Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

1–10 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#4

> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.

Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary)

Not actually, I am not a law breaker;)

Re: Increasing Google and Alphabet VRP rewards

#5

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

> I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

Most certainly, or those who can't get jobs because of their record but know how to code.

Re: Increasing Google and Alphabet VRP rewards

#6

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it).

But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to.

Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guaranteed to find a vuln, and the timing between findings is going to be inconsistent at best.

Re: Increasing Google and Alphabet VRP rewards

#7
post #6

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

Finding a vuln and selling to Google is also presumably something you can put on your resume. Like a portfolio piece.

Re: Increasing Google and Alphabet VRP rewards

#8

> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.

Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)

You're both missing the point. Consider this: you're a big tech engineer, would you risk your career and many years in jail for 75k? Of course not. How about 5 million? Maybe you would... Big tech already has a massive problem with insider threats, they don't need to offer some of the most clever programmers in the world(their employees) a massive incentive to screw them over.

Re: Increasing Google and Alphabet VRP rewards

#9
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

Finding a vuln and selling to Google is also presumably something you can put on your resume. Like a portfolio piece.

True. It’s not likely to be a huge difference-maker, but it certainly belongs on a resume more than “sold 0day to foreign governments” heh

Re: Increasing Google and Alphabet VRP rewards

#10
post #6

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

Fair enough, but do people claim them after finding them by accident? Or do people see a bounty and then put in up to X hours of effort (before either succeeding or giving up)? Does that model end up with a reasonable hourly rate?

I'm trying to figure out the labor-side economics of this.

Generally the supply side is getting a massive discount on these vulnerabilities compared to their potential costs. Although perhaps the discount applies is appropriate considering how few vulnerabilities do result in observable expense.

Post reply on HN