Skip to main content

Google starts offering up-front payments to security researchers in hunt for bugs

Google has been paying researchers for uncovering flaws in its software since 2010. The company’s Security Rewards Program has proved so successful that it’s getting harder to find new bugs, a situation that’s forced it to review the way it rewards the work of its valued bug hunters.

In a blog post over the weekend, Google security engineer Eduardo Vela Nava said that while it’s good news that its products and services now contain fewer security flaws than ever, this means “it can also be discouraging when researchers invest their time and struggle to find issues.”

As a result, the company is launching the Vulnerability Research Grants program that allows skilled researchers to receive payments before they begin their search for bugs in Google’s software.

The company said that starting now it’ll make special requests to experts regarding the kind of research that’s required. The cash payments will run from about $500 to $3,000 per project and will be handed out “immediately before research begins, with no strings attached.”

Google also said that from now all mobile apps officially developed by Google on Google Play and iTunes will also be within the scope of the Vulnerability Reward Program.

Any researchers interested in getting involved can find out more here.

The Mountain View company said that in 2014 it paid more than 200 researchers around $1,500,000 for their work, which involved the discovery of more than 500 bugs.

“For Chrome, more than half of all rewarded reports for 2014 were in developer and beta versions [so we] were able to squash bugs before they could reach our main user population,” Vela Nava said.

The single largest reward was $150,000, made to computer whizz George Hotz after he picked apart Google Chrome’s defenses. So impressed was Google by Hotz’s work that it invited him to join an internship with Project Zero, an initiative launched last year aimed at improving the security of all software, not just Google’s.

[Source: Google]

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
How to create a Subreddit on desktop and mobile
Laptop Working from Home

Few social media sites are as popular as Reddit. Regardless of what you're interested in, there's probably a thriving community for you to interact with on the platform. Known as subreddits, these communities are home to topics like gaming, world news, science, movies, and more. If you can't find a subreddit with your particular interest, Reddit makes it easy to create your own Reddit community.

Running a successful Reddit community isn't easy – but the process of starting one only takes a few minutes. Keep in mind that you'll want to keep a close eye on your subreddit to prevent it from being shut down or turning into a wasteland with no users, but running a subreddit can be a lot of fun when done properly. If you prefer, you can also create a private community that only your friends can join, giving you a place to hang out beyond Twitter and TikTok.

Read more
How to download music from YouTube on desktop and mobile
A woman sitting on a couch, wearing airpods and holding and looking at a smartphone.

Downloading music from YouTube is a fairly common practice, and the demand for making the process easier has inspired the creation of countless websites and software.

But not every service can be considered safe. In fact, some of these services may infect your computer with malware or produce poor-quality audio files. When downloading music from YouTube, you’ll need to first make sure that the websites or apps you use for doing so won’t hurt your device. For this guide our team has found two methods to make the process safer and easier.

Read more
How to clear your browser cache in Chrome, Edge, or Firefox
The Firefox iPhone app.

A stocked computer cache may be convenient for logging into and out of go-to sites in seconds flat, but a major buildup of these tracking codes could significantly impact your PC’s performance. If you’ve noticed that your PC has been running rather slow of late, or you’re using a new browser and don’t know how to clear its cache, we’ve got you covered with the following guide.

Read more