Latest in Chrome os

Image credit:

Google now rewards Chrome bug hunters all year round

Matt Brian, @m4tt
February 25, 2015
Share
Tweet
Share

Sponsored Links

One way to reduce the number of bugs or exploits in your software is to throw it open to some of the best and most devious minds in the industry and ask them to pull it apart. That's what Google has done with its annual Pwnium conference, where it's rewarded researchers with millions of dollars in Chrome-based security bounties. However, the search giant has decided now is the time to do things a little differently. As of this week, the Pwnium competition is shifting from an annual affair to a "year round, worldwide opportunity for security researchers."

What does this mean? Well, instead of requiring researchers to submit their bugs in March, register for the conference, attend the venue and hope everything goes as planned, they can now do it all remotely. Whenever bug hunters come across an exploit, they can submit it to Google's Chrome Vulnerability Reward Program (VRP) and immediately become eligible for a cash payout. The reasoning is sound: holding time-limited events incentivizes researchers to sit on their discoveries for a cash reward, which means potential flaws could go unpatched and leave users vulnerable.

To promote disclosures, Google's reward pot now stands at "$∞ million," which means that if bugs are identified, disclosed and patched, the people doing the good work can keep adding to their earnings. Researchers requested that the program should be an open affair -- now they've got their wish.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
Tweet
Share

Popular on Engadget

Peter Parker has been recast in ‘Marvel’s Spider-Man: Remastered’

Peter Parker has been recast in ‘Marvel’s Spider-Man: Remastered’

View
Google's 'Hold for Me' Assistant feature appears first on new Pixel phones

Google's 'Hold for Me' Assistant feature appears first on new Pixel phones

View
The Aura Strap adds new tricks to your Apple Watch

The Aura Strap adds new tricks to your Apple Watch

View
Twitter bans deepfakes that are 'likely to cause harm'

Twitter bans deepfakes that are 'likely to cause harm'

View
Here's everything Google announced at its Pixel 5 event

Here's everything Google announced at its Pixel 5 event

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr