Google Increases Rewards for Bug Catchers...Again
Google sees a significant drop-off in reported security issues and hopes to increase efforts by introducing more bonuses.
Earlier this year Google increased its bug bounty drastically, offering an award of up to $20,000 in comparison to its previous top reward of $3,133.70.
Now, the company is giving even more incentives to crafty bug catchers out there.
On Tuesday, Chrome software engineer Chris Evans (not to be confused with Captain America) stated in the Chromium Blog, "Recently, we've seen a significant drop-off in externally reported Chromium security issues. This signals to us that bugs are becoming harder to find."
According to the engineer, Google will be awarding researchers additional bonuses starting from $1,000 and increasing based on the severity of the bugs. The bonuses will be added to the current base payments, which range anywhere from $500 to $3,133 for "particularly exploitable" bugs found in Chrome's code and for vulnerabilities that affect additional browsers.
The bug bounty program changes were immediately put into effect, but the company graciously gave $1,000 and $3,000 bonuses to recent bug reporters who were eligible under the new program. In addition to the bonuses for bug reporting, Google also hopes to increase activity in the Chromium community by offering additional bonuses of $500 to $1000 to any bug catcher who joins the community and provides a peer-reviewed patch.
An outsider will think 'outside the box'; and get paid only if he/she finds something.
Then you can imagine the google employee being terminated, having their benifits revoked for defrauding / embezzling, then going to "federal pound you in the ass" prison...
This is crowd sourcing at its finest.
Dude, just reading your comments makes me ROFL. You are pretty good with catching every negative side and slapping it on the forums. I guess you picked your name pretty well. I usually thumb you up just for the negative spin.
On this one, however, I have to give the point to dalethepcman. Just because this system is so much in the open nobody can expect to do that and get away with it. And we all know by now how sweet is to be a Google employee.....
Why don't more companies do this? Of course I also see the flip side of how a relesed product shouldn't have major bugs (hah!).
Most companies don't release a product with a billion dollars worth of bugs in it
Or, they're so cheap that they couldn't bother bug-checking in the first place.