Live data from Hacker News

The Chrome VRP Panel has decided to award $250k for this report

issues.chromium.org

161–170 of 292 posts

Re: The Chrome VRP Panel has decided to award $250k for this report

#161
post #110
post #73

Earlier quoted context omitted.

Do you pay a software engineer for their time based on your revenue or his skill?

Be somewhat competitive to what such developers could get on the black market. Discounting the ethics. Surely a bug on Chrome is worth more than a bug on Firefox.

Should I be competitive with meth manufacturers when I buy prescription cold medicine from a pharmacist?

Re: The Chrome VRP Panel has decided to award $250k for this report

#163
post #47

Earlier quoted context omitted.

"If I report the body, no-one will suspect I'm the murderer" Yes they will.

Which is why people are hesitant to report a body they have not killed, just found!

Can usually report anonymously so this shouldn't be an issue. If there's no mechanism for that then yeah I'd consider keeping my mouth shut if it doesn't involve me directly (like the body is in my home somehow).

Re: The Chrome VRP Panel has decided to award $250k for this report

#164

Earlier quoted context omitted.

Depends on where in the world you are. I wouldn't call $250k life-changing-money anywhere developed. It's "I can probably stop worrying about money for a while" kind of money, not "life-changing" money. Not a whole lot you can buy for $250k. After taxes, that probably doesn't even buy a house.

Can somebody help me understand why these obviously very stupid takes keep popping up on HN? Is it rich people who genuinely have no idea what anything costs? Is it rich people intentionally being cruel to everybody else? Is it people trying to appear rich by pretending they have no idea what anything costs? Is it a bay area thing, are people just blowing through a literal fortune every year and unaware of their spen…

tech salaries in the US are high enough that this is approximately 1-3 years of income as a lump sum. more than that, if you got this amount as a bonus you already have stupid money.

of course $140k would be life changing for most people. but OP, and i suspect most of the other commenters, are not in that situation.

Re: The Chrome VRP Panel has decided to award $250k for this report

#165
post #9

Earlier quoted context omitted.

How much Alphabet makes is almost irrelevant. The incentive here should be for security researchers. As long as there's enough incentive for security researchers to continue to report the bugs they find (which must be balanced against the potential payment a criminal could get if exploiting the bug, which is not directly correlated to the company's income either, at least not necessarily), the payment is appropriate.

> How much Alphabet makes is almost irrelevant. While I embrace the downvotes, I disagree. From my pov, the amount of money paid should factor in the anticipated risk for your business. If a privilege escalation means that Google takes a massive hit in Ad Revenue, than this should be factored in.

Why would it affect ad revenue?

An exploit like this would be abused by somebody who sets up a malicious website to try to take control over somebody's device or otherwise steal secrets from them like keys for cryptocurrencies. These attacks tend to be targeted. Nobody is using an exploit like this to create an ad blocker or even to do ad fraud.

The only risk to revenue here is reputational, and I think that it is likely that the existence of this bug would be less widely known if the bounty program didn't exist and the bug was sold on the black market.

Re: The Chrome VRP Panel has decided to award $250k for this report

#166
post #106
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

[dead]

Re: The Chrome VRP Panel has decided to award $250k for this report

#167
post #104

Earlier quoted context omitted.

Selling something to the black market doesn't magically make it tax free. It's almost the opposite. The money is going to show up in your auditable accounts sooner or later, so it's best to pay tax on it, but you'll also have to come up with a fake but auditable story of where it came from, meaning you'll have to engage the services of professional money launderers. They will also take a cut. So, it's like paying tax…

The money itself might not be dirty, couldn’t you just claim something like “I sold a secret, highly valuable algorithm to this guy”? Tax would still need to be paid of course

And when they ask you who “this guy” is?

Re: The Chrome VRP Panel has decided to award $250k for this report

#168
post #106

Earlier quoted context omitted.

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

> How There are companies that specialize in getting grey market bugs in important software, ie browsers and OSes. They are repwat players and have a reputation to actually pay out.

From what I understand, they generally require complete reliable exploits. I don't think they generally buy proofs of concept, or exploits that only work some percent of the time. This specific exploit worked 80% of the time, which I'm not sure is good enough for them.

Yes, maybe the exploit could likely be modified to be more reliable. That's more work though.

Re: The Chrome VRP Panel has decided to award $250k for this report

#169
post #106
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

Thats what trusted middle men are for, instead of gaining rep among infosec posers on twitter you build rep under your anonymous alias. This is nothing new.

Or just sell it to the israelis.

Re: The Chrome VRP Panel has decided to award $250k for this report

#170

Earlier quoted context omitted.

Is their CEO comp not in line with the market?

No. More than 80% of Mozilla Corp's income is a yearly payment from Google. [0] The payment will stop immediately if Google thinks it's no longer needed, or if federal prosecutors (who have determined this payment is illegal ) decide the remedy is to stop the payment. [1] The CEO's job is simple. Say "I think we should take Google's money again this year", and then pocket several million of it. Ca-ching! What are you…

> Mitchell Baker did not leave the gravy train by stepping down as CEO, she merely moved to a different seat on the gravy train - chair of the Mozilla Foundation

Mitchell has not been a member of the Mozilla Foundation or Mozilla Corporation boards since February 2025.

https://blog.mozilla.org/en/mozilla/mozilla-leadership-growt...

Post reply on HN