Feeds

Google splashes out the cash for cunning cracks

Boosts bug bounties and offers $2m Pwnium purse

Protecting against web application threats using SSL

Google's increasing the financial incentives for reporting vulnerabilities with an upgraded bug bounty scheme and a $2m purse for its latest Pwnium Chrome hacking contest, to be held in October.

The Chocolate Factory's Chromium Vulnerability Rewards Program has paid out more than ONE MILLION DOLLARS to researchers who bring in documented new bugs, on top of nearly half a million shelled out for non-Chromium web vulnerabilities. But according to Google security software engineer Chris Evans, this still isn't enough dosh to hold a hacker's interest.

"Recently, we've seen a significant drop-off in externally reported Chromium security issues," he blogged. "This signals to us that bugs are becoming harder to find, as the efforts of the wider community have made Chromium significantly stronger."

To spur interest and reward harder work, Google's adding a bonus of $1,000 for any bugs that are deemed "particularly exploitable," with similar awards for flaws that work on a wide variety of platforms besides Google's, or which are discovered in sections of the code base previously determined to be stable and bug free.

In particular, Google is looking for flaws in GPU drivers, especially in Intel's hardware, as well as any 64-bit code flaws. It's also said extra awards are available for finding vulnerabilities in the stripped-down Linux kernel that powers its Chrome OS, if they can bypass the system's sandboxing.

Presumably these kinds of hacks will be what the judges are looking for at in Google's second Pwnium Chrome hacking contest. The purse for this round, held at the 10th anniversary Hack in the Box conference in Kuala Lumpur in October, has doubled to $2m for people who can kick holes in Chrome's security.

Those who can demonstrate (and document) a "Full Chrome exploit" on a Windows 7 system running the latest build of the browser can bag $60,000. A "Partial Chrome Exploit," which uses at least one bug to get user access earns $50,000, and a successful attack on a "Non-Chrome exploit" via Windows or Flash will net $40,000 to the demonstrator.

All this money sloshing around is good news for security researchers, and the bounty system Google has run since 2010 pays off internally, too. The Chocolate Factory gets a bit more security, which is a useful selling point for Google Apps in enterprise, and the cost is nothing in terms of its marketing budget, while providing pocket money and more for legitimate researchers. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.