TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Increasing Google and Alphabet VRP rewards

100 pointsby erbbysam11 months ago

11 comments

Topfi11 months ago
I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail&#x2F;Google account, I am pretty sure it has to be an order (perhaps even orders) of magnitude more than 75k.<p>Looked into it and am equally surprised to find that others, like Microsoft [0] also have such low bounties for these types of attacks.<p>While providing such an exploit to the affected company has value beyond the bounty (potential job offers, media exposure, credibility, ethical considerations, etc.), weighing that up against life-changing money really makes it hard to fault those who take the more lucrative route of selling these to the highest bidder, whoever that may be.<p>Seriously, Alphabet and Co. can afford more, especially considering any such exploit would most certainly hit their bottom line&#x2F;stock far beyond a few 100k.<p>[0] <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;msrc&#x2F;bounty</a>
评论 #40956355 未加载
评论 #40956831 未加载
评论 #40956771 未加载
评论 #40956613 未加载
评论 #40956922 未加载
评论 #40956117 未加载
评论 #40956264 未加载
评论 #40956300 未加载
评论 #40956955 未加载
评论 #40956358 未加载
评论 #40956198 未加载
sirdarckcat11 months ago
151515 is such an elitist number.. 3 * 13 * 37 * 3 * 5 * 7
评论 #40956153 未加载
neilv11 months ago
So if you find several catastrophic vulnerabilities each year, then you can make as much as one of the many people whose jobs it was <i>not</i> to create those vulnerabilities in the first place? :)
评论 #40956257 未加载
lallysingh11 months ago
Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time?<p>I&#x27;m wondering if bounty programs effectively form a low-paid gig economy for programmers.
评论 #40956122 未加载
评论 #40955940 未加载
评论 #40956139 未加载
评论 #40955914 未加载
评论 #40956820 未加载
评论 #40956046 未加载
评论 #40959216 未加载
zb311 months ago
I personally know at least one normally functioning person that didn&#x27;t claim their $1k bounty due to the complexity of that process (also bureaucracy).<p>Fortunately this is not a problem for me, because I couldn&#x27;t find anything even if I wanted.
xyst11 months ago
Hot Take: these bug bounty systems are a way to get cheap labor.<p>Instead of spending the time and money to build secure systems up front, they will offload this to &quot;bounty programs&quot; where the time spent finding vulnerabilities will not match the reward. It&#x27;s like an unpaid internship, but worse since you are competing with people of varying cost of living requirements.<p>Yea, a potential $150K bounty sounds is a shit ton of money for a person in a third world country. But for anybody else (given the same time spent finding the vulnerability), there is no financial motivation. Only &quot;fame&quot; via disclosure reports in the security community.<p>This is the equivalent of a customer asking a professional photographer who is new on the scene to do their photography for free in exchange for &quot;exposure&quot;. No, you aren&#x27;t innovative. You are a cheap asshole.
评论 #40956640 未加载
评论 #40956289 未加载
pizzalife11 months ago
This is still not nearly enough to reach parity with market prices. Try offering a few million.
评论 #40956884 未加载
modeless11 months ago
We will know AGI is here when an agent can autonomously claim these bounties.
评论 #40956296 未加载
laweijfmvo11 months ago
&gt; A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000<p>Should be $10m honestly.
评论 #40955910 未加载
评论 #40956086 未加载
评论 #40957062 未加载
nothrowaways11 months ago
151515.151
tkz131211 months ago
These amounts are hilariously low. $150k for a full gmail account takeover is peanuts compared to the potential impact, and the $4k for PII leak on nest.com is frankly just insulting.