This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example.
Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff is worth far more than the (up to) $3133 they are offering.
No More Free Bugs, as they say.
They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally. Fair is fair. There is no reason this isn't worth compensating but something like pagerank optimizations is.
What makes you think they don't already? You make it sound like Google doesn't give a shit about security. That clearly isn't the case.
That doesn't mean they're going to find everything, though.
At the end of the day, private companies are perfectly within their rights to do offensive research against Google products, to be selective about how they disclose their results, and to tell the public whatever they want about those results. As long as they aren't lying, there's nothing unethical about it.
Correction: not even well-paid Google employees did. They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.
I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be crossing a line if they posted a press release trumpeting a major vulnerability they discovered, mentioning by name which company and approximately where the vulnerability was located, but then refused to disclose it to the company in question.
I'm not sure how much it survives, but I believe there was traditionally even a common-law "duty to warn" if you were aware of significant risks to someone's person or property.
The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over.
But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensation?
On which moral principle are you condemning them?
If you send a letter to a bank saying "I have found a breach in the kind of vault you use at your banks, I'm giving the details to some expert robbers but you can't have it unless you pay me $10m", with evidence you've done it, I'm pretty sure you will find yourself waking up at gunpoint at 6am, courtesy of the FBI.
Since unauthorised access of a computer is a crime in many places, I'm sure you can see the relevance, even if the consequences aren't as drastic. One hopes that we have misinterpreted this and that they have performed 'responsible disclosure' by telling Google all the details.
Think about the audacity of farmers, who make a profit for food, which you need to live. But nobody thinks like that for some reason.
Earning profit just means you've done something for someone who really wanted it done. It's a necessary signal.
> http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN" part of the disclosure bit.
The 100% unhackable browser and OS... how much does it cost? I think the turnaround time is going to be infinite. I'm not sure what you're saying.
These companies have employees, who have a nice situation with a financial exchange of value. Let them do their own work. If I'm going to do something their employees should be doing, they're free to hire me or pay me as a consultant.