[HN Gopher] Google paid $10M in bug bounty rewards last year
___________________________________________________________________
Google paid $10M in bug bounty rewards last year
Author : mikece
Score : 48 points
Date : 2024-03-12 17:27 UTC (5 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| xeckr wrote:
| Probably averting billions in damage.
| robertlagrant wrote:
| Yeah, smart, and contributing to the commons. As it should be.
| xeckr wrote:
| I think it's still pretty clear that the bug hunters are
| getting the short end of the stick.
| tptacek wrote:
| In what way? If they're not getting a market offer from
| Google, they don't have to participate.
| anonu wrote:
| Doesn't seem like a lot of money, either in aggregate or to
| individuals.
| jobs_throwaway wrote:
| anyone have data on comparable companies' bug bounty payouts?
| $10m seems like a drop in the bucket for an org worth nearly $2
| trillion, but its hard to say without seeing what similar-size
| companies do
| jsnell wrote:
| Totally comparable to the amounts paid out by $3 trillion
| companies:
|
| Apple: https://security.apple.com/blog/apple-security-bounty-
| upgrad... ($20M in 2.5 years)
|
| Microsoft: https://msrc.microsoft.com/blog/2023/08/microsoft-
| bug-bounty... ($14M in a year)
| htrp wrote:
| Probably a really cheap cost for security research recruitment.
|
| That's the recruiter cost for 200 security personnel.
| reaperman wrote:
| or the annual salary of 10 really, really good security
| engineers at Google.
| neilv wrote:
| One way to look at it is a small price to pay, relative to the
| cost of those vulnerabilities being discovered and exploited in
| ways that cause major brand damage, negligence liabilities, and
| regulatory pressure.
|
| (Though, as developers, we shouldn't forget: _not_ continuously
| creating vast numbers of defects in the first place would be
| better for society, and for the professionalism of our field.)
| Workaccount2 wrote:
| Google spending $10M is roughly equivalent to their share price
| moving 1/10 of 1 penny. Compare this to the cost of an exploit
| making into the wild and causing potentially hundreds of
| billions in value being lost.
|
| From this perspective one could make a reasonable argument that
| the bounty should be far higher.
| tptacek wrote:
| Exploits have a market clearing price, and for most
| vulnerabilities, that price is drastically lower (often
| asymptotically approaching zero) than technologists not i the
| field assume.
|
| Exploits can also _cause damage_ , and the scale of damage
| inflicted doesn't have to connect to the market clearing
| price; that's a valid point to make. But it doesn't
| necessarily follow from it that researchers should get a
| bigger cut of the hypothetical damages.
|
| The most essential thing to understand about
| FAANG/hyperscaler bug bounty programs is: the people running
| these programs are _incentivized to pay out more money_.
| Google (or at least, the people running the bounty programs)
| would be happier i they were paying $20MM instead of $10MM.
| But they modulate prices to attract more and better
| submissions, and they can 't raise prices "just because".
| Veserv wrote:
| Critical exploits make it into the wild all the time. At
| worst they cause a tiny, temporary dip in stock price and
| frequently they cause the stock price to go up long term due
| to publicity. That is why they only spend 10 M$ on bounties,
| there is literally no point to spending more because the ROI
| is garbage.
|
| The only reason to run a bug bounty program is optics. You
| run a program paying out paltry amounts so that when your
| security is routinely completely compromised you can say you
| were a upstanding company who tried to work with upstanding
| offensive researchers. It is those evil, dastardly criminals
| funded by _insert government here_ using "advanced",
| "unique" techniques and who can stop that? Therefore it is
| not our fault, now go keep buying our products and stock even
| though we have made no changes to our incompetent security
| process. Works every time.
| mrkramer wrote:
| >Compare this to the cost of an exploit making into the wild
| and causing potentially hundreds of billions in value being
| lost.
|
| Hundreds of billions?! What software vulnerability ever
| caused financial loss even close to that? Although you are
| right, that if your products are used on millions of devices
| you want to earn and keep users' trust. That's what Bill
| Gates and Microsoft realized 20 years ago[1][2] after lots of
| Microsoft's users and their devices got wrecked by Windows
| worms.
|
| [1] https://en.wikipedia.org/wiki/Trustworthy_computing [2]
| https://www.microsoft.com/en-
| us/security/blog/2022/01/21/cel...
| rKarpinski wrote:
| > Hundreds of billions?! What software vulnerability ever
| caused financial loss even close to that?
|
| Does seem high but Cambridge Analytica Facebook scandal
| comes close if were talking about market cap they (it-least
| temporarily) lost over 100B [1]
|
| [1] https://www.theguardian.com/technology/2018/jul/26/face
| book-...
| mrkramer wrote:
| Cambridge Analytica was Facebook's screw-up on their
| users' data usage policy; basically Facebook enabled
| developers through Facebook's API and Social Graph
| integration siphoning of people's data for nefarious
| reasons. Could this be caught by public crowdsourced bug
| hunting project? Probably not or perhaps, if you would
| think about ways on how you can use people's social
| signals and connections to create some sort of privacy
| invading or flat out criminal products.
|
| I remember that after Cambridge Analytica, Google started
| limiting their API scope as well.
|
| I wouldn't classify Cambridge Analytica scandal as a
| software vulnerability but as a reckless data usage
| policy on the Facebook's part.
| rKarpinski wrote:
| > I wouldn't classify Cambridge Analytica scandal as a
| software vulnerability but as a reckless data usage
| policy on the Facebook's part.
|
| In addition to the reckless policy (and oversight), I
| assumed they were also violating the TOS & SLA's etc of
| the FB api's they used.
| baxtr wrote:
| How can one quantify this?
| readyplayernull wrote:
| The question is how much they saved not employing more
| infosec/research staff?
| missedthecue wrote:
| $10m is only about 20-30 engineers so probably quite a lot of
| money as saved
| tptacek wrote:
| Google has one of the best staffed and best regarded security
| teams in the entire world; that consideration is not limited
| simply to the technology industry, but to all organizations
| globally. They are outgunned by the US Government, of course,
| but they in turn probably outgun the security teams of many
| other significant countries.
| JamesBarney wrote:
| I had assumed Google/Microsoft/Apple had better security
| teams than the US Government because they could pay so much
| more. I wouldn't be surprised if maybe the NSA had better red
| teams than Google, but I'm honestly surprised the US
| Government outguns Google outside of that.
| sigma5 wrote:
| seeing these number makes me wonder if bounty hunting these days
| is more profitable that working on a side project
| blitzar wrote:
| Google also spent $10M for in flight catering on their private
| jets last year.
| wfh wrote:
| Original blog post that the article was seemingly based on
| https://security.googleblog.com/2024/03/vulnerability-reward...
___________________________________________________________________
(page generated 2024-03-12 23:02 UTC)