3 ms·
I think if it worked more broadly (I couldn't test without risk at that point) you could make decent money off of this just through affiliate programs. I've be
by TomAnthony 9y ago
I think if it worked more broadly (I couldn't test without risk at that point) you could make decent money off of this just through affiliate programs.
I've been doing research like this for 5+ years, and you go in knowing most if it won't lead to anything. I'd hoped for more, but I could have simply failed again and got nothing! :)
As I've said below, I'd have reported it anyway even without a bounty; however I probably wouldn't have done the research in the first place were there not a bug bounty programme.
I've previously had 2 bounties from Google. One was an easy find and was also $1337. The other was more technical but still straight forward and also played to SEO and got $5000 - in that instance Matt Cutts was involved and I believe advocated for the amount (thanks, Matt!). This was far more impactful than that other issue, and more directly monetisable.
- downandout 9y agoI do have to ask...were you at all tempted to try to monetize this? The guys in the BHW thread aren’t wrong about the potential. I applaud you for taking the high road, I’m just curious if the thought of giving away probably low six figures/day for $1337 nags at you at all.
- TomAnthony 9y agoIt is a good question. I wouldn't have monetised this and would have still report it, because doing so would hurt legitimate businesses (by pushing them out of the results). However, I have to admit it does nag at me a bit that the bounty is so small - it is like they are trying to send a message but I'm just not sure what it is! I have done loads of research over the last 5 years (this exploit took me a couple of months to craft) and most comes to nothing, and then when I do find something big that the bounty is so small is frustrating. A bigger bounty would have made a meaningful difference to me (kids+no savings!). The broader issue is how this may play to motivating people to discover/report these sorts of issues in the future. I have a couple of other ideas for search related attacks, but am not sure I'm going to explore them any longer.
- downandout 9y agoThe broader issue is how this may play to motivating people to discover/report these sorts of issues in the future. I have a couple of other ideas for search related attacks, but am not sure I'm going to explore them any longer. Agreed. Relative to the value of exercising this exploit, your bounty is missing a few 0’s at the end. I hope that you at least get some professional credit for this, and that it translates to a financial boost. You certainly deserve it for discovering something like this and doing the right thing with it.
- emerongi 9y agoThis is a straight-up 100k-500k bug. If I were to discover this bug and know I'd only get $1k and be a "good guy" vs. getting millions, well... The fact is that these bug bounty programs should start paying competitive prices. They can lowball it by 10x-20x at most, but lowballing by 1000x leads to people just giving up their ethics.
- um_ya 9y agoAlmost as if a bug bounty program should show the effect of the bug before explaining how it works. Then, Google will be more inclined to pay more if it wants the info on how the bug works.
- brownbat 9y agoThe cybersecurity research community should solicit some sort of endowment, like a Nobel Prize, that goes to deserving WH bug discoveries each year. Uncovering bugs that aren't attached to bug bounty programs still has external benefits for the security community. Thanks for your work here, even without such a program.