Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

21–30 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#21
Hot Take: these bug bounty systems are a way to get cheap labor.

Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements.

Yea, a potential $150K bounty sounds is a shit ton of money for a person in a third world country. But for anybody else (given the same time spent finding the vulnerability), there is no financial motivation. Only "fame" via disclosure reports in the security community.

This is the equivalent of a customer asking a professional photographer who is new on the scene to do their photography for free in exchange for "exposure". No, you aren't innovative. You are a cheap asshole.

Re: Increasing Google and Alphabet VRP rewards

#23
post #18

Earlier quoted context omitted.

You're both missing the point. Consider this: you're a big tech engineer, would you risk your career and many years in jail for 75k? Of course not. How about 5 million? Maybe you would... Big tech already has a massive problem with insider threats, they don't need to offer some of the most clever programmers in the world(their employees) a massive incentive to screw them over.

The point you are missing is that many of us do not have big tech careers. I am very fortunate to have a big tech career, but before I was hit by a stroke of luck, I was doing gig work paycheck to paycheck barely making ends meet. When you can’t see more than two weeks ahead in time, which you cannot do living paycheck to paycheck, you don’t think about the long term consequences because you are not capable of it. Th…

I think GP is suggesting an insider could introduce a bug, have a confederate "find" it, and split the money. At $5m I think more than a few big tech employees might decide to write themselves a new minivan.

Re: Increasing Google and Alphabet VRP rewards

#24
I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of magnitude more than 75k.

Looked into it and am equally surprised to find that others, like Microsoft [0] also have such low bounties for these types of attacks.

While providing such an exploit to the affected company has value beyond the bounty (potential job offers, media exposure, credibility, ethical considerations, etc.), weighing that up against life-changing money really makes it hard to fault those who take the more lucrative route of selling these to the highest bidder, whoever that may be.

Seriously, Alphabet and Co. can afford more, especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k.

[0] https://www.microsoft.com/en-us/msrc/bounty

Re: Increasing Google and Alphabet VRP rewards

#25

> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.

Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)

I'd expect getting involved with bad people would lead to bad outcomes. The "must tie up any loose ends" trope. Too many movies?

Re: Increasing Google and Alphabet VRP rewards

#27
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

Fair enough, but do people claim them after finding them by accident? Or do people see a bounty and then put in up to X hours of effort (before either succeeding or giving up)? Does that model end up with a reasonable hourly rate? I'm trying to figure out the labor-side economics of this. Generally the supply side is getting a massive discount on these vulnerabilities compared to their potential costs. Although perha…

The economics of bug bounties from a “bug hunters” perspective are quite interesting! I’m going to give the short version.

There are public (such as the one being discussed here) and private programs.

To gain access to private programs you have to be invited to participate - you get an invite usually based on reputation for providing good reports on public programs.

Platforms like H1 and BugCrowd act as intermediaries for this, with reputation scores, etc.

It should also be noted here that if you rediscover a bug someone else reported, you don’t usually get paid.

With public BBP/VRP, you are competing against everyone in the space against a relatively limited subset of targets. The way to “win” is to either “go deep” against high payout targets, expending a lot of effort in the hopes of avoiding a duplicate finding, or to invest heavily in automation, or some combination of the above.

With private programs you are competing against many less people and have a higher probability of payout for time/effort expended.

The guys who tend to make a shitload of money off BBP/VRP either are focused solely on a handful of high payout targets, or have invested heavily in automation to grind public programs, gain invites to private ones, and repeat.

A lot of the better offerings in the “continuous vuln scanning” or “attack surface monitoring” market are from people who have been “full time” bounty hunters for a while, built out significant automation platforms, and pivoted to offering it as SaaS products to enterprise for detection of issues.

There’s a lot more to it, but it’s probably worth a blog post at some point tbh.

In my own experience, as someone who has participated in bug bounties and vuln disclosure programmes in my free time for about a decade now, I usually land a couple of nice payouts per year and a lot of issues reported without payment.

Re: Increasing Google and Alphabet VRP rewards

#28
I personally know at least one normally functioning person that didn't claim their $1k bounty due to the complexity of that process (also bureaucracy).

Fortunately this is not a problem for me, because I couldn't find anything even if I wanted.

Re: Increasing Google and Alphabet VRP rewards

#29
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.

Re: Increasing Google and Alphabet VRP rewards

#30

Earlier quoted context omitted.

Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)

What is the legality of selling an exploit? Are you free and clear, or can you be tagged with enabling a future crime? Would they need to be able to trace a specific incident back to your exploit or get you on a catch-all law? Bugs are found all the time. Sharing a bug you found is not a crime, but I imagine they can always get you on tax fraud.

There are quite a few "legit" exploit resellers who will gladly pay millions for exploits and report the income to the IRS. They seem to do fine legally so long as their primary customers are govt or quasi-govt agencies. Now, if you decided to sell to an embargoed country I'm sure they'd suddenly declare the exploits munitions and try to lock you up for a long time.
Post reply on HN