Earlier quoted context omitted.
Maybe these bounties are intentionally set to be roughly comparable to annual salaries. A very high bounty might encourage developers to plant backdoors instead, a la cobra effect: https://en.wikipedia.org/wiki/Perverse_incentive
Current or former employment is almost always a disqualifier for a bounty payout.
Increasing Google and Alphabet VRP rewards
91–100 of 102 posts
Re: Increasing Google and Alphabet VRP rewards
#92I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…
You might find these slides on the 0day market interesting https://github.com/mdowd79/presentations/blob/main/bluehat20... Unfortunately the talk wasn’t recorded but he did do a follow up interview on a podcast called Security, Cryptography, Whatever
Re: Increasing Google and Alphabet VRP rewards
#93Earlier quoted context omitted.
curious why Saudi? Are they known to be prolific buyers of vulnerabilities?
They're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc. China and Russia are on the same boat, but they are far more capable with in-house tech.
Re: Increasing Google and Alphabet VRP rewards
#94Hot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit t…
That’s not actually fair. Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in. A defender has to win every time , which is much much harder, if not impossible.
Re: Increasing Google and Alphabet VRP rewards
#95Earlier quoted context omitted.
That’s not actually fair. Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in. A defender has to win every time , which is much much harder, if not impossible.
Defender does not have to win every time. That is what defense in depth is all about. Multiple lines of defense.
No matter how many lines of defense in depth you have, protecting the surface area of a product or service is always going to be harder than attacking it.
Re: Increasing Google and Alphabet VRP rewards
#96Re: Increasing Google and Alphabet VRP rewards
#97Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.
They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…
https://github.com/mdowd79/presentations/blob/main/bluehat20...
Re: Increasing Google and Alphabet VRP rewards
#98Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.
https://shubs.io/high-frequency-security-bug-hunting-120-day...
Re: Increasing Google and Alphabet VRP rewards
#99Re: Increasing Google and Alphabet VRP rewards
#100Earlier quoted context omitted.
There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/
No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.