News: 1627455490

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google revamps bug bounty program

(2021/07/28)


Google has revealed that its bug bounty program – which it styles a "Vulnerability Reward Program" – has paid out for 11,055 bugs found in its services since 2010.

11,055 bugs seems like a lot, but it's not out of step with other vendors. Microsoft's monthly Patch Tuesday packages regularly fix over 100 flaws, while Oracle's quarterly patch collections often contain well more than 300 pieces of corrective code. Across 11 years, the two abovementioned vendors would also produce over 11,000 bugs.

Google's disclosure — which appeared in a Tuesday [1]post that also revealed the company has paid out over $29 million in bug bounties to 2022 researchers — came with news that the ad giant has decided its vulnerability reward program (VRP) needs a major makeover.

[2]

The company has renamed it "Bug Hunters", whipped up a sparkling new [3]site , and brought together programs that once covered discrete VRPs for Google, Android, Abuse, Chrome and Play.

[4]Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos

[5]So nice of China to put all of its network zero-day vulns in one giant database no one will think to break into

[6]AWS launches BugBust contest: Help fix a $100m problem for a $12 tshirt

[7]Dutch watchdog fines Booking.com €475k after it kept customer data thefts quiet for more than 3 weeks

The new site offers a "single intake" for bug reports across all of the above, plus "a bit of healthy competition through gamification, per-country leader boards, awards/badges for certain bugs and more!"

That's Google's exclamation mark, by the way.

[8]

The data-harvesting company has also revamped individual leader boards, and suggested that prominent positions on those charts don't hurt if you're applying for a gig in the VRP team.

Also improved is a "streamlined publication process" – because security researchers "know the value that knowledge sharing brings to our community". And if you're new to the bug-hunting game or looking to hone your skills, there's a brand new [9]Bug Hunter University .

[10]

No, really. That's what it's called.

The post also served as a reminder that Google pays out for patches to open-source software as well as research papers on FOSS security. ®

Get our [11]Tech Resources



[1] https://security.googleblog.com/2021/07/a-new-chapter-for-googles-vulnerability.html

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQEqsnwwlKkJBIhczPZSrQAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://bughunters.google.com/

[4] https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/

[5] https://www.theregister.com/2021/07/15/china_vulnerability_law/

[6] https://www.theregister.com/2021/06/25/aws_bugbust_contest/

[7] https://www.theregister.com/2021/04/01/booking_dot_com_fine/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQEqsnwwlKkJBIhczPZSrQAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://bughunters.google.com/learn

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQEqsnwwlKkJBIhczPZSrQAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



"11,055 bugs found in its services since 2010"

Mike 137

On average, that's about three a day. That makes me quite nervous.

Maths

elsergiovolador

29,000,000 / 11,000 = ~2,636 of their currency per bug

I mean why would anyone bother...

Dignity is like a flag. It flaps in a storm.
-- Roy Mengot