Live data from Hacker News

Google launches new vulnerability reward platform

security.googleblog.com

71–80 of 109 posts

Re: Google launches new vulnerability reward platform

#71
post #34

Earlier quoted context omitted.

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.

Why would they care. They have gotten your best work for free and can safely cast you aside because another sucker will take your place.

Re: Google launches new vulnerability reward platform

#72

Earlier quoted context omitted.

> I would like to see private issues shared with reporters when they are independently discovered. Other people have covered most of the rest of your comment, but there are things to say about this one specifically. The reporting platforms support it. It's a very frequent request from researchers who file duplicate reports. It's rare for a company to do this, because (1) it doesn't do anything to help with the issue…

Couldn't companies just publish a list of hashes of existing but not yet public disclosures? Seems as if that could solve the issue of doubt wrt timing.

How would that work? I publish some 256-bit values. You file a report. I mark you duplicate and tell you a random 256-bit value. What did you learn?

The number of reports that eventually become fully public is nearly zero. Most don't become public at all, but of those that do, a lot of content is generally redacted.

Re: Google launches new vulnerability reward platform

#73
post #62
post #58

Earlier quoted context omitted.

6 figures from breaking systems and reporting them responsibly? Sounds amazing, what's the catch?

There's no catch. You want a job as a pentester. That job is in high demand.

Frankly low 6 figures sounds low for a software job. How do you attract talent at that level?

Re: Google launches new vulnerability reward platform

#74
post #70
post #42

Earlier quoted context omitted.

For what it's worth, I think the argument that bounty participants are gig workers is pretty silly.

They are gig workers. Security gets outsourced to these workers where normally the company would need to pay a salary. The refusal to pay while fixing the bug in 48 hours shows a power inbalance. I fear this is where we are headed in the future as AI pumps out most code all of the remaining work comes in the form of contests where thousands spends 80 hours a week and the company (in the best case) will award one pers…

Google does not use bug bounties instead of paying people salaries to do software security. Google pays more people to do software security than does any company on the planet. They do bug bounties because you get different bugs from them than you would from any employee. If bounty hunters are benefits-eligible employees, then there are virtually no services a company can buy from anybody that don't qualify similarly; read IRS P15-A; there are basically no IRS classification tests that bug bounties hit.

Here's the "20 factor test" (condensed from Oregon's condensed version) the IRS uses for employee classification:

* Does the company direct where, when, and how the work is done? (You can hunt for bugs from any country in the world, whenever you want, using whichever tools you like.)

* Does the company require company-provided training to provide the service? (The first contact Google has from a bounty hunter can be the bug they submit, and Google will pay).

* Is the service directly integrated into the business the company provides? (No: Google doesn't provide bug bounty services to other companies, and is not in fact a bug bounty with a small search engine attached.)

* Does the company insist on a particular named person to do the work? (No; in fact, until they're actually paid, many bounty hunters are psueodonymous.)

* Does the company control who the provider hires to assist in the work? (Nope, you can hire your own team of people to assist with your bountying, and Google does not care.)

* Does the company maintain a continuous relationship with the service provider? (Nope, you can submit a bug in June and then come back next April with another one, or come back never).

* Does the company determine the schedule on which the work is done, or is the schedule flexible? (Google does not even slightly care what schedule you find bugs on, or even the timeline you use to report bugs on once you find them.)

* Does the company demand full-time hours? (Google doesn't set any hours for bounty hunters whatsoever.)

* Does the company demand that the service be provided on-site? (Bounty hunters work exclusively from their own facilities.)

* Does the company demand that the work be performed in a specific order or sequence? (No, you can look for any combination of bugs in any set of services using whichever set of tests you want to use, be they fuzzing or mitmproxying or scanning, in any order you like.)

* Does the company require regular periodic written or oral reports? (Indeed they do not.)

* Does the company pay hourly, weekly, or monthly, rather than by the project? (Bounties are paid by the bug.)

* Does the company defray expenses for the work? (Nope.)

* Does the company provide the tools and materials needed for the work? (Nope, bounty hunters BYO laptops and Burp Suites.)

* Does the company provide facilities, office space, etc for the work? (Google doesn't provide even so much as a Slack account for bug hunters.)

