Google Pays $10 Million In Bug Bounties
Google has revealed it paid $10 million in bounties to people who spotted security bugs in its products last year. More people earned rewards than in an equivalent Microsoft program, though Google paid out less per person.
Such programs are designed not only to boost security but to encourage security researchers to work for good, rather than exploit bugs. However, critics say tech companies should put more of their resources into making software as bug-free as possible to start with.
Google paid out a total of $10 million in 2023, split between 632 researchers in 68 countries. The highest single payment was a surprisingly specific $113,337. It's possible that was a round figure in another currency. (Source: googleblog.com)
The total payout is the second highest ever in the eight-year history of the program. However, it's down from $12 million last year, the first time the annual amount has fallen.
By way of comparison, Microsoft paid out $13.8 million to 345 people between July 2022 and June 2023.
Android Bounty Budget Unspent
The actual Google payouts are far short of what it's prepared to pay. For example, it had reportedly earmarked a budget of $15 million for researchers who discovered critical bugs in Android. It only paid out $3.4 million in this category. (Source: zdnet.com)
The big story in the figures is that Google has expanded the scope of security areas in which it's prepared to pay bounties. These now include dedicated amounts for wearable devices and generative AI tools such as Google Bard.
Sandbox Breach a Major Concern
However, it's not lost sight of the importance of more widely used software such as the Chrome Browser. It's offering triple the usual payout for anyone who discovers a "full chain exploit." That's one which lets somebody remotely take advantage of a bug to control or run the browser, overcoming its "sandbox" feature that's designed to limit the impact of any attacks.
Not everyone's convinced such programs are the most effective way to boost security, though. Katie Mossouris of Luta Security told The Register that even after learning about bugs this way, software companies still need to fix the problem. That means it's more efficient to put extra efforts into avoiding releasing buggy software in the first place. (Source: theregister.com)
What's Your Opinion?
Is this money well spent? Will such rewards prevent people from exploiting bugs for malicious purposes? Do you think software is getting more or less secure?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.