upvote
The discount Google is getting on bounties versus internal spend is easy to estimate:

  # assumed to be $0.5mil USD or greater
  A := What quantity of salaries-and-benefits and AI-dollars does Google spend on zero-day research?

  # assumed to be greater than zero
  B := How many full sandbox RCEs are they *hoping* to discover per year with that budget?

  # $/RCE budgeted spend
  C := A ÷ B

  # $/bounty
  D := $1000 USD

  # % discount per bounty relative to in-house spend
  E := (C - D) / C
While we lack the data to be sure, it is reasonable to estimate that they're getting a discount of 90% or better versus internal spend on this bounty payment, if one assumes that they do not have many sandbox RCEs left undiscovered. It's unclear whether that assumption holds, but with only a single researcher at an assumed $0.5mil/year (all-inclusive after pay, stock, and benefits) is enough to support the plausibility of that 90% figure, before accounting at market rates for their internal use of the house AIs.

So, the most likely case is that they're greedy and miserly, and hope we don't do the math. However I recognize that there are judgment calls to be made here. Either their internal spending finds hundreds of RCEs per year, or they're significantly discounting bounty payments versus their actual worth, or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al. All of these are bad in different ways; one hopes a competent tech reporter actually pursues this line of questioning with them!

reply
> or they're negligent in budgeting for RCE discovery at all, or they assign zero value to the security of the Chromium platform underpinning Edge, Electron, et al

I generally agree, but a 3rd explanation is they figure that too generous a bounty will flood them with reports of minor issues making major ones harder to see (and costing time and money to verify that could be spent looking for security issues).

reply
You let the market decide. Google could purchase the bugs on the same market blackhats do.
reply
Google directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions:

* They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable).

* They don't require you to actually build a reliable exploit chain.

* They pay up front, not in tranches.

* They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.

reply
They pay in plain old money, too. On the market your counterparty will be a criminal who is trying to scam you every step of the way.
reply
Not so much, the grey market is pretty well structured.
reply
Is there anywhere I could read more about this?

Sound very interesting!

reply
we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.
reply
Companies sometimes reward their employees with important bug fixes. When I worked on a big dev team, we'd even decide what were the most important fixes and give people a special 5k bonus or something.

But they weren't security issues necessarily. I never thought about it, fixing a huge performance issue is big. A security fix that gets caught early makes no noise so you just don't know how important it would have been. We also once had a really terrible bug that lead to lots of customers getting effectively attacked.

reply
"Crime" is very flexible term. One country's criminal is another country hero. Maybe the author would sell the vulnerability to an organization making exploits for government use.

"Safety" is also a relative thing, when the world is safer for one party, it is usually worse for another.

reply
Having secure browsers, encryption etc. actually clearly benefits the world. No “but think about the children/terrorists” please.
reply
> we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime.

"Making money from bugs" is not solely a black-market activity. There are plenty of grey and even white hat activities in this market.

reply
[dead]
reply
> The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier.

Yeah let's see how this plays out, paying people less than their time is worth for RCEs.

reply
Finding bugs is hardly a crime, selling them even isn't.

Now exploiting them? Yes that's a crime.

reply
> using bugs to make money

Aka security research.

It's one thing to hold something for ransom ("give me $5M or I release the 0day"). It's another to sell a valuable piece of information ("give me $5M if you want the 0day"). As long as you're only offering the bug to the company who would be impacted by its release, there's nothing unethical about asking for payment.

Maybe you think that, ethically, all bugs should be reported, regardless of payment, because it prevents harm. Well a lot of things prevent harm that we don't all take it upon ourselves to do voluntarily. Should everyone do all safety-related work for free? If we don't want to do it for free, should we not do safety work at all?

If the company really wanted it safe, and they can't make it safe themselves, they can pay someone else to make it safe. If they aren't willing to do that, then nobody is obligated to do free work for them, because we don't require anyone else to do safety-critical work for free. Let's not forget, this isn't a scrappy startup struggling for a seed round, this is one of the world's largest corporations with billions of dollars in cash. If they want your labor, make them pay for it.

reply
>Well a lot of things prevent harm that we don't all take it upon ourselves to do voluntarily. Should everyone do all safety-related work for free?

Thanks for putting it like that, it changed my opinion on the subject.

If it's normal to expect people to be compensated for other security work, it implies it should also be normal to compensate security researches.

reply
> using bugs to make money [is a crime]

No it’s not lol

reply
Well, someone did decide to tell google about this in exchange for a thousand dollars (albeit unclear how much the money was the motivator). Doesn't that mean the market did decide in google's favour?
reply
Someone decided to tell Google about this in exchange for an unknown amount of money, chosen unilaterally by Google at a later date, at which point the market value of the vulnerability is $0.

There's no way money is the motivator.

reply
Money is not the only coin to pay someone in.
reply
Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.
reply
> Blackhat markets will always be able to pay better.

... than Google?

> Selling to Google though you aren't chancing jail time.

Why would you go to jail for selling a vulnerability? It's free speech.

reply
"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.
reply
"this vulnerability is being sold for research purposes only and must never be used outside of a tightly controlled research sandbox"
reply
Has anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.
reply
deleted
reply
[flagged]
reply
It’s not. Same as credible threats are also seen as nothing to do with free speech.

It just isn’t what free speech is.

It’s a separate thing.

reply
No, it is a limit on free speech but it is one of several that various governments (and cultures as a whole) throughout the world have upheld fairly consistently. Free speech is more or less an unachievable platonic ideal that we aspire to. Success varies, as do the compromises made along the way.

Speaking more generally, don't let your ideals bias your judgment. Just because you support policy X and also view ideal Y as good that doesn't mean that X isn't detrimental to Y. It's important to be objective about these things.

reply
Telling someone the steps to rob a bank world probably catch you some charges, I'm assuming.
reply
No, it wouldn't.
reply
They would be broke quick.
reply
In the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
reply
> In the past I would have thought this would incentivize finding bugs that might never be found.

Isn't that a good thing?

> However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.

If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.

reply
Sure they make sense — you need some incentive to drive the price to zero.
reply
Because there’s still a sizable group of people who see $1,000 from Google as more than $1,000.

Even a resume item.

reply
deleted
reply
ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
reply
What kind of auction would you like to run?

Remember that you can sell the same vulnerability to multiple people: it's software you can copy.

reply
Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.)

$1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?).

Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.

reply
it seems unlikely google's lawyers would go for this
reply
Maybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works.
reply
well that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter.
reply