Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

61–70 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#61
post #6

Earlier quoted context omitted.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

Fair enough, but do people claim them after finding them by accident? Or do people see a bounty and then put in up to X hours of effort (before either succeeding or giving up)? Does that model end up with a reasonable hourly rate? I'm trying to figure out the labor-side economics of this. Generally the supply side is getting a massive discount on these vulnerabilities compared to their potential costs. Although perha…

it is pretty lucrative for researchers who are unable to find similarly paying full time jobs in their countries

Re: Increasing Google and Alphabet VRP rewards

#62

Earlier quoted context omitted.

It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

Yes, they used a WhatsApp 0day in the murder of Khashoggi.

Re: Increasing Google and Alphabet VRP rewards

#63
post #58
post #50

Earlier quoted context omitted.

So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple. You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto. I guess you could get paid in a suitcase of cash, that has…

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/

At the same time, it's likely that Google's (along with most companies) VRP are not actually trying to compete on price with government exploit purchasers. If such an institution is trying to get into someone's Gmail account, they will probably find a way anyhow. And if they do need a certain exploit to do it, they have infinite funds to just keep upping the price they offer.

It's pretty much "Mossad/Not Mossad" threat modeling: https://philsrandomblathering.quora.com/The-Mossad-Not-Mossa...

Re: Increasing Google and Alphabet VRP rewards

#64
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

On the other hand, if you boost these too much, you're now incentivizing your full time security researchers to have white box access to leave and make more money doing white hat black box vuln checking.

And from there it follows that maybe the market rate isn't really that high, zerodium pays, maybe 2x what Google does for similar vulnerabilities, which is more but not a ton more.

Re: Increasing Google and Alphabet VRP rewards

#66
post #21

Hot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit t…

If it really was a way to get cheap labor, more companies would be doing it.

As it is now, only the largest tech companies with the strongest security records are actually running good bug bounty programs. They have excellent, well-paid security teams and they put systems in place to incentivize all of their employees to write secure code. But, they know that (1) mistakes can still happen, (2) clever vulnerabilities can be discovered that get around code that was previously thought to be following all best practices, and finally they understand very well that (3) if they don't pay, others will.

Unfortunately it's the companies that need it most - like AT&T and Experian - that have the worst track record with rewarding third-party security researchers.

Re: Increasing Google and Alphabet VRP rewards

#67
post #42
post #23

Earlier quoted context omitted.

I think GP is suggesting an insider could introduce a bug, have a confederate "find" it, and split the money. At $5m I think more than a few big tech employees might decide to write themselves a new minivan.

I think you'd have a tough time deliberately putting something like that in at a large company. The cost of failure is losing a very good job. If you discovered a vulnerability and sat on it for a future payout that would be more likely, yet still risky. Though it does come down to choosing to do crimes in the face of incentives and disincentives. Nothing unique here - humans break the rules all the time.

It's trivial for a motivated engineer to deliberately introduce bugs, most couldn't avoid it if they tried. It wouldn't be too hard to pass it off as an honest mistake either. You might not even lose your job, as a lot of places have a "blameless culture".

Re: Increasing Google and Alphabet VRP rewards

#68
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…

Google has 12B shares outstanding. A 1 cent hit to share price is already far more than $100K.

Re: Increasing Google and Alphabet VRP rewards

#69
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

A thought about when these big bugs occur, and bounties are awarded, they can't look too great.

I wonder if it's because Google was hit with more issues because they started doing cloud apps a bit before microsoft, amazon, etc.

The example that comes to mind is Gmail and it's rapid growth and issues it learned to sort out while it was becoming workspace.

No cloud is perfect, however I have heard different clouds have different maturity levels in certain areas of their security.

Something to always think about when using the cloud, which is someone else's computer.

If something goes wrong at the Cloud provider you'd have to deal with securing it some how moving forward anyways, so why not when selecting a cloud and trying to be hybrid cloud, or cloud agnostic.

Re: Increasing Google and Alphabet VRP rewards

#70

Earlier quoted context omitted.

> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…

Google has 12B shares outstanding. A 1 cent hit to share price is already far more than $100K.

Google has thousands of things going for and against it at any point in time. Unless an event is bad enough to wipe out tens of billions at once, there’s no way to quantify. And what can’t be measured can’t be a target.
Post reply on HN