Feeds

Google splashes out the cash for cunning cracks

Boosts bug bounties and offers $2m Pwnium purse

The essential guide to IT transformation

Google's increasing the financial incentives for reporting vulnerabilities with an upgraded bug bounty scheme and a $2m purse for its latest Pwnium Chrome hacking contest, to be held in October.

The Chocolate Factory's Chromium Vulnerability Rewards Program has paid out more than ONE MILLION DOLLARS to researchers who bring in documented new bugs, on top of nearly half a million shelled out for non-Chromium web vulnerabilities. But according to Google security software engineer Chris Evans, this still isn't enough dosh to hold a hacker's interest.

"Recently, we've seen a significant drop-off in externally reported Chromium security issues," he blogged. "This signals to us that bugs are becoming harder to find, as the efforts of the wider community have made Chromium significantly stronger."

To spur interest and reward harder work, Google's adding a bonus of $1,000 for any bugs that are deemed "particularly exploitable," with similar awards for flaws that work on a wide variety of platforms besides Google's, or which are discovered in sections of the code base previously determined to be stable and bug free.

In particular, Google is looking for flaws in GPU drivers, especially in Intel's hardware, as well as any 64-bit code flaws. It's also said extra awards are available for finding vulnerabilities in the stripped-down Linux kernel that powers its Chrome OS, if they can bypass the system's sandboxing.

Presumably these kinds of hacks will be what the judges are looking for at in Google's second Pwnium Chrome hacking contest. The purse for this round, held at the 10th anniversary Hack in the Box conference in Kuala Lumpur in October, has doubled to $2m for people who can kick holes in Chrome's security.

Those who can demonstrate (and document) a "Full Chrome exploit" on a Windows 7 system running the latest build of the browser can bag $60,000. A "Partial Chrome Exploit," which uses at least one bug to get user access earns $50,000, and a successful attack on a "Non-Chrome exploit" via Windows or Flash will net $40,000 to the demonstrator.

All this money sloshing around is good news for security researchers, and the bounty system Google has run since 2010 pays off internally, too. The Chocolate Factory gets a bit more security, which is a useful selling point for Google Apps in enterprise, and the cost is nothing in terms of its marketing budget, while providing pocket money and more for legitimate researchers. ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?