Live data from Hacker News

Increasing Google and Alphabet VRP rewards

bughunters.google.com

91–100 of 102 posts

Re: Increasing Google and Alphabet VRP rewards

#91

Earlier quoted context omitted.

Maybe these bounties are intentionally set to be roughly comparable to annual salaries. A very high bounty might encourage developers to plant backdoors instead, a la cobra effect: https://en.wikipedia.org/wiki/Perverse_incentive

Current or former employment is almost always a disqualifier for a bounty payout.

Yea but I didn’t find the bug. My buddy Jim did.

Re: Increasing Google and Alphabet VRP rewards

#92
post #24

I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of…

You might find these slides on the 0day market interesting https://github.com/mdowd79/presentations/blob/main/bluehat20... Unfortunately the talk wasn’t recorded but he did do a follow up interview on a podcast called Security, Cryptography, Whatever

Skip to the end if you want to see the numbers.

Re: Increasing Google and Alphabet VRP rewards

#93

Earlier quoted context omitted.

curious why Saudi? Are they known to be prolific buyers of vulnerabilities?

They're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc. China and Russia are on the same boat, but they are far more capable with in-house tech.

NSA banking EternalBlue was the reason for Wannacry ransomware proliferation, which killed people due to downtime of hospital systems.

Re: Increasing Google and Alphabet VRP rewards

#94
post #48
post #21

Hot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit t…

That’s not actually fair. Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in. A defender has to win every time , which is much much harder, if not impossible.

Defender does not have to win every time. That is what defense in depth is all about. Multiple lines of defense.

Re: Increasing Google and Alphabet VRP rewards

#95
post #48

Earlier quoted context omitted.

That’s not actually fair. Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in. A defender has to win every time , which is much much harder, if not impossible.

Defender does not have to win every time. That is what defense in depth is all about. Multiple lines of defense.

You’re missing the point, either intentionally or unintentionally.

No matter how many lines of defense in depth you have, protecting the surface area of a product or service is always going to be harder than attacking it.

Re: Increasing Google and Alphabet VRP rewards

#96
post #52

Earlier quoted context omitted.

On bro plus that side doesn’t pay taxes / it’s free cash anyway

Or at least that's what Al Capone thought.

On fratello officer I filed my taxes I got the receipts right here lol

Re: Increasing Google and Alphabet VRP rewards

#97
post #6

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

They pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guara…

There are brokers for website vulns? This presentation says there are brokers for clientside RCE vulns, but doesn't mention any brokers for website vulns.

https://github.com/mdowd79/presentations/blob/main/bluehat20...

Re: Increasing Google and Alphabet VRP rewards

#98

Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

Here's someone who found 120 bugs in 120 days (in addition to working full time). The bounties totaled $80k.

https://shubs.io/high-frequency-security-bug-hunting-120-day...

Re: Increasing Google and Alphabet VRP rewards

#100
post #58

Earlier quoted context omitted.

There are legitimate companies that buy exploits, not just ones that are on the dark web and pay in bitcoin. Just with a quick check I found Zerodium, which claims to offer bounties up to $2.5 million. They say their clients are "government institutions (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities." https://zerodium.com/

No one paying you $2.5 million for exclusive access to an exploit is planning to do anything even remotely "legitimate". On a good day, you might be selling to the CIA and helping catch bin Laden. On a bad day, you're selling to the Saudis and getting a journalist killed. I bet that "mainly" is doing a lot of heavy lifting in that sentence - plus, "Europe" includes Albania, Belarus, portions of Turkey, and more.

I meant legitimate in the sense that you won't go to jail, and you'll get an I9 for your taxes. I did not mean it as ethical, and I definitely agree with what you're saying there.
Post reply on HN