4 ms·
Hey folks, I am one of the co-founders of the Vulnerability Reward Program at Google. It's one of the longest-running and most generous programs of this kind:
by f- 13y ago
Hey folks,
I am one of the co-founders of the Vulnerability Reward Program at Google. It's one of the longest-running and most generous programs of this kind: since 2010, we have paid out around $1M in rewards for more than 1,500 qualifying bug reports in web applications alone. We take great pride in keeping the process responsive, friendly, and hassle-free.
Of course, it takes just one bad experience to undo much of that. Tom's report is a valid issue. The reward panel - of which I am a member - decided that it did not meet the bar for a financial reward. I stand by this decision, but I think we should have been more forthcoming, precise, and responsive when communicating that. In other words, I think we messed up.
PS. If you ever run into any problems of this type - or just want a friendly soul to chat - please do not hesitate to poke me at lcamtuf@google.com :-)
- schackbrian 13y agoTom Van Goethem makes a strong case that this is a security vulnerability and it does deserve an award. Can you explain why not?
- adobkin 13y agoThis type of vulnerability can be used to aid phishing attacks but it cannot be directly exploited by an attacker to obtain or modify user data. Phishing attacks are not listed as qualifying in the Program Rules http://www.google.com/about/appsecurity/reward-program/ http://www.google.com/about/appsecurity/reward-program/ although they are evaluated as security issues on a case by case basis. In this case a bug was filed, but it took some prodding to get it fixed.
- deleted 13y ago[deleted]
- f- 13y agoI think it's a valid security bug report. We welcome all reports of security vulnerabilities, we try to fix them quickly, and we credit the researchers - but we offer rewards only for higher-impact flaws. You can check out this page for more info: http://www.google.com/about/appsecurity/reward-program/ http://www.google.com/about/appsecurity/reward-program/ In this context, phishing issues are tricky. Because many of our products simply have to do things such as displaying snippets of potentially attacker-controlled text and multimedia, we try to evaluate phishing concerns on a case-by-case basis. In essence, we ask ourselves how easy it would be to exploit a particular behavior to mount a convincing attack. My take on this bug is that the attack vector is severely constrained in well-behaved e-mail clients; and that in badly-behaved clients, the existing exposure is already considerably worse than any incremental hazard caused by this flaw. It's valid and worth fixing - but does not quite meet the bar for the reward tiers set up for higher-impact bugs.
- dasil003 13y agoSo chuck him a C note and move on. I don't think it's worth the bad PR to quibble over what is clearly a security bug no matter how minor. HTML injection is sort of like the bike shed of security vulnerabilities, every web developer understands it, so you'll get a perverse amount of attention and discussion on it.
- f- 13y agoIn essence, we have a reward structure that we think is internally consistent, attracts the right sorts of research, and makes an optimal use of our resources - and we try to apply it fairly. Here, we handled the communications poorly, and I think it's OK to call us out on that. In fact, I think it would be wrong to offer a reward in hopes of buying silence from the reporter :-)
- tomvangoethem 13y agoI don't think that giving me some money would have refrained me from writing this blog post. The main issue here is that it was not recognized as security sensitive, and would most likely not be fixed if I didn't insist on it.
- crocowhile 13y agoWhat happens in the gmail web interface?
- kcbanner 13y agoOne would assume when he says "well-behaved e-mail clients", he was including his own company's product.
- tomvangoethem 13y agoHow would you describe a well-behaved e-mail client with regards to this vulnerability? The phishing attack I described in my blog post affects all e-mail clients that are able to render HTML and CSS. As for rendering remotely included CSS, this was not necessary, as one might as well include a <style> element. If you are referring to just GMail as a well-behaved e-mail client, you are most likely correct that it wouldn't be possible to create a legit-looking phishing e-mail (as GMail only allows in-line styles). I think that most other e-mail clients allow the use of <style> or <link> in e-mails. The screenshot of the "phishing e-mail" in the blog post came from Mail.app (version 6.5) I intentionally did not classify this vulnerability as "Cross-Site Scripting", although XSS vulnerabilities also rely on injecting HTML content, as the main impact here was not the execution of Javascript code in the user's e-mail client, but rather changing the visual output of an e-mail so it can be used for phishing.
- iamshs 13y agoTom states about monetary compensation, "Even if this vulnerability doesn’t qualify for a reward, I strongly believe that it should be fixed promptly to protect end users." But then you guys are experienced, so maybe know more about the impact. {1500 bug reports sure earns you that (and it shows :p)} I would like to hear your side of the story.
- Zoomla 13y agoAnyone participating in this program are cheap employees if you look at it from Google's perspective.
- _r5wf 13y agoCome on now. One guy is complaining and you made it look a hacker sweat-shop. You don't like the bounty, don't participate. As simple as that.
- skeletonjelly 13y agoSure. A sweatshop with voluntary arrival and departure times.
- Zoomla 13y agoit doesn't matter if you get paid or not... the amount is too small for the risk you are taking, unless it's a hobby. But I think that most of these hackers work for free and never get paid (and also don't get any of the benefits from working directly for Google).
- tomvangoethem 13y agoSeems there is some misconception here: 1. I was not complaining that I did not get paid for this bug, but that different Bug Bounty programs have different thresholds on whether a vulnerability qualifies for a monetary reward. This seems like useful information for someone who would like to make a living out of bounty-hunting. 2. Even though I participate in these bounty programs as a hobby, which is about 1-2 days per month, I was already awarded generously. If I did this full-time, I would expect to earn a great deal more than when I would be working directly for Google (unless they have crazy wages)