Showing posts with label Program. Show all posts
Showing posts with label Program. Show all posts

Wednesday, 14 August 2013

Google boosts flaw bounties to $5,000 on Chromium program


Google is upping the rewards it offers to bug hunters on its Chromium Vulnerability Rewards (VRP) program to $5,000 (£3,250) for those previously rated at $1,000, the firm has announced.

Nearly three years after it started handing out money to researchers on this program, Google has gradually increased the sums it offers for those wanting to make it  on to its 'Hall of Fame' list.

Judging from the list, a small elite of researchers is already making a tidy living from the rewards.


As for the higher sums, “In many cases, this will be a 5x increase in reward level! We’ll issue higher rewards for bugs we believe present a more significant threat to user safety, and when the researcher provides an accurate analysis of exploitability and severity,” said Google’s Chris Evans.

Google currently has three types of bug rewards; the Chromium VRP, the highly-rewarded and more critical Web VRP, and the sums it hands out at the public CanSecWest Pwnium contest.

In total, Google had handed out over $2 million across these schemes, split evenly between the Chromium/Pwnium track and the Web VRP, it said.

It’s the second increase in as many months with Google in June boosting the money on offer for critical cross-site scripting (XSS) flaws and those affecting its own programs by about the same factor.

Despite the optimistic enthusiasm of the latest announcement, the higher rewards are probably linked to lower submission rates. Last August, the firm raised bounties generally, saying it planned to offer much larger sums to specific types of serious flaw.

It remains true that bug hunters can get larger rewards by offering significant flaws to other vendors.

Earlier this year Google paid out a record $31,000 bug bounty to a University of Luxembourg researcher for spotting flaws in the O3D JavaScript API.

Monday, 29 July 2013

PayPal opens up bug bounty program to minors

PayPal is opening up its bug bounty program to individuals aged 14 and older, a move intended to reward younger researchers who are technically ineligible to hold full-fledged PayPal accounts.

PayPal's program, which is a year old this month, only applied to those 18 years and older. Under the old rule, participants in the program were required to hold valid accounts, which excluded minors, said Gus Anagnos, PayPal's director of information security.

In May, 17-year-old Robert Kugler, a student in Germany, said he'd been denied a reward for finding a vulnerability. PayPal said the bug had already been found by two other researchers, which would have made Kugler ineligible for bounty.

In an apparent miscommunication, Kugler said he was initially told he was too young rather than the bug had already been discovered. Nonetheless, PayPal said it would look to bring younger people into its program, which pays upwards of US$10,000 for remote code execution bugs on its websites.

Those who are under 18 years old can receive a bug bounty payment through a PayPal student account, an arrangement where a minor can receive payments via their parent's account, Anagnos said.

Anagnos said other terms and conditions have been modified to make its program more transparent, such as clarifying which PayPal subsidiaries and partner sites qualify for the program.

PayPal pays much less for vulnerabilities on partner websites, which have a URL form of "www.paypal-__.com." A remote execution bug found on that kind of site garners only $1,500 rather than up to $10,000 on the company's main sites.

Like other bug bounty programs run by companies such as Microsoft and Google, PayPal will publicly recognize researchers on its website with a "Wall of Fame" for the top 10 researchers in a quarter. Another "honorable mention" page lists anyone who submitted a valid bug for the quarter.

Eusebiu Blindu, a testing consultant from Romania, was one of the researchers listed on the Wall of Fame for the first quarter of this year.

"I think Paypal is the best bug bounty program, and I am glad I participated in it from the first days of its launching," he wrote on his blog.

Monday, 8 July 2013

Pogue's Posts: Photoshop’s New Rental Program, and the Outrage Factor

My review of Photoshop CC on Thursday — especially its availability only as a rental, with a monthly or yearly subscription fee — generated a lot of reader feedback. Some of it was astonishing.

Here’s a sampling, with my responses.

Can you rent for a few months, stop for a couple of months, resume as needed, stop as desired? That could have advantages for non-pros.

Yes, you can. That’s the purpose of the month-to-month rental programs ($30 a month for a single program, like Photoshop). Of course, having the software is much less expensive if you agree to rent for an entire year ($240 a year instead of $360).

There is an alternative to Photoshop you didn’t mention: GIMP. It has one big advantage: it is free.

Many readers wondered why I didn’t mention the free GIMP program. It does indeed do most of what Photoshop does. I’ve found it to be even more dense and complex than Photoshop. But since it’s free, everyone who’s unhappy with Adobe’s new rental program for Photoshop should definitely give it a try.

Good article but you fail to mention what happens with plug in programs. Many of us find programs like the Nik series to be much better at doing some adjustments than Photoshop. How does CC handle this?

Exactly the same way. Remember: Photoshop CC is a program that you download to your computer and run from there — exactly like previous Photoshop versions. Nothing changes in the way it works with plug-ins.

Does Adobe actually pay you for mindlessly reprinting their press releases and calling it “news”? An actual journalist would have at least mentioned that huge numbers of Photoshop users are FURIOUS about this sleazy move by Adobe and are refusing to go along with it. More than 35,000 people have signed a Change.org petition to demand the restoration of the perpetual license. Lots of people are going to be seriously hurt by your journalistic malpractice.

I was stunned by the number of readers who came away from my column thinking that I am a fan of Adobe’s new rental-only program. In fact, I thought that I had written a 1,300-word condemnation of this practice.

“You have to pay $30 a month, or $240 a year, for the privilege of using the latest Photoshop version,” I wrote. “Adobe isn’t offering the rental plan — it’s dictating it. The 800-pound gorilla of the creative world has become the 1,600-pound gorilla.”

I then listed alternatives to Photoshop, and concluded: “Nobody knows what improvements Adobe plans to add, how many, how often, or what the subscription rates will be next year or the year after that. Adobe is just saying, ‘Trust us.’”

As for the Change.org petition with 35,000 signatures: Somehow my readers managed to miss this paragraph in my column:

“The switch to a rental-only plan may sound like a rotten deal for many creative people, especially small operators on a budget. And, indeed, many of them are horrified by the switcheroo. A touching but entirely hopeless petition (http://j.mp/1aynMtK) has 35,000 signatures so far. (‘We want you to restart development for Adobe Creative Suite 7 and all future Creative Suites,’ it says. ‘Do it for the freelancers. For the small businesses. For the average consumer.’)”

It’s possible that what angered these readers so much is my reference to the petition as “touching but entirely hopeless.” This is not a put-down of the petition. This is a simple acknowledgment that companies like Adobe have already factored in the anger.

Remember when Netflix raised the price of its most popular DVD rental/streaming-movie price by 60 percent? A million people canceled their Netflix subscriptions.

An employee told me at the time that, incredibly, Netflix’s spreadsheets showed that the company would still come out ahead, even with the mass defections. Netflix had already factored the anger into its business plan.

And that’s exactly what Adobe’s spreadsheets show. Even if the predicted number of angry customers abandon Photoshop, the total annual revenue for Photoshop will increase as a result of the rental-only program.

That’s why the petition is utterly hopeless. Adobe won’t change its course, because Adobe doesn’t care about those people. It already considers them a lost cause.

It’s very clearly a case where customer happiness is being sacrificed for more profit. And that’s the most upsetting part of all.

Follow me on Twitter @sajilpl