* Are the earnings from the work predetermined, or can the workers realize greater or lesser profits from the amount of work they put on? (Regardless of the hours committed to bug-hunting, bug hunters earn revenue based on the value of the assets they generate; if you come up with a technique to find dozens of XSS vulnerabilities in a couple hours, you'll make a zillion dollars per hour.)

* Is the relationship exclusive? (Of course not, bounty hunters work with multiple companies as a rule.)

* Can the worker make similar services available to the public? (Not only can they, but independent consulting is the norm for this kind of work.)

* (This is 2 bullets, condensed) Can either party terminate the relationship independently? (Yep.)

Bug bounty participants are not, as a general rule, classifiable as employees. People make noise about it because there's drama about Uber --- where the company exerts substantial control over how employees do the work, when and where they do it, where they check in with their cars, &c, and do so while providing the core service the company offers. Someone on a message board is going to try to suggest that Google is in fact a bug bounty program with a small search engine attached to it, but I mean, come on.

Re: Google launches new vulnerability reward platform

#75
post #62

Earlier quoted context omitted.

There's no catch. You want a job as a pentester. That job is in high demand.

Frankly low 6 figures sounds low for a software job. How do you attract talent at that level?

The median bounty hunter isn't an SFBA software developer.

Re: Google launches new vulnerability reward platform

#76

> To recap our progress on these goals, here is a snapshot of what VRP has accomplished with the community over the past 10 years: > Total bugs rewarded: 11,055 > Number of rewarded researchers: 2,022 So each person found an average of 5.5 bugs? That seems really high, no?

The distribution probably has a relatively small amount of people reporting a disproportionately large amount of the bugs.

This is very true. It's been a reality for a long time that the most successful (measured in $x rewarded) bug hunters sometimes have hundreds or even thousands of bugs submitted per year.

This way, they can capitalise on the fact that smaller security issues are much easier to find, especially if the bug hunter has expertise in the underlying framework.

Re: Google launches new vulnerability reward platform

#77
post #38

Earlier quoted context omitted.

Sounds like the conclusion is that the bounty programs needs to work closer together with the product teams if it wants to be more effective. Phrased differently, internal organizational challenges should never be a valid reason why a bug is disqualified. It’s completely irrelevant from an outsider’s perspective.

I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. The challenge, however, is constructing a sustainable model to incentivize product teams to reciprocate this closer working relationship. I would say all but the smallest of companies running bug bounties also have an internal security function that is already doing reporting on vulnerabilities, time…

> I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree.

Completely off-topic comment follows, but I find lingustics interesting, am a native (Br) English speaker, and think it's worthwhile to reassure someone they're foreign language skills are fine.

Yes, it's good. (It's extremely valid :wink:). It has a slightly comical flair to it - not sarcastic, just certainly not formal. You could push it further to 'I extremely agree', which is more debatable but as long as they realised you were 'being ironic' nobody would say 'hey that's extremely invalid English' or anything.

Only one thing wrong: characterise (oxendict be damned!) and incentivise are spelt (not spelled) with an 's'. :British-trollface:

Re: Google launches new vulnerability reward platform

#78
post #75

Earlier quoted context omitted.

Frankly low 6 figures sounds low for a software job. How do you attract talent at that level?

The median bounty hunter isn't an SFBA software developer.

Is it international arbitrage? Or something else cause low 6 figures is now the going rate all over the states.

*not trying to be argumentative just trying to price the market.

Re: Google launches new vulnerability reward platform

#79
post #75

Earlier quoted context omitted.

The median bounty hunter isn't an SFBA software developer.

Is it international arbitrage? Or something else cause low 6 figures is now the going rate all over the states. *not trying to be argumentative just trying to price the market.

It's a combination of the lower value of the median bug bounty submission (we hear about the high-ticket vulnerabilities, but most of them are pretty low-test) and the fact that huge numbers of bounty participants are abroad. I know there are people who claim to make high-6's and even low-7's from bounties, but they're very rare. I think most people who participate in bounties would be best off financially by using them to build a portfolio they can exploit to pivot into consulting or full-time work of some other sort.

Re: Google launches new vulnerability reward platform

#80

I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…

So much this. It’s insanely annoying when they say something isn’t a risk and then they fix it shortly after. Google should improve this problem over new webpages.
Post reply on HN