Live data from Hacker News

Google launches new vulnerability reward platform

security.googleblog.com

81–90 of 109 posts

Re: Google launches new vulnerability reward platform

#81
post #74
post #70

Earlier quoted context omitted.

They are gig workers. Security gets outsourced to these workers where normally the company would need to pay a salary. The refusal to pay while fixing the bug in 48 hours shows a power inbalance. I fear this is where we are headed in the future as AI pumps out most code all of the remaining work comes in the form of contests where thousands spends 80 hours a week and the company (in the best case) will award one pers…

Google does not use bug bounties instead of paying people salaries to do software security. Google pays more people to do software security than does any company on the planet. They do bug bounties because you get different bugs from them than you would from any employee. If bounty hunters are benefits-eligible employees, then there are virtually no services a company can buy from anybody that don't qualify similarly…

Where's my mic drop ascii thing? Too long anyway.

Re: Google launches new vulnerability reward platform

#82
post #71

Earlier quoted context omitted.

> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.

Why would they care. They have gotten your best work for free and can safely cast you aside because another sucker will take your place.

It sounds like you have a story to tell.

Re: Google launches new vulnerability reward platform

#83
post #2

It's here: https://bughunters.google.com/ . Not sure which is the better top-level URL.

Dang, that is super slow to load on mobile. Seriously takes like 5 seconds.

just awful. pointlessly slow for such a simple page.

Re: Google launches new vulnerability reward platform

#84
post #71

Earlier quoted context omitted.

Why would they care. They have gotten your best work for free and can safely cast you aside because another sucker will take your place.

It sounds like you have a story to tell.

I've never taken part. I have seen so many people find a bug and not getting paid for a variety of reasons and even the ones who do get paid get paid so little compared to the value it gives the company. I'm sick of the everyday tech person getting taken advantage of and used as a cheap workforce. These bug bounties should pay people for the time they invest.

Re: Google launches new vulnerability reward platform

#85
post #77
post #38

Earlier quoted context omitted.

I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. The challenge, however, is constructing a sustainable model to incentivize product teams to reciprocate this closer working relationship. I would say all but the smallest of companies running bug bounties also have an internal security function that is already doing reporting on vulnerabilities, time…

> I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. Completely off-topic comment follows, but I find lingustics interesting, am a native (Br) English speaker, and think it's worthwhile to reassure someone they're foreign language skills are fine. Yes, it's good. (It's extremely valid :wink:). It has a slightly comical flair to it - not sarcastic, jus…

Ehh.

"extremely valid" is slightly off.

"extremely agree" is comical but definitely not standard US English.

Re: Google launches new vulnerability reward platform

#86

Earlier quoted context omitted.

Couldn't companies just publish a list of hashes of existing but not yet public disclosures? Seems as if that could solve the issue of doubt wrt timing.

How would that work? I publish some 256-bit values. You file a report. I mark you duplicate and tell you a random 256-bit value. What did you learn? The number of reports that eventually become fully public is nearly zero. Most don't become public at all, but of those that do, a lot of content is generally redacted.

The hash input could just be a generic description of the bug, minus any sensitive info, plus some salt.

All report hashes would have to go public as soon as the report is accepted. The hash input could go public once the bug goes public, so the duplicate reporters can then finally see proof that the bug had already been reported.

In what cases would companies be unable to publish generic descriptions after the bug is public? I'm not in the industry so I have no idea about this.

Re: Google launches new vulnerability reward platform

#87
post #48

Earlier quoted context omitted.

> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.

I'm not saying you shouldn't feel that way. I'm saying Google has no incentive to actually screw you over; that they have in fact the exact opposite incentive.

Aside from the monetary gain of simply not paying. You keep posting this but it’s simply not true, there is always a gain in not paying debts. Money is money, The making of which is Google’s cute business. Chill on the loop-aid consumption.

Re: Google launches new vulnerability reward platform

#88
post #25

There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP. But they dont do this. I dont know why. Security throug…

Third party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome... You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qua…

False: Seven figures trumps six.

Think like a mercenary.

Re: Google launches new vulnerability reward platform

#89
post #88

Earlier quoted context omitted.

Third party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome... You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qua…

False: Seven figures trumps six. Think like a mercenary.

No criminal organization is paying 7 figures for serverside vulnerabilities. They're not even paying 5 figures for them.
Post reply on HN