Earlier quoted context omitted.
They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…
Fair enough, but do people claim them after finding them by accident? Or do people see a bounty and then put in up to X hours of effort (before either succeeding or giving up)? Does that model end up with a reasonable hourly rate? I'm trying to figure out the labor-side economics of this. Generally the supply side is getting a massive discount on these vulnerabilities compared to their potential costs. Although perha…
Increasing Google and Alphabet VRP rewards
61–70 of 102 posts
Re: Increasing Google and Alphabet VRP rewards
#62Earlier quoted context omitted.
It's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.
curious why Saudi? Are they known to be prolific buyers of vulnerabilities?
Re: Increasing Google and Alphabet VRP rewards
#63Earlier quoted context omitted.
So morality aside, I imagine dealing with large amounts of money that you can't explain the origin of isn't simple. You can't just do a bank transfer, so you're probably getting paid on crypto. Converting the crypto to fiat will probably be a pain. All the reputable exchanges have KYC requirements. You'd have to explain how you came to acquire so much crypto. I guess you could get paid in a suitcase of cash, that has…
There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/
It's pretty much "Mossad/Not Mossad" threat modeling: https://philsrandomblathering.quora.com/The-Mossad-Not-Mossa...
Re: Increasing Google and Alphabet VRP rewards
#64I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
And from there it follows that maybe the market rate isn't really that high, zerodium pays, maybe 2x what Google does for similar vulnerabilities, which is more but not a ton more.
Re: Increasing Google and Alphabet VRP rewards
#65Re: Increasing Google and Alphabet VRP rewards
#66Hot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit t…
As it is now, only the largest tech companies with the strongest security records are actually running good bug bounty programs. They have excellent, well-paid security teams and they put systems in place to incentivize all of their employees to write secure code. But, they know that (1) mistakes can still happen, (2) clever vulnerabilities can be discovered that get around code that was previously thought to be following all best practices, and finally they understand very well that (3) if they don't pay, others will.
Unfortunately it's the companies that need it most - like AT&T and Experian - that have the worst track record with rewarding third-party security researchers.
Re: Increasing Google and Alphabet VRP rewards
#67Earlier quoted context omitted.
I think GP is suggesting an insider could introduce a bug, have a confederate "find" it, and split the money. At $5m I think more than a few big tech employees might decide to write themselves a new minivan.
I think you'd have a tough time deliberately putting something like that in at a large company. The cost of failure is losing a very good job. If you discovered a vulnerability and sat on it for a future payout that would be more likely, yet still risky. Though it does come down to choosing to do crimes in the face of incentives and disincentives. Nothing unique here - humans break the rules all the time.
Re: Increasing Google and Alphabet VRP rewards
#68I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…
Re: Increasing Google and Alphabet VRP rewards
#69I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
I wonder if it's because Google was hit with more issues because they started doing cloud apps a bit before microsoft, amazon, etc.
The example that comes to mind is Gmail and it's rapid growth and issues it learned to sort out while it was becoming workspace.
No cloud is perfect, however I have heard different clouds have different maturity levels in certain areas of their security.
Something to always think about when using the cloud, which is someone else's computer.
If something goes wrong at the Cloud provider you'd have to deal with securing it some how moving forward anyways, so why not when selecting a cloud and trying to be hybrid cloud, or cloud agnostic.
Re: Increasing Google and Alphabet VRP rewards
#70Earlier quoted context omitted.
> especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. This assumption seems misplaced. Can you give an example of a security exploit seriously impacting the finances of a publicly traded company? This is also on the front page https://news.ycombinator.com/item?id=40944505 and I really doubt AT&T stock will suffer significantly. Maybe they'll miss Q3 targets,…
Google has 12B shares outstanding. A 1 cent hit to share price is already far more than $100K.