I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
Increasing Google and Alphabet VRP rewards
81–90 of 102 posts
Re: Increasing Google and Alphabet VRP rewards
#82I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
This is why a hacker should consult an agent that has more experience in negotiating with these companies.
Re: Increasing Google and Alphabet VRP rewards
#83Earlier quoted context omitted.
There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/
No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.
Re: Increasing Google and Alphabet VRP rewards
#84I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
Re: Increasing Google and Alphabet VRP rewards
#85Earlier quoted context omitted.
There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/
No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.
Re: Increasing Google and Alphabet VRP rewards
#86Earlier quoted context omitted.
Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)
What is the legality of selling an exploit? Are you free and clear, or can you be tagged with enabling a future crime? Would they need to be able to trace a specific incident back to your exploit or get you on a catch-all law? Bugs are found all the time. Sharing a bug you found is not a crime, but I imagine they can always get you on tax fraud.
There are no issues reporting the income on tax filings
Re: Increasing Google and Alphabet VRP rewards
#87I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
There are two reasons for this. First, you're not competing with the gray market because it's quite simply a folly. If a government badly wants a 0-day, they will essentially pay whatever it takes . If you offer a million, they will offer two. You offer five, they offer ten. If you write bug-free software, they will send in Jia Tan. Their alternative to using a 0-day might be trying to hit someone with a million-doll…
Some take a bureaucratic approach but they are labeled as such on the bug bounty marketplaces
Web 2.0 organizations aren’t just competing with the gray market, they’re competing with Web 3.0’s licit market, while 3.0 is competing with immediate weaponization which is far easier to monetize
Re: Increasing Google and Alphabet VRP rewards
#88Earlier quoted context omitted.
There are two reasons for this. First, you're not competing with the gray market because it's quite simply a folly. If a government badly wants a 0-day, they will essentially pay whatever it takes . If you offer a million, they will offer two. You offer five, they offer ten. If you write bug-free software, they will send in Jia Tan. Their alternative to using a 0-day might be trying to hit someone with a million-doll…
Organizations in the crypto space more frequently value their bug bounty programs more accurately and pay in very clear terms, almost instantly Some take a bureaucratic approach but they are labeled as such on the bug bounty marketplaces Web 2.0 organizations aren’t just competing with the gray market, they’re competing with Web 3.0’s licit market, while 3.0 is competing with immediate weaponization which is far easi…
Re: Increasing Google and Alphabet VRP rewards
#89> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.
Re: Increasing Google and Alphabet VRP rewards
#90I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
Maybe these bounties are intentionally set to be roughly comparable to annual salaries. A very high bounty might encourage developers to plant backdoors instead, a la cobra effect: https://en.wikipedia.org/wiki/Perverse_incentive