Hacker News new | ask | show | jobs
by mbertschler 3132 days ago
Does reward 100000 mean 100k$ in bounty?
2 comments

Yes. https://www.google.com/about/appsecurity/chrome-rewards/

> We have a standing $100,000 reward for participants that can compromise a Chromebook or Chromebox with device persistence in guest mode

Searching by label shows only another instance of a bug that got paid that amount:

https://bugs.chromium.org/p/chromium/issues/detail?id=648971...

It was actually reported by the same guy!

There is another persistent exploit, by GeoHot, that earned $150,000: https://bugs.chromium.org/p/chromium/issues/detail?id=351788
I wonder if s/he save a bunch of bugs to chain together a single big exploit. From the latest report, there was 6 bugs chained together.

Imagine reporting 6 small bugs individually that nets you 6 x 1000$ = 6k$. But if you save each one, it may chain together for a potential 100k$ bounty. Of course, any insight that reveals these underlying relations is most certainly worth 100k$.

AFAIUI (not a security researcher) that's actually how most of the most devastating security exploits work. There are obvious exceptions like HEARTBLEED, but in general escalation through multiple levels seems to be the name of the game.
Or you can just get root from javascript, which that guy also did
If they care about security, they shouldn't pay more for chaining, because that gives security researchers incentive to hoard vulnerabilities, rather than report them ASAP.
> i hope it's delivered via absurdly large check :D

this would be awesome