206 ms·
Increasing Google and Alphabet VRP rewards
- lallysingh 2y agoQuestion for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time? I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.
- byearthithatius 2y ago> I'm wondering if bounty programs effectively form a low-paid gig economy for programmers. Most certainly, or those who can't get jobs because of their record but know how to code.
- doe_eyes 2y agoThere's a lot of participation from India and other lower-income countries. Not a bad thing - it keeps a fair number of talented school-age kids gainfully employed, and it's a lot more dignified than being paid peanuts for solving captchas.
- borski 2y agoThey pay much less than selling the equivalent vulnerabilities to unnamed entities (there are brokers for it). But, and this is the important part, in this case there is zero moral quandary, whereas when selling an 0day there is a significant moral question depending on who you’re selling to. Some people do make it their full time gig, but it’s fairly unpredictable is the issue; much like “gig work,” you’re not guaranteed to find a vuln, and the timing between findings is going to be inconsistent at best.
- Ozzie_osman 2y ago> in this case there is zero moral quandary And zero legal quandary.
- borski 2y agoAlso true.
- HPsquared 2y agoFinding a vuln and selling to Google is also presumably something you can put on your resume. Like a portfolio piece.
- borski 2y agoTrue. It’s not likely to be a huge difference-maker, but it certainly belongs on a resume more than “sold 0day to foreign governments” heh
- lallysingh 2y agoFair enough, but do people claim them after finding them by accident? Or do people see a bounty and then put in up to X hours of effort (before either succeeding or giving up)? Does that model end up with a reasonable hourly rate? I'm trying to figure out the labor-side economics of this. Generally the supply side is getting a massive discount on these vulnerabilities compared to their potential costs. Although perhaps the discount applies is appropriate considering how few vulnerabilities do result in observable expense.
- borski 2y agoBoth. And the issue about trying to relate it to an hourly rate is the immense unpredictability. Some months (and some companies) may have a lot of vulns in a new product and it’s open season for a bit, but then it slows down, and you’re constantly hunting for new bounties. It’s not entirely unlike a proper consulting gig, where half your time is spent doing the job, and half your time is spent building a pipeline of future work.
- 0cf8612b2e1e 2y agoOnly economical way is to collect a salary from the NSA while hunting for the exploits. Otherwise seems too much of a lottery on both discovering a valuable exploit and getting a sufficient payout.
- edent 2y agoYes. I've claimed a few Bug Bounties after accidentally discovering them. For example https://shkspr.mobi/blog/2021/12/responsible-disclosure-chrome-security-bug-lets-tabs-draw-over-each-other/ https://shkspr.mobi/blog/2021/12/responsible-disclosure-chro... It is uncertain work. As well as finding the exploit, you've got to write it up in such a way that it is convincing to the people reading it. Then you have to argue with them if they don't accept it. You have to pay currency conversion fees and, depending on where you live, tax on income. That's a lot of work. But it is significantly easier (I imagine) than selling to the mafia. The bad guys don't have a publicly available schedule of payments. And if they don't pay, you can't complain publicly.
- fullspectrumdev 2y ago
- doe_eyes 2y agoIt's also easier than "gray market" sales. Bug bounties pay for a wider variety of bugs, including plenty of stuff that's of no interest to your perhaps-Saudi buyers; and they don't require you to develop a weaponized exploit - "hey, I noticed this crashes" is often enough. Plus, less risk of waking up and finding out you've been sanctioned by OFAC or something like that.
- Ozzie_osman 2y agocurious why Saudi? Are they known to be prolific buyers of vulnerabilities?
- 3np 2y agoperhaps-Saudi-prob-Israel. (Israel is known to be prolific; many brokers and the whole industry on all sides has a lot of people and entities from Israel. Saudi is publically obv active due to stories like MSB pwning Bezos over Whatsapp)
- doe_eyes 2y agoThey're rich, don't hold civil liberties in high esteem, and don't have a lot of in-house expertise. So, yeah - along with some neighboring states, they're a buyer for tools they use to target journalists, dissidents, etc. China and Russia are on the same boat, but they are far more capable with in-house tech.
- borski 2y agoAlso, just to be clear - the US gov buys tons of zerodays.
- Ozzie_osman 2y agoOK i see, re-reading this with your top level post is "not all vulnerabilities are the type that could be bought by (insert state actor)", which makes sense (for some reason I thought you meant that they were buying the type of bugs that would end up getting reported to a BBP, but I just misread the original comment). And yes the Saudis definitely bought software from NSO Group but it's also been used by plenty of other governments, including half the EU...
