and where they do it, where they check in with their cars, &c, and do so while providing the core service the company offers. Someone on a message board is going to try to suggest that Google is in fact a bug bounty program with a small search engine attached to it, but I mean, come on.
Re: Google launches new vulnerability reward platform
#75Re: Google launches new vulnerability reward platform
#76> To recap our progress on these goals, here is a snapshot of what VRP has accomplished with the community over the past 10 years: > Total bugs rewarded: 11,055 > Number of rewarded researchers: 2,022 So each person found an average of 5.5 bugs? That seems really high, no?
The distribution probably has a relatively small amount of people reporting a disproportionately large amount of the bugs.
This way, they can capitalise on the fact that smaller security issues are much easier to find, especially if the bug hunter has expertise in the underlying framework.
Re: Google launches new vulnerability reward platform
#77Earlier quoted context omitted.
Sounds like the conclusion is that the bounty programs needs to work closer together with the product teams if it wants to be more effective. Phrased differently, internal organizational challenges should never be a valid reason why a bug is disqualified. It’s completely irrelevant from an outsider’s perspective.
I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. The challenge, however, is constructing a sustainable model to incentivize product teams to reciprocate this closer working relationship. I would say all but the smallest of companies running bug bounties also have an internal security function that is already doing reporting on vulnerabilities, time…
Completely off-topic comment follows, but I find lingustics interesting, am a native (Br) English speaker, and think it's worthwhile to reassure someone they're foreign language skills are fine.
Yes, it's good. (It's extremely valid :wink:). It has a slightly comical flair to it - not sarcastic, just certainly not formal. You could push it further to 'I extremely agree', which is more debatable but as long as they realised you were 'being ironic' nobody would say 'hey that's extremely invalid English' or anything.
Only one thing wrong: characterise (oxendict be damned!) and incentivise are spelt (not spelled) with an 's'. :British-trollface:
Re: Google launches new vulnerability reward platform
#78Earlier quoted context omitted.
Frankly low 6 figures sounds low for a software job. How do you attract talent at that level?
The median bounty hunter isn't an SFBA software developer.
*not trying to be argumentative just trying to price the market.
Re: Google launches new vulnerability reward platform
#79Earlier quoted context omitted.
The median bounty hunter isn't an SFBA software developer.
Is it international arbitrage? Or something else cause low 6 figures is now the going rate all over the states. *not trying to be argumentative just trying to price the market.
Re: Google launches new vulnerability reward platform
#80I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…