July 13th, 2024

Increasing Google and Alphabet VRP rewards up to $151,515

The blog highlights Google and Alphabet's VRP raising rewards to $151,515 for finding vulnerabilities. This motivates researchers to enhance platform security, attracting skilled individuals to strengthen overall system security.

Read original articleLink Icon
Increasing Google and Alphabet VRP rewards up to $151,515

The blog discusses the increase in rewards for finding vulnerabilities in Google and Alphabet's virtual reality platform (VRP) to up to $151,515. This incentivizes security researchers and hackers to identify and report potential security flaws in the VRP, helping the companies enhance their platform's security. The raised rewards aim to attract more skilled individuals to participate in the bug bounty program, ultimately strengthening the overall security of Google and Alphabet's virtual reality systems.

Link Icon 11 comments
By @Topfi - 4 months
I am genuinely surprised that these have been and continue to be so low. Do not know why but I was under the impression, that we had already gotten into the 1 Million USD range. While I do not know how much an interested party would realistically pay for an exploit that enables the complete takeover or even just limited access to a Gmail/Google account, I am pretty sure it has to be an order (perhaps even orders) of magnitude more than 75k.

Looked into it and am equally surprised to find that others, like Microsoft [0] also have such low bounties for these types of attacks.

While providing such an exploit to the affected company has value beyond the bounty (potential job offers, media exposure, credibility, ethical considerations, etc.), weighing that up against life-changing money really makes it hard to fault those who take the more lucrative route of selling these to the highest bidder, whoever that may be.

Seriously, Alphabet and Co. can afford more, especially considering any such exploit would most certainly hit their bottom line/stock far beyond a few 100k.

[0] https://www.microsoft.com/en-us/msrc/bounty

By @sirdarckcat - 4 months
151515 is such an elitist number.. 3 * 13 * 37 * 3 * 5 * 7
By @neilv - 4 months
So if you find several catastrophic vulnerabilities each year, then you can make as much as one of the many people whose jobs it was not to create those vulnerabilities in the first place? :)
By @lallysingh - 4 months
Question for the hackers: how much effort goes into solving these bounties, and are they monetarily worth the time?

I'm wondering if bounty programs effectively form a low-paid gig economy for programmers.

By @zb3 - 4 months
I personally know at least one normally functioning person that didn't claim their $1k bounty due to the complexity of that process (also bureaucracy).

Fortunately this is not a problem for me, because I couldn't find anything even if I wanted.

By @xyst - 4 months
Hot Take: these bug bounty systems are a way to get cheap labor.

Instead of spending the time and money to build secure systems up front, they will offload this to "bounty programs" where the time spent finding vulnerabilities will not match the reward. It's like an unpaid internship, but worse since you are competing with people of varying cost of living requirements.

Yea, a potential $150K bounty sounds is a shit ton of money for a person in a third world country. But for anybody else (given the same time spent finding the vulnerability), there is no financial motivation. Only "fame" via disclosure reports in the security community.

This is the equivalent of a customer asking a professional photographer who is new on the scene to do their photography for free in exchange for "exposure". No, you aren't innovative. You are a cheap asshole.

By @pizzalife - 4 months
This is still not nearly enough to reach parity with market prices. Try offering a few million.
By @modeless - 4 months
We will know AGI is here when an agent can autonomously claim these bounties.
By @laweijfmvo - 4 months
> A logic flaw leading to an accounts.google.com @gmail.com account takeover ($50,000 * 1.5) = $75,000

Should be $10m honestly.

By @nothrowaways - 4 months
151515.151
By @tkz1312 - 4 months
These amounts are hilariously low. $150k for a full gmail account takeover is peanuts compared to the potential impact, and the $4k for PII leak on nest.com is frankly just insulting.