Google pays $381,000 in bug bounties

Powered by SC Magazine
 

Payments used to squash 1100 vulnerabilities since November 2010.

Google has paid some $381,000 to close 1100 legitimate vulnerabilities under its bug bounty programme since its inception.

The vulnerabilities ranged from low to high severity and were reported by more than 200 individuals. Some 730 bugs qualified for reward.

Google security team technical program manager Adam Mein said that the programme "has been a big success".

The company received 43 bug reports in the week after the reward programme, an extension of Chromium Security Research, was launched in November 2010.

“Roughly half of the bugs that received a reward were discovered in software written by approximately 50 companies that Google acquired; the rest were distributed across applications developed by Google (several hundred new ones each year). Significantly, the vast majority of our initial bug reporters had never filed bugs with us before we started offering monetary rewards.”

Google accepts vulnerability reports for its google.com platform, as well as in YouTube, blogger.com and Orkut.

The base reward for qualifying bugs is $469, and if the rewards panel finds a particular bug to be severe or unusually clever, rewards of up to $2936 may be issued. The panel also said that it may also decide a single report actually constitutes multiple bugs requiring reward, or that multiple reports constitute only a single reward.

Mein said Google has gotten better and stronger as a result of this work and said  bug bounty programmes help build better relationships with the security research community.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, US edition


Google pays $381,000 in bug bounties
 
 
 
Top Stories
Meet FABACUS, Westpac's first computer
GE225 operators celebrate gold anniversary.
 
NSW Govt gets ready to throw out the floppy disks
[Opinion] Dominic Perrottet says its time for government to catch up.
 
iiNet facing new copyright battle with Hollywood
Fighting to protect customer details.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  25%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  22%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  26%
TOTAL VOTES: 327

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  56%
 
No
  44%
TOTAL VOTES: 135

Vote