Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

101–102 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#101
post #97
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

There are brokers for website vulns? This presentation says there are brokers for clientside RCE vulns, but doesn't mention any brokers for website vulns. https://github.com/mdowd79/presentations/blob/main/bluehat20...

It depends on the vuln and the need. For example, an XSS won’t net you very much, unless the buyer already has a browser RCE but needs a way to deliver it to a target they know uses a particular service or browser, and for that they may need an XSS.

Still won’t net you as much as an RCE, but they do get bought sometimes.

Re: Increasing Google and Alphabet VRP rewards

#102

Earlier quoted context omitted.

Organizations in the crypto space more frequently value their bug bounty programs more accurately and pay in very clear terms, almost instantly Some take a bureaucratic approach but they are labeled as such on the bug bounty marketplaces Web 2.0 organizations aren’t just competing with the gray market, they’re competing with Web 3.0’s licit market, while 3.0 is competing with immediate weaponization which is far easi…

I don't think it's about accuracy. It's just a different world. A bug in a smart contract exposes them to unavoidable, catastrophic losses. An XSS on google.com... doesn't.

those worlds compete for mindshare

people don't consistently enter the same market for less compensation when given the choice

Post reply on HN