Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

81–90 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#81
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

Maybe these bounties are intentionally set to be roughly comparable to annual salaries. A very high bounty might encourage developers to plant backdoors instead, a la cobra effect:

https://en.wikipedia.org/wiki/Perverse_incentive

Re: Increasing Google and Alphabet VRP rewards

#82
post #56
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

This is why a hacker should consult an agent that has more experience in negotiating with these companies.

That's not how it works.

Re: Increasing Google and Alphabet VRP rewards

#83
post #58

Earlier quoted context omitted.

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/

No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.

"Legitimate" in the limited sense that you can invoice them for cybersecurity consulting, they'll pay you in fiat, and you can report this income to the tax office.

Re: Increasing Google and Alphabet VRP rewards

#84
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

I agree. As a Nest user, I am astonished at how low the bounty is.

Re: Increasing Google and Alphabet VRP rewards

#85
post #58

Earlier quoted context omitted.

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/

No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.

On a worse day, you're selling to Israel and getting a 6 year old girl's jaw blown off

Re: Increasing Google and Alphabet VRP rewards

#86

Earlier quoted context omitted.

Right, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)

What is the legality of selling an exploit? Are you free and clear, or can you be tagged with enabling a future crime? Would they need to be able to trace a specific incident back to your exploit or get you on a catch-all law? Bugs are found all the time. Sharing a bug you found is not a crime, but I imagine they can always get you on tax fraud.

Selling exploits isn’t subject to criminal sanctions

There are no issues reporting the income on tax filings

Re: Increasing Google and Alphabet VRP rewards

#87
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

There are two reasons for this. First, you're not competing with the gray market because it's quite simply a folly. If a government badly wants a 0-day, they will essentially pay whatever it takes . If you offer a million, they will offer two. You offer five, they offer ten. If you write bug-free software, they will send in Jia Tan. Their alternative to using a 0-day might be trying to hit someone with a million-doll…

Organizations in the crypto space more frequently value their bug bounty programs more accurately and pay in very clear terms, almost instantly

Some take a bureaucratic approach but they are labeled as such on the bug bounty marketplaces

Web 2.0 organizations aren’t just competing with the gray market, they’re competing with Web 3.0’s licit market, while 3.0 is competing with immediate weaponization which is far easier to monetize

Re: Increasing Google and Alphabet VRP rewards

#88

Earlier quoted context omitted.

There are two reasons for this. First, you're not competing with the gray market because it's quite simply a folly. If a government badly wants a 0-day, they will essentially pay whatever it takes . If you offer a million, they will offer two. You offer five, they offer ten. If you write bug-free software, they will send in Jia Tan. Their alternative to using a 0-day might be trying to hit someone with a million-doll…

Organizations in the crypto space more frequently value their bug bounty programs more accurately and pay in very clear terms, almost instantly Some take a bureaucratic approach but they are labeled as such on the bug bounty marketplaces Web 2.0 organizations aren’t just competing with the gray market, they’re competing with Web 3.0’s licit market, while 3.0 is competing with immediate weaponization which is far easi…

I don't think it's about accuracy. It's just a different world. A bug in a smart contract exposes them to unavoidable, catastrophic losses. An XSS on google.com... doesn't.

Re: Increasing Google and Alphabet VRP rewards

#90
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

Maybe these bounties are intentionally set to be roughly comparable to annual salaries. A very high bounty might encourage developers to plant backdoors instead, a la cobra effect: https://en.wikipedia.org/wiki/Perverse_incentive

Current or former employment is almost always a disqualifier for a bounty payout.
Post reply on HN