Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

41–50 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#41

Earlier quoted context omitted.

It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

They're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc.

China and Russia are on the same boat, but they are far more capable with in-house tech.

Re: Increasing Google and Alphabet VRP rewards

#42
post #23
post #18

Earlier quoted context omitted.

The point you are missing is that many of us do not have big tech careers. I am very fortunate to have a big tech career, but before I was hit by a stroke of luck, I was doing gig work paycheck to paycheck barely making ends meet. When you can’t see more than two weeks ahead in time, which you cannot do living paycheck to paycheck, you don’t think about the long term consequences because you are not capable of it. Th…

I think GP is suggesting an insider could introduce a bug, have a confederate "find" it, and split the money. At $5m I think more than a few big tech employees might decide to write themselves a new minivan.

I think you'd have a tough time deliberately putting something like that in at a large company. The cost of failure is losing a very good job.

If you discovered a vulnerability and sat on it for a future payout that would be more likely, yet still risky.

Though it does come down to choosing to do crimes in the face of incentives and disincentives. Nothing unique here - humans break the rules all the time.

Re: Increasing Google and Alphabet VRP rewards

#43
post #29
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.

Absolutely, that would most likely happen, they'd compete like any other market. However, a more appropriate financial compensation would still come with all the other benefits that I mentioned. Reporting to the affected company tends to come with positive public exposure, potential long-term job offers from that company or others, and receiving taxable income with few complications. Even selling exploits to intelligence agencies or nation-states likely involves more hurdles compared to dealing with companies like Alphabet or Microsoft.

Receiving 75k from Google versus a few hundred thousand from a less reputable source is a different scenario compared to getting a few hundred thousand from Google versus slightly more from those same sources. In the former, I'd have a hard time not going for the large yet morally dubious payday. With the latter, I feel like most, myself included, would stick with Google

Re: Increasing Google and Alphabet VRP rewards

#44
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

> in this case there is zero moral quandary And zero legal quandary.

Also true.

Re: Increasing Google and Alphabet VRP rewards

#45
post #33

So if you find several catastrophic vulnerabilities each year, then you can make as much as one of the many people whose jobs it was not to create those vulnerabilities in the first place? :)

Yes, but you only have to succeed once. They have to succeed every time, which is a much much harder proposition.

Re: Increasing Google and Alphabet VRP rewards

#46
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

[deleted]

Re: Increasing Google and Alphabet VRP rewards

#47

Earlier quoted context omitted.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

They're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc. China and Russia are on the same boat, but they are far more capable with in-house tech.

Also, just to be clear - the US gov buys tons of zerodays.

Re: Increasing Google and Alphabet VRP rewards

#48
post #21

Hot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit t…

That’s not actually fair.

Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in.

A defender has to win every time, which is much much harder, if not impossible.

Re: Increasing Google and Alphabet VRP rewards

#50
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple.

You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto.

I guess you could get paid in a suitcase of cash, that has it's own headaches.

Personally, I'm just picturing so many headaches that even if I wasn't morally against selling it to the highest bidder, it doesn't feel worth it. Selling to some other "proper" corporate entity or a government agency seems reasonable, but are they offering more than Google?

Post reply on HN