Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

51–60 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#51

Earlier quoted context omitted.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

They're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc. China and Russia are on the same boat, but they are far more capable with in-house tech.

OK i see, re-reading this with your top level post is "not all vulnerabilities are the type that could be bought by (insert state actor)", which makes sense (for some reason I thought you meant that they were buying the type of bugs that would end up getting reported to a BBP, but I just misread the original comment).

And yes the Saudis definitely bought software from NSO Group but it's also been used by plenty of other governments, including half the EU...

Re: Increasing Google and Alphabet VRP rewards

#52
post #29

Earlier quoted context omitted.

You're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.

On bro plus that side doesn’t pay taxes / it’s free cash anyway

Or at least that's what Al Capone thought.

Re: Increasing Google and Alphabet VRP rewards

#53
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…

Solarwinds

Re: Increasing Google and Alphabet VRP rewards

#54
post #50
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple. You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto. I guess you could get paid in a suitcase of cash, that has…

There is a thriving “grey” market for vulnerabilities, where brokers buy vulns and sell them on to e.g. intelligence agencies. This is well established and unlikely to cause much legal difficulty for the bug finder.

Re: Increasing Google and Alphabet VRP rewards

#55
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You might find these slides on the 0day market interesting

https://github.com/mdowd79/presentations/blob/main/bluehat20...

Unfortunately the talk wasn’t recorded but he did do a follow up interview on a podcast called Security, Cryptography, Whatever

Re: Increasing Google and Alphabet VRP rewards

#56
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

This is why a hacker should consult an agent that has more experience in negotiating with these companies.

Re: Increasing Google and Alphabet VRP rewards

#58
post #50
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple. You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto. I guess you could get paid in a suitcase of cash, that has…

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin.

Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities."

https://zerodium.com/

Re: Increasing Google and Alphabet VRP rewards

#59
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…

I have a few examples I remembered where there was both short term impact on the stock directly after the publication of a breach and the stock remaied at a lower point across an extended period of time. I have to admit though that it is nearly impossible to attribute how much of this drop in value and the stock staying at that lower level can be directly attributed to the breach compared to other reasons, such as general performance, etc. However, on the other hand, this also does not reflect the likely high spending a company tends to do in the aftermath of such a breach on better security, PR, settling lawsuits, etc. which most certainly exceed 75k, a rounding error for business of any significant size.

Anyways, here a two examples of the top of my head:

Of course, the big one, Equifax, which had a significant drop in the week after the announcement. It took roughly two-years for the stock to trade at pre-breach levels [0], likely in part due to their less than stellar handling of the aftermath, though I'd still consider that directly linked to the breach.

More to the point, there was Yahoo, which I wanted to mention because its impact was more clearly measurable. What was weird about that one is that their case centered around a belated (by two years) announcement of a breach they faced between 2013 and 2014. That did impact their stock, but more importantly, it's the reason for a 350 million USD reduction in the acquisition price Verizon had to pay for Yahoo. Verizon agreed to cover half the cost of non-SEC government investigations and third-party lawsuits (which I feel also would fall under hitting their "bottom line"), while Yahoo covered the other half and any liability from shareholder lawsuits or SEC investigations. That 350 million USD plus fines to me is the clearest number one can put on a breach and I feel it shows that, whatever one thinks is fair compensation for reporting 0-days, 75k is far removed from that.

So yeah, there have been cases where a security exploit seriously impacted the finances of a publicly traded company and keep in mind, I only stuck with actual reductions in their stock value/acquisition price.

[0] https://www.marketwatch.com/investing/stock/efx

[1] https://www.geekwire.com/2017/verizon-pays-350m-less-yahoo-f...

Re: Increasing Google and Alphabet VRP rewards

#60
post #53

Earlier quoted context omitted.

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…

Solarwinds

How could I forget that one. Solarwinds is an even better example than the ones I remembered (Equifax and Yahoo).
Post reply on HN