Live data from Hacker News

The Chrome VRP Panel has decided to award $250k for this report

issues.chromium.org

181–190 of 292 posts

Re: The Chrome VRP Panel has decided to award $250k for this report

#181

Earlier quoted context omitted.

But Chrome is paying more as a percentage of their browser units' income, no? Virtually all of Mozilla's income comes from the browser (via the Google search agreement). The vast majority of Google's revenue comes from ad revenue on search, YouTube, and Adsense. Not from Chrome directly. So they had less incentive to reward its security, but did so anyway. And they also do some of the best work in the industry, free,…

The browser totally has zero to do with google ads. Totally no connection at all.

Well, maybe.

Personally I believe that the browser is intended to defend against e.g. Facebook's apps. Google wants to make sure that if you buy a new device and it comes with a Facebook app preinstalled, it also comes with a browser. And that the browser isn't controlled by anyone who'd like to disrupt any of Google's many nice income streams.

Re: The Chrome VRP Panel has decided to award $250k for this report

#182
post #106
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

[dead]

Re: The Chrome VRP Panel has decided to award $250k for this report

#183
post #113
post #104

Earlier quoted context omitted.

The money itself might not be dirty, couldn’t you just claim something like “I sold a secret, highly valuable algorithm to this guy”? Tax would still need to be paid of course

Immediate follow up questions from the tax man, and then shortly afterwards the police "who is this guy? where is the invoice? what is his phone number?"

No, it doesnt typically work that way at all. The tax man just wants to get paid.

I grew up in an area known for people growing cannabis before it was legal. An enormous amount of taxes got dodged through cash land deals, but tons of people just claimed the income under various categories and no one ever came knocking because of that.

Its usually the other way around. If you caught the Fed's eye, then they might try to get you on tax evasion or something. Although, frankly even that was very rare. There are just a lot of very obvious fish to fry.

Re: The Chrome VRP Panel has decided to award $250k for this report

#184
post #106

Earlier quoted context omitted.

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

Thats what trusted middle men are for, instead of gaining rep among infosec posers on twitter you build rep under your anonymous alias. This is nothing new. Or just sell it to the israelis.

Bahah, best description of the anime avatar people

Re: The Chrome VRP Panel has decided to award $250k for this report

#186
post #124

Earlier quoted context omitted.

> How There are companies that specialize in getting grey market bugs in important software, ie browsers and OSes. They are repwat players and have a reputation to actually pay out.

OK. But how do I find them ? And, again, how do I assess their reputation and likelihood of paying me. How much of a premium are they paying to make it worthwhile?

Just search for vulnerability or 0day acquisition platforms and do some research into the companies. All of them are kinda shady but there are some which only sell to Five Eyes if you want to be “moral”

You can also go through ZDI (owned by Trend Micro), but the payout will be lower. It’s in Trend Micro’s interest so they can get ahead in detections.

Re: The Chrome VRP Panel has decided to award $250k for this report

#187

Are there people who work full time from income on bug bounties?

Yes. There are plenty of folks who submit to the company I work for who live in regions of the world that are extremely low cost of living/salary (in USD terms) and most BB programs pay out fixed USD rates. It can be very lucrative.

Re: The Chrome VRP Panel has decided to award $250k for this report

#188
post #110

Earlier quoted context omitted.

Be somewhat competitive to what such developers could get on the black market. Discounting the ethics. Surely a bug on Chrome is worth more than a bug on Firefox.

Should I be competitive with meth manufacturers when I buy prescription cold medicine from a pharmacist?

This is the complete opposite in every facet. I struggle to think of a worse analogy.

Re: The Chrome VRP Panel has decided to award $250k for this report

#189

Earlier quoted context omitted.

No. More than 80% of Mozilla Corp's income is a yearly payment from Google. [0] The payment will stop immediately if Google thinks it's no longer needed, or if federal prosecutors (who have determined this payment is illegal ) decide the remedy is to stop the payment. [1] The CEO's job is simple. Say "I think we should take Google's money again this year", and then pocket several million of it. Ca-ching! What are you…

> Mitchell Baker did not leave the gravy train by stepping down as CEO, she merely moved to a different seat on the gravy train - chair of the Mozilla Foundation Mitchell has not been a member of the Mozilla Foundation or Mozilla Corporation boards since February 2025. https://blog.mozilla.org/en/mozilla/mozilla-leadership-growt...

Thanks for noting that, I hadn't realised. I've edited out that line.

Re: The Chrome VRP Panel has decided to award $250k for this report

#190
post #95

Earlier quoted context omitted.

Okay, I want to make a desktop app that runs on Linux. Which language should I use? Java?

Some current trendy options would be Kotlin (with Kotlin Multiplatform) or C# (with Avalonia UI). Edit: I guess I should've at least asked myself if the question was rhetorical.

My problem with "crossplatform" GUIs that run on Linux is that they aren't made to run on Linux desktop, they are made to run on Android, iOS, Windows, macOS, and finally Linux desktop.

All I want is a menubar, a toolbar, a statusbar, and some dialog windows. I don't want fading transitions when I click a tab.

It's crazy that I'm forced to write header files just to have a menubar.

Zig 1.0 can't come soon enough.

Post reply on HN