Going Beyond Vulnerability Rewards
googleonlinesecurity.blogspot.com
googleonlinesecurity.blogspot.com
* OpenSSH
* BIND
* ISC DHCP
* libjpeg
* libjpeg-turbo
* libpng
* giflib
* Chromium
* Blink
* OpenSSL
* zlib
* "Security-critical, commonly used components of the Linux kernel (including KVM)"
This is so smart. Every part of it, but especially the targets they picked.
Instead of trying that, we're catering to two groups of researchers:
1) Those who are not comfortable with the idea of selling weaponized exploits to the highest bidder for unspecified offensive purposes, and
2) Those who like to find bugs, but don't want to spend days or weeks to develop reliable, weaponized exploits for resale.
As it turns out, there are thousands of extremely prolific researchers who fall into these buckets; the number of "black market" players is much lower than that.
The reason why all of this matters is purely probabilistic: all this scrutiny limits the number of remaining vulnerabilities that can be leveraged for nefarious purposes, and limits the lifespan of any already-known 0-day bugs.
Now, having said all that, your comment is more applicable to vulnerability reward programs - which this isn't :-)
NOBODY is bidding for that kind of work. Google is the only company paying for it.
It would still be plenty great if Google provided its bug bounty for libpng or libjpeg. Oh, wait, they do: their own code depends on these libraries, which is why they picked them.
For many researchers in the world these reward programs ship a substantial amount of money.
And even if Google pays 20k for a bug and some cybermob promises 100k for an exploit. Are you really comfortable giving your bank account to those guys? Would you have to look up money laundering on the internet? And would you stop using the vulnerable Google product for yourself and tell those you hold dear to do the same?
The amount of legit money paid vs. the hassle and legal problems with selling on the black market even out very nicely for me, but I guess that depends on your priorities (and morals).
This video http://vimeo.com/54130349 (Bug Bounty Programs - Michael Coates, Chris Evans, Jeremiah Grossman, Adam Mein, Alex Rice) shows how great these companies are doing with these bug bounty programs. I'd welcome more companies to follow suit, both in bug bounty programs and hardening patches reward programs.
"We intend to soon extend the program to:
* Widely used web servers: Apache httpd, lighttpd, nginx
* Popular SMTP services: Sendmail, Postfix, Exim
* Toolchain security improvements for GCC, binutils, and llvm
* Virtual private networking: OpenVPN"
The reward scheme is dubious though: I love working on open source because it's intrinsically rewarding. But if you try to pay me a few bucks, chances are I'll lose interest because my day job pays better.
Extrinsic motivation killing intrinsic motivation is a known phenomenon in psychology: http://en.wikipedia.org/wiki/Motivation_crowding_theory It means that splashing money around to get people to do stuff can have the opposite effect. Also see the book Drive by Daniel Pink: http://www.amazon.com/Drive-Surprising-Truth-About-Motivates...
This means that Google is virtually funding these projects..
This is of course an old-school wink by Google here, although I'm not sure where it originally came from.
It kind of went everywhere in the 90ies, even in looking at the time... 13:37 is 'leet time (!)
Different to what I originally thought :)