Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Whatever the price, Google won't root out all the vulnerabilities. A (relatively) smaller price gets people to compete for fame, which can be a more powerful motivation; a large price gets people to compete for the money, but Google may not be the highest bidder.

That said, ZDI may have a point that the requirement for the full exploit is unnecessary; seeing the exploit in action might be enough for educated guesswork, thus seeing more exploits might be a good thing (in terms of security, not reputation).

The obvious compromise would be to set two rewards: one for showing the exploit, another for showing its source code, at the hacker's option. By not disclosing the exploit the hacker would give up a higher guaranteed reward in exchange for a chance to make a juicier deal, but they'd be racing against Google's reverse-engineering effort.



> The obvious compromise would be to set two rewards: one for showing the exploit, another for showing its source code, at the hacker's option. By not disclosing the exploit the hacker would give up a higher guaranteed reward in exchange for a chance to make a juicier deal, but they'd be racing against Google's reverse-engineering effort.

I'm not sure if I'm completely understanding your idea... but in your proposed scenario wouldn't Google be sponsoring a place were the actual attackers that want to screw their users can window shop for working exploits? All researchers would be getting money from Google for participating on their contest, to then sell their working exploit that would take Google a significant amount of time to fix to the highest bidding blackhat/government.


OK, it's a screwy compromise, and it wasn't exactly intended by a single party. But it's happening anyway, in the sense that Google is awarding money for full exploits, and ZDI is awarding money for something that is both tasteless advertising, and still allows Google to fix more bugs than if they appeared only on the black market.


I disagree, the sandbox is by far the best defense ever made in a browser. 60k per exploit is quite a good sum. Even for a couple month's worth of work.

It should not be a blackmail sort of operation.


It's a very good sum for a couple of months work coding indeed. That'd be about 1.5-3x the amount for regular coding work, roughly, yes?

However, if you factor in the freelance/one-time-only factor, it becomes somewhat more fair, but still really good money.

But then you also factor in the fact that he's using a very unique skill set in order to do this job, one that maybe a few handfuls of people on this planet possess. And then I wonder.

But it's still good money, regardless :)


>a large price gets people to compete for the money, but Google may not be the highest bidder.

How exactly does it hurt the fame angle?


It's a well-known psychological effect. If you reward people for an activity that they already enjoy, then they will enjoy the activity less; their motivation has been diverted towards the reward.


The extra money is for dealing in a grey market. I thought people would want to be more discreet about this.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: