3 ms·
The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it
by esseph 1mo ago
The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...
- rglover 1mo agoThey should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).
- vlovich123 1mo agoCVE severity is a terrible way to do this. If you follow the cybersecurity space you should know why.
- rglover 1mo agoIt's a simple multiplier number and you can set a cap on it (and payout amounts). Where's the fire?
- vlovich123 1mo agoCVEs are handed out like candy for non issues, the severity rating system isn’t a serious evaluation of the actual severity (eg a vulnerable function may not even be compiled in), the scoring is inconsistent and subjective and frequently inflated to make the severity seem worse, and with the AI flood they have a massive backlog of handing out CVEs. Like look at CVEs curl dealt with at one point that were just completely bogus and given huge severity ratings to start with. But honestly if you’re the one proposing a “simple solution” maybe do some research yourself.
- rglover 1mo ago> But honestly if you’re the one proposing a “simple solution” maybe do some research yourself. It's an off the cuff idea on a nerd forum. Relax buddy.
- SteveNuts 1mo agoThat would create a perverse incentive to inflate the severity levels even more than they already are
- rglover 1mo agoIt doesn't have to. Just put a cap and say "we officially recognize 1-10" and be done with it.
- Barbing 1mo agoPre-flood, they didn’t pay more did they? > viewed it as insurance Of course. Beyond the ethics, the social obligation, sleeping well at night by compensating hardworking people fairly. “We can’t pay more or we’d have to hire more human reviewers” should never be a massive company’s line of thinking.
- r_lee 1mo agoit's such a drop in the bucket, it wouldn't make any difference
- mccr8 1mo agoIn fact, Google will pay you $250,000 for a full chain exploit. The CVE reported here is a renderer process vulnerability. Google used to pay more for those before the vulnpocalypse. Now, they are fixing hundreds of bugs per week that they find themselves. https://bughunters.google.com/about/rules/chrome-friends/chrome-vulnerability-reward-program-rules https://bughunters.google.com/about/rules/chrome-friends/chr...