- Thorrez 2y agoThere are brokers for website vulns? This presentation says there are brokers for clientside RCE vulns, but doesn't mention any brokers for website vulns. https://github.com/mdowd79/presentations/blob/main/bluehat2023-mdowd-final.pdf https://github.com/mdowd79/presentations/blob/main/bluehat20...
- borski 2y agoIt depends on the vuln and the need. For example, an XSS won’t net you very much, unless the buyer already has a browser RCE but needs a way to deliver it to a target they know uses a particular service or browser, and for that they may need an XSS. Still won’t net you as much as an RCE, but they do get bought sometimes.
- bkallus 2y agoMy experience participating in Google's program has been pretty good. The reward money is a nice supplement to my grad student stipend. I got a free trip to DEFCON out of it, too.
- xyst 2y agoIt's not worth it. Payout by default is at least 90+ days (or 3 months) after disclosure (this is standard operating procedure to give company time to fix vulnerability). Then some companies have some bullshit internal company procedure for payout ("only at the end of the quarter"). Some companies dangle the carrot of "higher payouts" but after an internal review by some fresh out of college, security bootcamp asshole. The committee downgrades it to a less severe vulnerability (ie, fuck you). The number of clueless individuals running these bug bounty programs is not worth it. The only reason most people do it is for the "fame" within the security community; or that occasional researcher that was just bored. Even worse, some companies (like South Korean companies) will not even pay out if you are not a citizen of the country. Makes no sense to me.
- 8organicbits 2y agoAgreed about boredom. There are times I've discovered issues incidentally, checked if the company had a bug bounty program. If they don't, I may chuck a vague email to security@, if they do I'll write something quick and take whatever they send. I've seen $3k once from this, but usually it's not enough to justify the time it takes to do the write up. There are far too many: out of scope, we already know, or other non-payment results.
- bink 2y agoI've been on both sides of bug bounties for many years. In truth, no one is offering a comparable bounty to what you can get selling exploits to a reseller. The closest would be Apple or Google with their million dollar bounties for cell phone exploits, but even that is likely underpaying. The real value of bug bounties is for less sensitive products that aren't really big targets for nation states. Startups with products that haven't seen wide deployment in sensitive industries, for example. There are many people who are perfectly happy getting "rep" and lower payouts for finding flaws in even the highly targeted applications, thankfully.
- 8organicbits 2y agoThe highest ROI for me were bugs I found incidentally. Like I was building a client for some auth scheme and... yikes the documentation made it clear they are vulnerable. No POC needed, mostly linked to the part of the spec they forgot. Bug finding requires theory building and guesswork. You're working blind. Reporting requires detailed technical writing and POC implementation. It's time consuming, so unless you're able to crank out findings or submit the same issue to multiple companies in parallel, the hourly rate will be low. Companies are flooded with low quality reports, so you really need to make the issue crystal clear. Private bug bounties are better because there's usually obvious issues, but you're racing to be first to report. Contract security work is much more predictable. Companies who "haven't thought about security before" are desperate for help. You can get more money building a system inventory, recommending updates for EOL systems, finding leaked passwords, and turning on firewalls. Basically engineering teams that know they have issues, but need someone external to make it clear to management that they need to invest in security. I've never failed to find at least one way to get system root or cloud admin rights on those contracts.
- Thorrez 2y agoHere's someone who found 120 bugs in 120 days (in addition to working full time). The bounties totaled $80k. https://shubs.io/high-frequency-security-bug-hunting-120-days-120-bugs/ https://shubs.io/high-frequency-security-bug-hunting-120-day...
- laweijfmvo 2y ago> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000 Should be $10m honestly.
- byearthithatius 2y agoRight, with something that powerful I would just sell the 0-day to highest bidder. Or even use it to commit some fraud. Taking over any @gmail account is a pretty powerful exploit that could lead to a lot of monetary compensation if used correctly. Scary Google only see's that is being worth 75k (way less than one year engineering salary) Not actually, I am not a law breaker;)
- zeroCalories 2y agoYou're both missing the point. Consider this: you're a big tech engineer, would you risk your career and many years in jail for 75k? Of course not. How about 5 million? Maybe you would... Big tech already has a massive problem with insider threats, they don't need to offer some of the most clever programmers in the world(their employees) a massive incentive to screw them over.
