Earlier quoted context omitted.
They are gig workers. Security gets outsourced to these workers where normally the company would need to pay a salary. The refusal to pay while fixing the bug in 48 hours shows a power inbalance. I fear this is where we are headed in the future as AI pumps out most code all of the remaining work comes in the form of contests where thousands spends 80 hours a week and the company (in the best case) will award one pers…
Google does not use bug bounties instead of paying people salaries to do software security. Google pays more people to do software security than does any company on the planet. They do bug bounties because you get different bugs from them than you would from any employee. If bounty hunters are benefits-eligible employees, then there are virtually no services a company can buy from anybody that don't qualify similarly…
Google launches new vulnerability reward platform
81–90 of 109 posts
Re: Google launches new vulnerability reward platform
#82Earlier quoted context omitted.
> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.
Why would they care. They have gotten your best work for free and can safely cast you aside because another sucker will take your place.
Re: Google launches new vulnerability reward platform
#83Re: Google launches new vulnerability reward platform
#84Earlier quoted context omitted.
Why would they care. They have gotten your best work for free and can safely cast you aside because another sucker will take your place.
It sounds like you have a story to tell.
Re: Google launches new vulnerability reward platform
#85Earlier quoted context omitted.
I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. The challenge, however, is constructing a sustainable model to incentivize product teams to reciprocate this closer working relationship. I would say all but the smallest of companies running bug bounties also have an internal security function that is already doing reporting on vulnerabilities, time…
> I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. Completely off-topic comment follows, but I find lingustics interesting, am a native (Br) English speaker, and think it's worthwhile to reassure someone they're foreign language skills are fine. Yes, it's good. (It's extremely valid :wink:). It has a slightly comical flair to it - not sarcastic, jus…
"extremely valid" is slightly off.
"extremely agree" is comical but definitely not standard US English.
Re: Google launches new vulnerability reward platform
#86Earlier quoted context omitted.
Couldn't companies just publish a list of hashes of existing but not yet public disclosures? Seems as if that could solve the issue of doubt wrt timing.
How would that work? I publish some 256-bit values. You file a report. I mark you duplicate and tell you a random 256-bit value. What did you learn? The number of reports that eventually become fully public is nearly zero. Most don't become public at all, but of those that do, a lot of content is generally redacted.
All report hashes would have to go public as soon as the report is accepted. The hash input could go public once the bug goes public, so the duplicate reporters can then finally see proof that the bug had already been reported.
In what cases would companies be unable to publish generic descriptions after the bug is public? I'm not in the industry so I have no idea about this.
Re: Google launches new vulnerability reward platform
#87Earlier quoted context omitted.
> there is essentially zero upside to screwing over bounty hunters. Well, I felt pretty screwed over after Google decided not to reward me for discovering CVE-2021-30560.
I'm not saying you shouldn't feel that way. I'm saying Google has no incentive to actually screw you over; that they have in fact the exact opposite incentive.
Re: Google launches new vulnerability reward platform
#88There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP. But they dont do this. I dont know why. Security throug…
Third party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome... You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qua…
Think like a mercenary.
Re: Google launches new vulnerability reward platform
#89Earlier quoted context omitted.
Third party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome... You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qua…
False: Seven figures trumps six. Think like a mercenary.