News: 1710352814

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Poking holes in Google tech bagged bug hunters $10M

(2024/03/13)


Google awarded $10 million to 632 bug hunters last year through its vulnerability reward programs.

The web goliath's 2023 total represents a slight dip compared to the [1]$12 million in bounties it paid the previous year. Hopefully this means more-secure products — not more researchers [2]turning to the dark side and making money selling exploits instead of disclosing them to vendors.

For comparison, consider that Microsoft paid out $13.8 million to 345 researchers between July 1, 2022, and June 30, 2023, according to Redmond's most recent rewards totals.

[3]

Google's 2023 highlights include newer reward categories, including finding flaws in its AI products and Android phone apps, plus a brand-new [4]Bonus Awards program that periodically pays out time-limited, extra rewards for specific vulnerability targets.

[5]

[6]

The single biggest reward last year hit $113,337, although the [7]year-in-review post doesn't say which program paid that amount and to whom.

Some of 2023's high-paying categories included Android VRP, which awarded more than $3.4 million to researchers who spotted Android device vulnerabilities. Google also last year [8]increased the max-reward amount to $15,000 for critical Android bugs, and launched a new [9]Mobile VRP that focuses on first-party Android apps.

[10]

Google also added Wear OS to the bounty program to encourage bug hunters to poke around in its smartwatches and other wearable tech. And in a live hack-a-thon for Wear OS and Android Automotive OS, bug bounty recipients received $70,000 for finding more than 20 critical vulnerabilities.

Google has also encouraged ethical hackers to [11]test for five categories of attacks in its AI products.

Last year, the Android juggernaut ran a bugSWAT live-hacking event targeting LLM products that produced 35 reports, totaling more than $87,000 rewards. These included [12]Hacking Google Bard - From Prompt Injection to Data Exfiltration and [13]We Hacked Google A.I. for $50,000 .

Chrome rewards

Jacobus describes 2023 as "a year of changes and experimentation" for Google's [14]Chrome VRP , which awarded $2.1 million to bug hunters who spotted 359 unique Chrome vulnerabilities in 2023.

Chrome calls its major new versions "milestones," and with milestone 116 passed in August, Google added [15]MiraclePtr — this is technology to prevent exploitation of use-after-free bugs — across all Chrome platforms.

[16]

This resulted in fewer vulnerability reports and lower rewards. However, the Chrome VRP has also added the [17]MiraclePtr Bypass Reward , which pays up to $100,115, to encourage researchers to try to find ways to bypass this security feature.

It also launched the [18]Full Chain Exploit Bonus , which pays triple the usual reward amount for the first Chrome full-chain exploit reported and double for any follow-up reports.

"While both of these large incentives have gone unclaimed, we are leaving the door open in 2024 for any researchers looking to take on these challenges," we're told.

[19]Google bug bounties inch closer to Microsoft's payouts

[20]Microsoft's bug bounty turns 10. Are these kinds of rewards making code more secure?

[21]Bug bounty hunters load up to stalk AI and fancy bagging big bucks

[22]DEF CON to set thousands of hackers loose on LLMs

Of course, the question with all of these bug bounties is: have they made software more secure?

The short answer is no, according to [23]Katie Moussouris , who played a key role in convincing Microsoft execs that Remond needed a vulnerability disclosure rewards program.

Moussouris, founder and CEO of Luta Security, in an [24]earlier interview with The Register that the rise of bug bounty platforms — and companies investing in cash payouts and related programs instead of developing secure software — is to blame.

"Because both of those are investments – it's not just about cash payments, it's about the work you have to do to actually fix the vulnerabilities," she said. ®

Get our [25]Tech Resources



[1] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/

[2] https://www.theregister.com/2023/03/06/in_brief_security/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://bughunters.google.com/about/rules/5429687846305792/bonus-awards-rules

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://security.googleblog.com/2024/03/vulnerability-reward-program-2023-year.html

[8] https://security.googleblog.com/2023/05/new-android-google-device-VRP.html

[9] https://bughunters.google.com/about/rules/6618732618186752/google-mobile-vulnerability-reward-program-rules

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/

[12] https://embracethered.com/blog/posts/2023/google-bard-data-exfiltration/

[13] https://www.landh.tech/blog/20240304-google-hack-50000/

[14] https://g.co/chrome/vrp

[15] https://security.googleblog.com/2022/09/use-after-freedom-miracleptr.html

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfIwBUQwggdJBRC2hUDYpAAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://g.co/chrome/vrp/#miracleptr-bypass-reward

[18] https://g.co/chrome/vrp/#full-chain-exploit-bonus

[19] https://www.theregister.com/2023/06/24/google_bug_bounties_2022/

[20] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/

[21] https://www.theregister.com/2023/10/27/google_ai_bounty_hackerone/

[22] https://www.theregister.com/2023/05/06/ai_hacking_defcon/

[23] https://www.theregister.com/2022/08/10/us_security_hiring/

[24] https://www.theregister.com/2023/11/22/microsofts_bug_bounty_moussouris/

[25] https://whitepapers.theregister.com/



It isn't easy being a Friday kind of person in a Monday kind of world.