Google calls, raises Mozilla's bug bounty for Chrome flaws
Boosts cash-for-bugs maximum payment to $3,133, makes researchers mostly happy
Computerworld - Google on Tuesday hiked bounty payments for Chrome bugs to a maximum of $3,133, up almost $2,000 from the previous top dollar payout of $1,337.
The move came less than a week after rival browser maker Mozilla increased Firefox bug bounties to $3,000.
In an entry to the Chromium project's blog, Chris Evans, who works on the Chrome security team, announced the new maximum bounty of $3.133.70 and said Google would "most likely" award that amount for all vulnerabilities rated "critical" in the company's four-step scoring system.
"The increased reward reflects the fact that the sandbox makes it harder to find bugs of this severity," said Evans, referring to the technology baked into Chrome that isolates processes from one another and the rest of the machine, preventing or at least hindering malicious code from escaping an application to wreak havoc or infect the computer.
When Google launched Chrome bug bounties last January, it set $1,337 as the maximum amount, but said that the biggest bounty would be awarded only to vulnerabilities it considered "particularly severe or particularly clever." The company has cut a check for that amount only once in the last six months.
Like the previous maximum, the new amount is playing with "leet," a kind of geek-speak used by some researchers. There, "eleet" -- for the correctly-spelled "elite" -- is rendered as "31337."
Evans said that the base reward for less serious bugs would remain at $500, but that the security engineers who evaluate reported vulnerabilities would "consider rewarding more for high-quality bug reports" that included an accurate explanation of the root cause or to a researcher who, as Evans put it, conducted a "productive discussion towards resolution."
Google has paid out $14,846 for 21 reported vulnerabilities since January.
Researcher Sergey Glazunov earned not only the sole $1,337 that Google's awarded so far, but made the most of any contributor: $3,337. Four researchers -- Glazunov, Aki Helin, a researcher identified only as "wushi," and another nicknamed "kuzzcc" -- accounted for 73% of the money Google has paid for bounties.
Not surprisingly, researchers applauded the potential to earn more from Google and Mozilla.
"Chrome ups the ante on bug bounties. A bidding war begins!" said Charlie Miller on Twitter Tuesday. Miller is a well-known vulnerability researcher, and the only one to take home cash prizes three years running at the Pwn2Own hacking contest held each spring in Vancouver, British Columbia. "Who shall we help find bugs for?"
"It's a real beneficial development, and not only for researchers," said Dino Dai Zovi, a security consultant and researcher who, with Miller and colleague Alex Sotirov, launched an effort they dubbed "No Free Bugs" last year.
- Mozilla ships Firefox 31, adds search to new tab page
- Microsoft's IE steps back from the brink of irrelevance
- Firefox falters, falls to record low in overall browser share
- Firefox risks user backlash by adding search box to new tab page
- Google unseats Microsoft as the U.S. browser powerhouse
- Safari, Chrome push to mask URLs
- Chrome on Windows champs at the 64-bit
- Google pulls trigger, cripples some Chrome add-ons
- Microsoft shoots to shorten Internet Explorer's long tail
- Firefox risks irrelevance as mobile browsing booms
- EndPoint Interactive eGuide In this eGuide, Network World, Computerworld, and CIO examine two endpoint trends - BYOD and collaboration - and offer tips and advice on...
- Mobile First: Securing Information Sprawl Learn how the partnership between Box and MobileIron can help you execute a "mobile first" strategy that manages and secures both mobile apps...
- Cybersecurity Imperatives: Reinvent your Network Security The Rise of CyberSecurity
- Surescripts Case Study- Securing Keys and Certificates Surescripts implemented Venafi's Trust Protection Platform™ to secure digital keys and certificates, ensure the privacy and confidentiality of electronic clinical information for its...
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities.
- Deep Dive into Advanced Networking and Security with Hybrid Cloud Security and networking are among the top concerns when moving workloads to the cloud. VMware vCloud® Hybrid Service™ enables you to extend your... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!