Feeds

Google calls bug bounty hunters to YouTube, Blogger

'1337' cash for web flaws

Next gen security for virtualised datacentres

Google has unveiled a pilot program designed to make Blogger, YouTube and other company-run websites more secure by paying significant bounties to researchers who report bugs that threaten users.

The initiative expands on a previous bounty program that rewarded researchers only for bug reports in Chromium, the guts of Google's open-source Chrome browser. Effective immediately, rewards of as much as $3,133.70 (as in “leet,” or elite get it?) are available to people who report serious web-application flaws in Google properties such as its main site, YouTube or Blogger. Client apps such as Android, Picasa or Google desktop aren't eligible.

“Today, we are announcing an experimental new vulnerability reward program that applies to Google web properties,” the company said on Monday. “We already enjoy working with an array of researchers to improve Google security, and some individuals who have provided high caliber reports are listed on our credits page. As well as enabling us to thank regular contributors in a new way, we hope our new program will attract new researchers and the types of reports that help make our users safer.”

The bounties will be awarded when researchers privately report cross-site scripting (XSS), cross-site request forgery (XSRF), authentication bypasses and other types of web application vulnerabilities that might compromise the confidentiality or integrity of user data. The premium $3,133.7 reward will be paid in cases where the reported bug is especially severe or clever. Reports of less sophisticated bugs will fetch $500.

Members of Google's security team, including Chris Evans, Neel Mehta, Adam Mein, Matt Moore, and Michal Zalewski, will determine which bugs are eligible.

Google's blog post announcing the new program makes clear that proofs of concept should attack only accounts controlled by the researcher. Attacks against Google's corporate infrastructure, denial-of-service attacks and social-engineering and physical attacks are strictly forbidden. Google has also asked participants to refrain from using automated testing tools.

The rewards are also unavailable to those who publicly report the vulnerability before it is fixed, though researchers are free to toot their own horn once it has been patched.

While some companies – including Microsoft – have made it clear they won't retaliate against researchers who privately report bugs in their sites, Google is the only site we're aware of that's offering cash rewards to do so. Some researchers have long grumbled that they should receive compensation for the reports that benefit users of websites and software. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Best practices for enterprise data
Discussing how technology providers have innovated in order to solve new challenges, creating a new framework for enterprise data.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?