[HN Gopher] Google paid $10M in bug bounty rewards last year
       ___________________________________________________________________
        
       Google paid $10M in bug bounty rewards last year
        
       Author : mikece
       Score  : 48 points
       Date   : 2024-03-12 17:27 UTC (5 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | xeckr wrote:
       | Probably averting billions in damage.
        
         | robertlagrant wrote:
         | Yeah, smart, and contributing to the commons. As it should be.
        
           | xeckr wrote:
           | I think it's still pretty clear that the bug hunters are
           | getting the short end of the stick.
        
             | tptacek wrote:
             | In what way? If they're not getting a market offer from
             | Google, they don't have to participate.
        
       | anonu wrote:
       | Doesn't seem like a lot of money, either in aggregate or to
       | individuals.
        
       | jobs_throwaway wrote:
       | anyone have data on comparable companies' bug bounty payouts?
       | $10m seems like a drop in the bucket for an org worth nearly $2
       | trillion, but its hard to say without seeing what similar-size
       | companies do
        
         | jsnell wrote:
         | Totally comparable to the amounts paid out by $3 trillion
         | companies:
         | 
         | Apple: https://security.apple.com/blog/apple-security-bounty-
         | upgrad... ($20M in 2.5 years)
         | 
         | Microsoft: https://msrc.microsoft.com/blog/2023/08/microsoft-
         | bug-bounty... ($14M in a year)
        
       | htrp wrote:
       | Probably a really cheap cost for security research recruitment.
       | 
       | That's the recruiter cost for 200 security personnel.
        
         | reaperman wrote:
         | or the annual salary of 10 really, really good security
         | engineers at Google.
        
       | neilv wrote:
       | One way to look at it is a small price to pay, relative to the
       | cost of those vulnerabilities being discovered and exploited in
       | ways that cause major brand damage, negligence liabilities, and
       | regulatory pressure.
       | 
       | (Though, as developers, we shouldn't forget: _not_ continuously
       | creating vast numbers of defects in the first place would be
       | better for society, and for the professionalism of our field.)
        
         | Workaccount2 wrote:
         | Google spending $10M is roughly equivalent to their share price
         | moving 1/10 of 1 penny. Compare this to the cost of an exploit
         | making into the wild and causing potentially hundreds of
         | billions in value being lost.
         | 
         | From this perspective one could make a reasonable argument that
         | the bounty should be far higher.
        
           | tptacek wrote:
           | Exploits have a market clearing price, and for most
           | vulnerabilities, that price is drastically lower (often
           | asymptotically approaching zero) than technologists not i the
           | field assume.
           | 
           | Exploits can also _cause damage_ , and the scale of damage
           | inflicted doesn't have to connect to the market clearing
           | price; that's a valid point to make. But it doesn't
           | necessarily follow from it that researchers should get a
           | bigger cut of the hypothetical damages.
           | 
           | The most essential thing to understand about
           | FAANG/hyperscaler bug bounty programs is: the people running
           | these programs are _incentivized to pay out more money_.
           | Google (or at least, the people running the bounty programs)
           | would be happier i they were paying $20MM instead of $10MM.
           | But they modulate prices to attract more and better
           | submissions, and they can 't raise prices "just because".
        
           | Veserv wrote:
           | Critical exploits make it into the wild all the time. At
           | worst they cause a tiny, temporary dip in stock price and
           | frequently they cause the stock price to go up long term due
           | to publicity. That is why they only spend 10 M$ on bounties,
           | there is literally no point to spending more because the ROI
           | is garbage.
           | 
           | The only reason to run a bug bounty program is optics. You
           | run a program paying out paltry amounts so that when your
           | security is routinely completely compromised you can say you
           | were a upstanding company who tried to work with upstanding
           | offensive researchers. It is those evil, dastardly criminals
           | funded by _insert government here_ using  "advanced",
           | "unique" techniques and who can stop that? Therefore it is
           | not our fault, now go keep buying our products and stock even
           | though we have made no changes to our incompetent security
           | process. Works every time.
        
           | mrkramer wrote:
           | >Compare this to the cost of an exploit making into the wild
           | and causing potentially hundreds of billions in value being
           | lost.
           | 
           | Hundreds of billions?! What software vulnerability ever
           | caused financial loss even close to that? Although you are
           | right, that if your products are used on millions of devices
           | you want to earn and keep users' trust. That's what Bill
           | Gates and Microsoft realized 20 years ago[1][2] after lots of
           | Microsoft's users and their devices got wrecked by Windows
           | worms.
           | 
           | [1] https://en.wikipedia.org/wiki/Trustworthy_computing [2]
           | https://www.microsoft.com/en-
           | us/security/blog/2022/01/21/cel...
        
             | rKarpinski wrote:
             | > Hundreds of billions?! What software vulnerability ever
             | caused financial loss even close to that?
             | 
             | Does seem high but Cambridge Analytica Facebook scandal
             | comes close if were talking about market cap they (it-least
             | temporarily) lost over 100B [1]
             | 
             | [1] https://www.theguardian.com/technology/2018/jul/26/face
             | book-...
        
               | mrkramer wrote:
               | Cambridge Analytica was Facebook's screw-up on their
               | users' data usage policy; basically Facebook enabled
               | developers through Facebook's API and Social Graph
               | integration siphoning of people's data for nefarious
               | reasons. Could this be caught by public crowdsourced bug
               | hunting project? Probably not or perhaps, if you would
               | think about ways on how you can use people's social
               | signals and connections to create some sort of privacy
               | invading or flat out criminal products.
               | 
               | I remember that after Cambridge Analytica, Google started
               | limiting their API scope as well.
               | 
               | I wouldn't classify Cambridge Analytica scandal as a
               | software vulnerability but as a reckless data usage
               | policy on the Facebook's part.
        
               | rKarpinski wrote:
               | > I wouldn't classify Cambridge Analytica scandal as a
               | software vulnerability but as a reckless data usage
               | policy on the Facebook's part.
               | 
               | In addition to the reckless policy (and oversight), I
               | assumed they were also violating the TOS & SLA's etc of
               | the FB api's they used.
        
           | baxtr wrote:
           | How can one quantify this?
        
       | readyplayernull wrote:
       | The question is how much they saved not employing more
       | infosec/research staff?
        
         | missedthecue wrote:
         | $10m is only about 20-30 engineers so probably quite a lot of
         | money as saved
        
         | tptacek wrote:
         | Google has one of the best staffed and best regarded security
         | teams in the entire world; that consideration is not limited
         | simply to the technology industry, but to all organizations
         | globally. They are outgunned by the US Government, of course,
         | but they in turn probably outgun the security teams of many
         | other significant countries.
        
           | JamesBarney wrote:
           | I had assumed Google/Microsoft/Apple had better security
           | teams than the US Government because they could pay so much
           | more. I wouldn't be surprised if maybe the NSA had better red
           | teams than Google, but I'm honestly surprised the US
           | Government outguns Google outside of that.
        
       | sigma5 wrote:
       | seeing these number makes me wonder if bounty hunting these days
       | is more profitable that working on a side project
        
       | blitzar wrote:
       | Google also spent $10M for in flight catering on their private
       | jets last year.
        
       | wfh wrote:
       | Original blog post that the article was seemingly based on
       | https://security.googleblog.com/2024/03/vulnerability-reward...
        
       ___________________________________________________________________
       (page generated 2024-03-12 23:02 UTC)