Security Blog

The latest news and insights from Google on security and safety on the Internet

Security rewards at Google: Two MEEELLION Dollars Later

12 agosto 2013
Share on Twitter Share on Facebook
Google

7 commenti :

Anonimo ha detto...

For 1) a CSO out there wondering if it is wise to spend so many dollars, and 2) a security researcher who wonders if such a program is enough, I can add the organizational budget perspective:
1) Yes, $2M is very reasonable compared to the security value received. You could easily spend way more than that on commercial tools or services for less payback.
2) Before setting up such a program, a well-staffed internal team has to already be in place, because it is better to discover such problems internally and because very skilled people are needed to triage and act on the diverse reports that come in. The cost of that staff is way more than the award program, and hard to recruit. But top reporters are frequently top candidates.
Eric Grosse, VP Security & Privacy Engineering, Google

12 agosto 2013 alle ore 17:18
Unknown ha detto...

To the same CSO Mr Grosse was talking about: as an end user, I find this model attractive. I makes me feel secure to know goldminers around me indirectly work for my benefit and does have an influence on choosing my email/mobile/IM/cloud provider.

Thanks guys!

12 agosto 2013 alle ore 17:42
Unknown ha detto...

Google Thank You... Innovators Look like the bad guys...
Quite the opposite: The "bad" guys are hiding in the weeds.

12 agosto 2013 alle ore 17:59
Anonimo ha detto...

>read about raising reward levels significantly
>wait anxiously for the next batch of advisories
>20th of august: stable channel update
>my face when the median payout is still a measly $1,000
>nothingtodohere.gif

21 agosto 2013 alle ore 20:34
Unknown ha detto...

Great Blog!! That was amazing. Your thought processing is wonderful. The way you tell the thing is awesome. You are really a master.
it security program

4 dicembre 2013 alle ore 01:47
Unknown ha detto...

#8217

20 dicembre 2013 alle ore 04:02
Unknown ha detto...

I need help contacting google or finding a forum to solve my issue.
I am not receiving my emails. My accounts are dear to me and now they no longer receive 90% of emails. Ive done some checking and the most I can conclude is that goggle is marking me a spam email account??? WHICH I AM NOT!

please help me if your out there.

29 gennaio 2014 alle ore 14:17

Posta un commento

  

Etichette


  • #sharethemicincyber
  • #supplychain #security #opensource
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2024
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2023
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2022
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2021
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2020
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2019
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2018
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2017
    • dic
    • nov
    • ott
    • set
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2016
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2015
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2014
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • apr
    • mar
    • feb
    • gen
  •     2013
    • dic
    • nov
    • ott
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2012
    • dic
    • set
    • ago
    • giu
    • mag
    • apr
    • mar
    • feb
    • gen
  •     2011
    • dic
    • nov
    • ott
    • set
    • ago
    • lug
    • giu
    • mag
    • apr
    • mar
    • feb
  •     2010
    • nov
    • ott
    • set
    • ago
    • lug
    • mag
    • apr
    • mar
  •     2009
    • nov
    • ott
    • ago
    • lug
    • giu
    • mar
  •     2008
    • dic
    • nov
    • ott
    • ago
    • lug
    • mag
    • feb
  •     2007
    • nov
    • ott
    • set
    • lug
    • giu
    • mag

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms