Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

71–80 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#71

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

The highest ROI for me were bugs I found incidentally. Like I was building a client for some auth scheme and... yikes the documentation made it clear they are vulnerable. No POC needed, mostly linked to the part of the spec they forgot.

Bug finding requires theory building and guesswork. You're working blind. Reporting requires detailed technical writing and POC implementation. It's time consuming, so unless you're able to crank out findings or submit the same issue to multiple companies in parallel, the hourly rate will be low. Companies are flooded with low quality reports, so you really need to make the issue crystal clear.

Private bug bounties are better because there's usually obvious issues, but you're racing to be first to report.

Contract security work is much more predictable. Companies who "haven't thought about security before" are desperate for help. You can get more money building a system inventory, recommending updates for EOL systems, finding leaked passwords, and turning on firewalls. Basically engineering teams that know they have issues, but need someone external to make it clear to management that they need to invest in security. I've never failed to find at least one way to get system root or cloud admin rights on those contracts.

Re: Increasing Google and Alphabet VRP rewards

#72
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

There are two reasons for this. First, you're not competing with the gray market because it's quite simply a folly. If a government badly wants a 0-day, they will essentially pay whatever it takes. If you offer a million, they will offer two. You offer five, they offer ten. If you write bug-free software, they will send in Jia Tan. Their alternative to using a 0-day might be trying to hit someone with a million-dollar bomb launched from a $100M fighter jet.

But the second reason, quite prosaically, is that individual bugs aren't worth that much to a business. You can't build your security program on the expectation that you could reliably squash all bugs. You also invest in being able to detect and contain breaches - and if you do that, even the best exploit is a crapshoot for the attackers. Maybe they get in, lose access five minutes later, and are out a million bucks.

In other words, the point of paying for bugs is to raise the bar, and to get some independent validation of your security practices - not to make attacks impossible.

Finally, there's a retention element to it. Paradoxically, you might be worse off if your bounty program instantly turns your best bug hunters into millionaires. If they no longer need to make rent, they might decide that they like farming more.

Re: Increasing Google and Alphabet VRP rewards

#73
post #43
post #29

Earlier quoted context omitted.

You're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.

Absolutely, that would most likely happen, they'd compete like any other market. However, a more appropriate financial compensation would still come with all the other benefits that I mentioned. Reporting to the affected company tends to come with positive public exposure, potential long-term job offers from that company or others, and receiving taxable income with few complications. Even selling exploits to intellig…

Reporting a security issue to a company also comes with a large risk of being arrested and sentenced. Maybe not Google in particular, but it doesn't happen infrequently that someone reports a security issue to a company and is then convicted of hacking. Those people definitely wish they'd sold their exploit to hackers.

Re: Increasing Google and Alphabet VRP rewards

#74

> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.

That was my first thought. How much does the market pay for an account takeover?

If I'm locked out I'm likely to pay a thousand.

Re: Increasing Google and Alphabet VRP rewards

#75
post #56
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

This is why a hacker should consult an agent that has more experience in negotiating with these companies.

You don’t negotiate bug bounties really.

Re: Increasing Google and Alphabet VRP rewards

#76
post #31

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

It's not worth it. Payout by default is at least 90+ days (or 3 months) after disclosure (this is standard operating procedure to give company time to fix vulnerability). Then some companies have some bullshit internal company procedure for payout ("only at the end of the quarter"). Some companies dangle the carrot of "higher payouts" but after an internal review by some fresh out of college, security bootcamp asshol…

Agreed about boredom. There are times I've discovered issues incidentally, checked if the company had a bug bounty program. If they don't, I may chuck a vague email to security@, if they do I'll write something quick and take whatever they send. I've seen $3k once from this, but usually it's not enough to justify the time it takes to do the write up. There are far too many: out of scope, we already know, or other non-payment results.

Re: Increasing Google and Alphabet VRP rewards

#78
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You might find these slides on the 0day market interesting https://github.com/mdowd79/presentations/blob/main/bluehat20... Unfortunately the talk wasn’t recorded but he did do a follow up interview on a podcast called Security, Cryptography, Whatever

That seems to be saying that currently there is no market for website vulnerabilities, but a market for them might develop in the future as memory corruption vulnerabilities disappear due to mitigations.

This Google/Alphabet VRP change I think is pretty much just about website vulnerabilities.

Disclosure: I work at Google but not on the VRP.

Re: Increasing Google and Alphabet VRP rewards

#80
post #58
post #50

Earlier quoted context omitted.

So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple. You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto. I guess you could get paid in a suitcase of cash, that has…

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/

No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate".

On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.

Post reply on HN