Live data from Hacker News

Google launches new vulnerability reward platform

security.googleblog.com

101–109 of 109 posts

Re: Google launches new vulnerability reward platform

#101
post #19

Earlier quoted context omitted.

*Not a Google employee but have worked for a bug bounty* I agree everything you've stated would be desirable, and if there was a strong culture and policy of supporting bounty programs from the CEO on down, this could potentially be achievable. However: dupes - On the bounty side dupes are extremely common and buddies telling buddies about their finds is going to drive fraud up quite a bit. In my triage work I saw ve…

>dupes - On the bounty side dupes are extremely common and buddies telling buddies about their finds is going to drive fraud up quite a bit. In my triage work I saw very clear attempts at this regularly. wouldn't looking at the logs of when the reports were taken pretty much clearly show the first person to make the report? how is this a thing that gets confused to be an issue?

Yes. There was never a real problem figuring out who reported it first.

Duplicate reports are likely the most frustrating thing most security researchers will encounter. They put in a ton of work into finding the bug, developing a proof of concept and writing up a detailed report with the hope and expectation of being awarded for their effort. So when the triage team comes back and say it’s a duplicate and there will be no award, it's incredibly maddening. If someone needs to vent in my direction because of that, I can totally understand. The *problem* was trying to remain diplomatic with people who would sit there and repeatedly claim they were actually first, or that it wasn't a dupe, or that all of this was far too sophisticated for me to understand. Then, finding no sympathy from me, go to Twitter to wail and moan and bash the program with impunity because they know that the org won't respond in kind.

Re: Google launches new vulnerability reward platform

#102
post #89
post #88

Earlier quoted context omitted.

False: Seven figures trumps six. Think like a mercenary.

No criminal organization is paying 7 figures for serverside vulnerabilities. They're not even paying 5 figures for them.

5 figures is the minimum for good ones. $10k ain’t much.

Guess you need to meet richer criminals.

Re: Google launches new vulnerability reward platform

#103
post #101

Earlier quoted context omitted.

>dupes - On the bounty side dupes are extremely common and buddies telling buddies about their finds is going to drive fraud up quite a bit. In my triage work I saw very clear attempts at this regularly. wouldn't looking at the logs of when the reports were taken pretty much clearly show the first person to make the report? how is this a thing that gets confused to be an issue?

Yes. There was never a real problem figuring out who reported it first. Duplicate reports are likely the most frustrating thing most security researchers will encounter. They put in a ton of work into finding the bug, developing a proof of concept and writing up a detailed report with the hope and expectation of being awarded for their effort. So when the triage team comes back and say it’s a duplicate and there will…

>they know that the org won't respond in kind.

Maybe they should be allowed to. If it is someone that is seriously being that petulant about something, then the Org could post dates of correspondence, and even quote petulant tempertantrum once it escalates beyond civility. Once the user name gets out there, other bounty programs could just put a blanket ignor and drive the petulant person into obscurity. But of course it is the today&now, and nobody actually believes facts anymore.

Re: Google launches new vulnerability reward platform

#104
post #101

Earlier quoted context omitted.

Yes. There was never a real problem figuring out who reported it first. Duplicate reports are likely the most frustrating thing most security researchers will encounter. They put in a ton of work into finding the bug, developing a proof of concept and writing up a detailed report with the hope and expectation of being awarded for their effort. So when the triage team comes back and say it’s a duplicate and there will…

>they know that the org won't respond in kind. Maybe they should be allowed to. If it is someone that is seriously being that petulant about something, then the Org could post dates of correspondence, and even quote petulant tempertantrum once it escalates beyond civility. Once the user name gets out there, other bounty programs could just put a blanket ignor and drive the petulant person into obscurity. But of cours…

I worked with some true geniuses back then, and the idea of watching them systematically dismantle idiots in a public forum would give me chills. Alas, it wasn't to be. :)

Re: Google launches new vulnerability reward platform

#105
post #85
post #77

Earlier quoted context omitted.

> I don't know if 'extremely valid' is good English but it's how I would characterize your assessment. I totally agree. Completely off-topic comment follows, but I find lingustics interesting, am a native (Br) English speaker, and think it's worthwhile to reassure someone they're foreign language skills are fine. Yes, it's good. (It's extremely valid :wink:). It has a slightly comical flair to it - not sarcastic, jus…

Ehh. "extremely valid" is slightly off. "extremely agree" is comical but definitely not standard US English.