- c4wrd 2y agoThe point you are missing is that many of us do not have big tech careers. I am very fortunate to have a big tech career, but before I was hit by a stroke of luck, I was doing gig work paycheck to paycheck barely making ends meet. When you can’t see more than two weeks ahead in time, which you cannot do living paycheck to paycheck, you don’t think about the long term consequences because you are not capable of it. The incentive structure is too strong to sell zero days to any external party for those who have nothing to do all day but try to find exploits.
- dmurray 2y agoI think GP is suggesting an insider could introduce a bug, have a confederate "find" it, and split the money. At $5m I think more than a few big tech employees might decide to write themselves a new minivan.
- sirdarckcat 2y ago151515 is such an elitist number.. 3 * 13 * 37 * 3 * 5 * 7
- deleted 2y ago[deleted]
- xyst 2y agoHot Take: these bug bounty systems are a way to get cheap labor. Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements. Yea, a potential $150K bounty sounds is a shit ton of money for a person in a third world country. But for anybody else (given the same time spent finding the vulnerability), there is no financial motivation. Only "fame" via disclosure reports in the security community. This is the equivalent of a customer asking a professional photographer who is new on the scene to do their photography for free in exchange for "exposure". No, you aren't innovative. You are a cheap asshole.
- borski 2y agoThat’s not actually fair. Defense is very hard. Offense, by comparison, is much easier. An attacker has to win once, and then they’re in. A defender has to win every time, which is much much harder, if not impossible.
- shortsunblack 2y agoDefender does not have to win every time. That is what defense in depth is all about. Multiple lines of defense.
- borski 2y agoYou’re missing the point, either intentionally or unintentionally. No matter how many lines of defense in depth you have, protecting the surface area of a product or service is always going to be harder than attacking it.
- dmazzoni 2y agoIf it really was a way to get cheap labor, more companies would be doing it. As it is now, only the largest tech companies with the strongest security records are actually running good bug bounty programs. They have excellent, well-paid security teams and they put systems in place to incentivize all of their employees to write secure code. But, they know that (1) mistakes can still happen, (2) clever vulnerabilities can be discovered that get around code that was previously thought to be following all best practices, and finally they understand very well that (3) if they don't pay, others will. Unfortunately it's the companies that need it most - like AT&T and Experian - that have the worst track record with rewarding third-party security researchers.
- Topfi 2y agoI am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of magnitude more than 75k. Looked into it and am equally surprised to find that others, like Microsoft [0] also have such low bounties for these types of attacks. While providing such an exploit to the affected company has value beyond the bounty (potential job offers, media exposure, credibility, ethical considerations, etc.), weighing that up against life-changing money really makes it hard to fault those who take the more lucrative route of selling these to the highest bidder, whoever that may be. Seriously, Alphabet and Co. can afford more, especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k. [0] https://www.microsoft.com/en-us/msrc/bounty https://www.microsoft.com/en-us/msrc/bounty
- jcims 2y agoYou're making a bit of an assumption that the black market won't simply adjust to incentivize darkening the hat.
- iftheshoefitss 2y agoOn bro plus that side doesn’t pay taxes / it’s free cash anyway
- thfuran 2y agoOr at least that's what Al Capone thought.
- iftheshoefitss 2y agoOn fratello officer I filed my taxes I got the receipts right here lol
- 2y ago
- modeless 2y agoWe will know AGI is here when an agent can autonomously claim these bounties.
- zb3 2y agoI personally know at least one normally functioning person that didn't claim their $1k bounty due to the complexity of that process (also bureaucracy). Fortunately this is not a problem for me, because I couldn't find anything even if I wanted.
- neilv 2y agoSo if you find several catastrophic vulnerabilities each year, then you can make as much as one of the many people whose jobs it was not to create those vulnerabilities in the first place? :)
- borski 2y agoYes, but you only have to succeed once. They have to succeed every time, which is a much much harder proposition.
- pizzalife 2y agoThis is still not nearly enough to reach parity with market prices. Try offering a few million.
- saagarjha 2y agoIf they do that they should also raise their standards to match, no?
- tkz1312 2y agoThese amounts are hilariously low. $150k for a full gmail account takeover is peanuts compared to the potential impact, and the $4k for PII leak on nest.com is frankly just insulting.
- nothrowaways 2y ago151515.151