4 ms·
There must be something I am missing, because I dont understand how underpaid most bug bounty programs are. If I ran Googles program, I would immediately 10x a
by ds 5y ago
There must be something I am missing, because I dont understand how underpaid most bug bounty programs are.
If I ran Googles program, I would immediately 10x all payments, unironically. Yes, that means paying 1 million bucks for something you previously paid 100k for. Drop in the bucket. You also get a ton more eyeballs on you, letting you patch everything ASAP.
But they dont do this. I dont know why. Security through obscurity? I suppose that works if you are myspace.com in 2021. Nobody likely gives a shit to try and hack it, but at the end of the day this is still google so that really doesn't apply.
The downside of not paying handsomely is people realize they can make more money selling to third party vendors, (which some do) then every once in a while you get a bad PR story showing that your stuff was hacked and exploited for months/years and it potentially knocks a few points off your stock price.
Money is really the end all be all. If you pay more than third party vendors, I can see almost no reason people would sell to them. At that point, your only adversary's are gov employees of nation states and the staff of companies dedicated to finding vulnerabilities.
- bsamuels 5y agoBug bounty prizes are set to encourage a certain quantity of bugs to be reported. If you offer 10x as much, your triage channels will get overwhelmed and you'll have to deal with a bunch of hostile researchers and development teams who hate your guts because you just blocked their next 2 sprints. If a bug bounty program is effective, then the payouts should trend up slowly over time as your security program becomes more efficient and produces more secure code. It's important to remember that purpose of bug bounty programs is not to reduce the number of bugs in the code base - it is a validation measure to check whether your controls are effective or if additional controls need to be added elsewhere.
- gibba999 5y agoAs a customer, I'd be okay with dev teams being blocked for their next 2 sprints if it meant security I can trust. Google Docs, Search, and Mail do little in 2021 that I need that they didn't do in 2016. There's a lot more churn than bona fide improvement. Most tech just doesn't change that much. Heck, I'd take an online version of WordPerfect 7 from 1996 if it was trustworthy. That's a quarter-century. There's nothing Google Docs does, aside from collaboration, that I need that WP7 didn't do. On the other hand, I strongly distrust Google to maintain my data securely. As far as I can tell, aside from backwards compatibility/legacy reasons, the major reason people use Office 365, for better or worse, are issues like compliance and security. Security bugs ought to be sold to Google, found, and fixed. They shouldn't be sold to a ransomware gang or a government.
- izacus 5y ago> As a customer, I'd be okay with dev teams being blocked for their next 2 sprints if it meant security I can trust. As an enterprise customer of said products, you'd probably switch to the nearest competitor who offers more features and better UX as soon as the "secure" option would lag behind. That's what numbers show.
- gibba999 5y agoWhat numbers? My experience is the opposite.
- remus 5y ago> On the other hand, I strongly distrust Google to maintain my data securely. As far as I can tell, aside from backwards compatibility/legacy reasons, the major reason people use Office 365, for better or worse, are issues like compliance and security. Out of interest, why do you distrust google to maintain your data securely? Having done no actual research, my impression is that google has a pretty good record when it comes to security (though obviously not perfect).
- gibba999 5y ago* Android loses security updates after a short amount of time, with no notification to the user. Lots of people run insecure devices and have been susceptible to ransomware attacks. * Chromebooks expire likewise. It does better on notifying users, but many Chromebook users can't afford to upgrade. Google has planned obsolesce to increase sales, but in a particularly security-unfriendly way. * Google has a long history of withholding security features based on tiered enterprise pricing, especially with regards to Google Workspace / Google Docs. I understand tiered pricing, but having users intentionally be unable to trace back attacks is bad for the internet at large. I know cases where bad actors weren't traced down due to Google charging for basic security features. ... and so on. I could step through minor issues, and I could give large numbers of them, but that'd be a blog post. That sort of general apathy for user security is omnipresent in Google's culture. Google has an excellent track record in its own corporate security, and is paranoid about IP and internal data. That doesn't translate to my IP and data. A lot of this comes from looking at customers at statistics. My value to Google are my eyeballs. If my computer is compromised, and I switch vendors, Google's cost is one user's worth of ad revenue, which is a manageable risk. Google doesn't at all care about the security of its customers. Unfortunately, that attitude carries over to the B2B space, not to mention increasing risks to normal Google users.
- askesisdev 5y agoThird party vendors don't buy vulnerabilities on Google's infrastructure and web services. Third parties like Zerodium are interested in 0days on Android, iOS, Windows, Chrome... You could try to sell it to criminal organizations or monetizing the vulnerability yourself, but it doesn't make any sense to be in that situation if you are making six figures as a bug bounty hunter.. even if you didn't have any ethical qualms regarding such acts.
- mtnGoat 5y agoFalse: Seven figures trumps six. Think like a mercenary.