Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

31–40 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#31

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

It's not worth it. Payout by default is at least 90+ days (or 3 months) after disclosure (this is standard operating procedure to give company time to fix vulnerability). Then some companies have some bullshit internal company procedure for payout ("only at the end of the quarter"). Some companies dangle the carrot of "higher payouts" but after an internal review by some fresh out of college, security bootcamp asshole. The committee downgrades it to a less severe vulnerability (ie, fuck you).

The number of clueless individuals running these bug bounty programs is not worth it. The only reason most people do it is for the "fame" within the security community; or that occasional researcher that was just bored.

Even worse, some companies (like South Korean companies) will not even pay out if you are not a citizen of the country. Makes no sense to me.

Re: Increasing Google and Alphabet VRP rewards

#32

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

I've been on both sides of bug bounties for many years. In truth, no one is offering a comparable bounty to what you can get selling exploits to a reseller. The closest would be Apple or Google with their million dollar bounties for cell phone exploits, but even that is likely underpaying.

The real value of bug bounties is for less sensitive products that aren't really big targets for nation states. Startups with products that haven't seen wide deployment in sensitive industries, for example.

There are many people who are perfectly happy getting "rep" and lower payouts for finding flaws in even the highly targeted applications, thankfully.

Re: Increasing Google and Alphabet VRP rewards

#34
post #29
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.

On bro plus that side doesn’t pay taxes / it’s free cash anyway

Re: Increasing Google and Alphabet VRP rewards

#35
post #6

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

> in this case there is zero moral quandary

And zero legal quandary.

Re: Increasing Google and Alphabet VRP rewards

#37
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

Re: Increasing Google and Alphabet VRP rewards

#38
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k.

This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company?

This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets, but they'll be fine. All the execs will get their bonuses.

Re: Increasing Google and Alphabet VRP rewards

#40

Earlier quoted context omitted.

It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

perhaps-Saudi-prob-Israel.

(Israel is known to be prolific; many brokers and the whole industry on all sides has a lot of people and entities from Israel. Saudi is publically obv active due to stories like MSB pwning Bezos over Whatsapp)

Post reply on HN