[1] https://bughunters.google.com/about/rules/chrome-friends/574...
[2] https://www.mozilla.org/en-US/security/client-bug-bounty/
[1] https://bughunters.google.com/about/rules/chrome-friends/574...
[2] https://www.mozilla.org/en-US/security/client-bug-bounty/
Sounds fine to me.
[0]: https://en.wikipedia.org/wiki/Mozilla_Corporation
//Edit: Had a typo in my percentage. 20.000 of 157.000.000 is, indeed, 0.012% - that makes it 50x the amount of Google's percentage.
How much of the Mozilla foundation's income goes into product development nowadays?
Virtually all of Mozilla's income comes from the browser (via the Google search agreement). The vast majority of Google's revenue comes from ad revenue on search, YouTube, and Adsense. Not from Chrome directly. So they had less incentive to reward its security, but did so anyway. And they also do some of the best work in the industry, free, for competitors via Project Zero.
https://textslashplain.com/2024/10/13/content-blocking-in-ma... shows a ten-line ad blocker that blocks Google's ads, https://github.com/extesy/hoverzoom/discussions/670 is a list of polite email messages from people who'd like to have elevated access to browsers.
uBlock Origin Lite blocks YouTube ads just fine.
Do you really think Google wouldn't do anything about as blockers? Especially now that no ads is one of the selling points of YouTube Premium?
And it doesn't matter what I think about it. I'm giving you facts not opinions.
Personally I believe that the browser is intended to defend against e.g. Facebook's apps. Google wants to make sure that if you buy a new device and it comes with a Facebook app preinstalled, it also comes with a browser. And that the browser isn't controlled by anyone who'd like to disrupt any of Google's many nice income streams.
That is why you see equivalent skill levels being paid differently in big tech compared to other places.
And why you see millions in salaries at some big techs Ai hiring.
It's really no secret that higher revenue means higher potential pay/more devs...
Surely a bug on Chrome is worth more than a bug on Firefox.
But more to your point: the bounty is more similar to an auction. Once you sell the bug to the software producer the black market has no more use of it, assuming it gets fixed.
Supply is constrained, so competition is on the demand side.
On the drug example demand is constrained, if you're the only buyer. So competition happens on the supply side.
The payment will stop immediately if Google thinks it's no longer needed, or if federal prosecutors (who have determined this payment is illegal) decide the remedy is to stop the payment. [1]
The CEO's job is simple. Say "I think we should take Google's money again this year", and then pocket several million of it. Ca-ching! What are your plans for post-Google-money? Uh uh... AI? Sell out our users to advertisers? [2] It's not looking good.
The Firefox market share continues to dwindle. The board continues to hob-nob with San Francisco socialites and "activists" and use Mozilla as a piggybank to fund their chums. [edit: removed line about Mitchell Baker as she does seem to have finally left]
[0] https://en.wikipedia.org/wiki/Mozilla_Corporation#Finances
[1] https://www.bloomberg.com/news/articles/2024-08-05/google-lo...
Mitchell has not been a member of the Mozilla Foundation or Mozilla Corporation boards since February 2025.
https://blog.mozilla.org/en/mozilla/mozilla-leadership-growt...
Marching into the home office, kicking butt, and pointing at the whiteboard for their favorite pet project:
* Mozilla focusing on privacy
* Mozilla focusing on web standards
* Mozilla focusing on speed
* Mozilla (apparently, here) focusing on maximizing the size of payouts for bug bounties
Inspiring, Rocky-style music plays in the background.
In the foreground, a red line continuously traces slowly downward, with no perceivable relationship to the scenes in the montage.
* Or basically just compare black market prices which already taken the above 3 into account
Won't complain about that.
Yup, clearly Mozilla.
$250k is loose change for Google.
Is monetary expenditure on vulnerability payouts really the primary determinent of who's taking security more seriously, by the way? Sounds a bit backwards to me.
Maybe had they ran the company competently, they could to afford to pay their engineers and offer larger bounties instead.
> Is monetary expenditure on vulnerability payouts really the primary determinent of who's taking security more seriously.
Many such researchers would rather sell their 0day to the black market if the effort + price offered is too low and not worth it. It is up to the vendor (Mozilla) to set a fair price to prevent that exploit from reaching the black market for a much higher price.
So given all the above, Mozilla is not serious.