4 ms·
Ummm... no. If this is like a week's worth of work, you're looking at $250k annualized income, $125k after overhead. In practice, you're not finding a bug like
by wegs 6y ago
Ummm... no. If this is like a week's worth of work, you're looking at $250k annualized income, $125k after overhead.
In practice, you're not finding a bug like this every week.
The bug bounty programs were originally intended to give a white hat market alternative to the black hat and gray hat markets. They don't do that. If I find a bug, and I want profit, I'm much better off selling to my government than to Google.
One can only imagine the number of exploits the US, China, Russia, North Korea, etc. have in their cyber-warfare vaults.
Exploits compound. Often, two minor exploits make a major exploit.
- EE84M3i 6y agoAll I meant was that this is significantly better than other programs. I've seen similar bugs pay out in the hundreds.
- bitwize 6y agoIf everything were priced at its actual value, SV would collapse like a house of cards. The whole industry is based on obtaining for bargain basement prices engineering or research work which coukd be worth billions.
- gitanovic 6y agoThat's exactly why there is a black market for 0-day exploits... because they are worth more than what are paid by the companies owning those liabilities
- seastonATccs 6y agoI got a 5k payout from google for serious OAuth bypass bug. I'm not a security researcher so I wouldn't have any idea or really desire to sell something like this to a Government. But I'd have to agree that if I had publicly revealed the bug Goog would have lost magnitudes of business or possible fines from governments far above and beyond 5k.
- sam1r 6y agoBaller alert.
- seastonATccs 6y agoLol so far from it. This came from a bug assigned to me in JIRA like any other support ticket on any other bullshit day. Its just by the end of the day I realized I could access certain data from any gSuite domain. I submitted it through the bounty system as I didn't want it public in the issue tracker. I really just wanted the API fixed as we were getting shitted on by our customers...
- sam1r 6y agoBeautifully put.
- jimmaswell 6y agoEvery time someone gets a bug bounty there's someone saying it's not enough and it should have been a bajillion dollars instead. $5000 for a week's work is great and clearly it's working. Some points to consider are that there's risk involved dealing with the black market, including getting the payout in a way that doesn't trace back to you and legal liability if you're caught, a company has no reason to pay >=$x for an exploit that will cost them $x, and beyond that I suspect a lot of people simply feel better about telling the company about an exploit than selling it to criminals who will use it for extortion and theft.
- JamesSwift 6y agoSo lets say you are able to find one of these every other week. $130k pretax. But you are finding 26 different bugs that (judging on the responses in this comment section) require fairly clever thinking, and you are doing it consistently. I don't think companies owe it to researchers to exclusively supply their income, but I think theres room for improvement on the payout when most of the point is to deter selling on the black/gray market.
- twox2 6y ago$5K for a long tail bug like this ain't bad.