6 ms·
The author participates in bug bounties and Google have a $250k reward for certain vulnerability types so perhaps it’s more “sent me $250k without notifying me
by phphphphp 4y ago
The author participates in bug bounties and Google have a $250k reward for certain vulnerability types so perhaps it’s more “sent me $250k without notifying me about my bounty submission” than “randomly”
https://bughunters.google.com/about/rules/6171833274204160/android-and-google-devices-security-reward-program-rules https://bughunters.google.com/about/rules/6171833274204160/a...
Alternatively, they have his bank details from participation in bug bounties and he was mistakenly sent someone’s Ad revenue.
https://support.google.com/admanager/answer/2731686?hl=en https://support.google.com/admanager/answer/2731686?hl=en
- capableweb 4y agoSeems to be a transfer from some ad-related business on Google's side: > Electronic Funds Transfer (EFT) directly deposits your Ad Exchange revenue into your bank account [...] the deposit will be labeled as one of the following [...] Google LLC EDI PYMNTS https://support.google.com/admanager/answer/2731686?hl=en https://support.google.com/admanager/answer/2731686?hl=en
- jefftk 4y agoThat ad payments arrive labeled "Google LLC EDI PYMNTS" doesn't tell us that bug bounty payments would not also arrive with that label. In this case, the text probable means "[Google the Company] [Electronic Data Interchange] [Payments]" and I wouldn't expect that to be ads-specific? (Disclosure: I used to work on ads at Google, but don't know anything internal here)
- iancarroll 4y agoGoogle makes every security researcher sign up as a vendor inside their procurement system, SAP Ariba. Seems likely that a payment for another vendor got misdirected by the procurement team as a result of this.