Well, 'valid' is comparable (more valid, less valid, etc.). I don't think it can be said that it's incorrect grammar.

It's just an unusual pairing, and 'extremely' is so much of a 'stronger' word that it's got that humourous edge.

Not in formal writing, sure, but it wouldn't make me think the speaker's struggling with English, if anything the opposite - a good command of it and able to twist it in fun ways.

Re: Google launches new vulnerability reward platform

#106
post #34

I would rather see more transparency once you are a reporter than shinier leaderboards. It is extremely frustrating to spend a week reverse engineering a vulnerability in an opaque cloud service only to be told it was a known issue (but private), won’t be fixed (but is within 48 hours), and that you don’t qualify for any compensation. I would like to see private issues shared with reporters when they are independentl…

It's really clear to me why people want more transparency on this stuff. I'd want it too if I was submitting to bounties. But the transparency you're asking for is difficult to actually provide. Meanwhile, for a vendor at Google's scale, there is essentially zero upside to screwing over bounty hunters. At any realistic valuation for a vulnerability, these are rounding error sums to the business. In fact, the exact op…

It’s not a question of if a report really is a dupe. This is going to happen constantly, proportionally to participation. The assertion is that secondary reports can have measurable value. Automatically paying dupes is untenable, but it seems like triage should handle dupes containing new information differently. If a vulnerability is sitting as a low priority and a dupe of the underlying vulnerability contains new information about the severity that gets it prioritized, it must have value.

Re: Google launches new vulnerability reward platform

#107

Earlier quoted context omitted.

It comes down to how much companies are willing to reveal after the fact then. If companies aren't prepared to reveal enough unpredictable detail involved in an exploit after the exploit had been fixed, that's another issue. I think companies like Google would be ok with it though.

You're proposing that they do a lot of work for no benefit. What would they get out of it? You're also still failing to account for the fact that reports rarely become public. I can refer you, again, to a random number just as easily as I can refer you to the calculated hash of my bespoke summary of an issue that was reported eight years ago.

As stated previously, it wouldn't work unless the company was prepared to disclose all reports at two stages: 1) hash of unpredictable description of the issue when the issue is reported, 2) hash input when the issue becomes public.

There would be no benefit except for a tiny amount of goodwill, so it's almost certainly not worth it. This is simply a method to address the duplicates issue. Nothing else.

Re: Google launches new vulnerability reward platform

#108
post #101

Earlier quoted context omitted.

>dupes - On the bounty side dupes are extremely common and buddies telling buddies about their finds is going to drive fraud up quite a bit. In my triage work I saw very clear attempts at this regularly. wouldn't looking at the logs of when the reports were taken pretty much clearly show the first person to make the report? how is this a thing that gets confused to be an issue?

Yes. There was never a real problem figuring out who reported it first. Duplicate reports are likely the most frustrating thing most security researchers will encounter. They put in a ton of work into finding the bug, developing a proof of concept and writing up a detailed report with the hope and expectation of being awarded for their effort. So when the triage team comes back and say it’s a duplicate and there will…

Why can’t you share the bounty between the people that report the bug while it is valid (ie. actually a non-fixed bug)?

Re: Google launches new vulnerability reward platform

#109
post #48

Earlier quoted context omitted.

I'm not saying you shouldn't feel that way. I'm saying Google has no incentive to actually screw you over; that they have in fact the exact opposite incentive.

I understand your point, but saying that Google has no incentive isn't accurate. There's always an incentive not to pay for bug reports, simply because it results in a short-term gain. Whether it's a good decision in the long run is another question. It's more helpful to analyze the situation from a game-theoretic standpoint. Bug bounty programs are a typical example of a cooperative game. If someone reports a securi…

Being the one who decides to pay or not pay bounties in our bug bounty program: trust me when I say that the internal discussion, fact finding, classification, quality control, release planning & the rest exceeds your bounty by a factor 10.

Same goes for the dialogs with unhappy hunters who like 'proof' for the arguments that a bug / vulnerability is not there.

There is literally no financial incentive for me at all to not reward, au contraire actually.

Post reply on HN