Who discovers a vulnerability first can make a big difference to the outcome. If a hacker is the first to find something, it can be incredibly lucrative for them if they manage to exploit it for financial gain.Knowing this, tech companies have taken Ford’s example and offered rewards to anybody who can help them solve problems.Here are the five biggest paying programmes currently out there.
Apple announced at the Black Hat conference that it was launching a programme worth up to $200,000.The programme is currently open only to researchers who have previously made valuable bug disclosures to Apple.It will be invite-only for the time being but is expected to expand to other researchers in time.The top rewards will be given for boot firmware components.Flaws that could allow extraction of confidential information protected by the Secure Enclave could reward up to $100,000.Eligibility is based on the quality of the report, including proof-of-concept, and the clarity of the report and the novelty of the problem.
Microsoft launched its bug bounty programme in late 2013, and has paid out over $500,000.The most lucrative categories are the Bounty for Defense, which allows security researchers to “submit a technical white paper to describe a defensive idea that could effectively block a mitigation bypass technique”, and the Mitigation Bypass Bounty.Qualifying submissions will receive up to $100,000 USD, depending on the quality and uniqueness of the idea.
Meanwhile, the categories of Nano Server technical preview bounty program and Online Services can receive between $500 USD and $15,000 USD. Microsoft states that it could pay out more than this if the ideas are unique enough.
Since Android does not have the same reputation for security as Apple due to its open architecture, it is in Google’s interests to find vulnerabilities in the operating system as quickly as possible.The Android Security Rewards are the main public-facing inlet for these vulnerabilities.Google specifies that the size of the reward depends on the severity of the vulnerability and the quality of the report.The reward increases with the quality of the report, with proof of concepts, crash dumps, CTS tests and patches bolstering the value.A critical vulnerability with a good report could pay up to $8000, while a poor report for a low-severity vulnerability could pay in the hundreds.Google also pays larger amounts, into the tens of thousands, for functional exploits. $50,000 is the prize for an exploit or chain of exploits leading to TEE (TrustZone) or Verified Boot compromise from a remote or proximal attack vector.Google adds that the final reward remains at the discretion of the reward panel.Google also offers to donate the reward to charity, doubling it if this option is chosen.