Following the success of the program awarded to those who discovered the vulnerability of the Chrome browser, Google now says it will pay cash for these vulnerabilities are announced on the website. Google said the program "test" will encourage security researchers reported vulnerabilities web directly to Google's security team. "We hope their new program will attract many new researchers and other reports to help make our users more secure, “Google said in a blog post notification program.
The idea of the program is to help Google a chance to plug the holes before the bad guys were exploiting them. So to qualify, the first researchers to disclose security vulnerabilities on the new Google own research prior to their public. In return, the researchers are eligible will receive a cash reward of 500 dollars to $ 3,133.7, depending the severity of this vulnerability.
However, Google does not pay for all the defects in their products. For example, there is no bonus for finding bugs in Android, Picasa or Google Desktop. Web-based attack involves experimenting with Google's servers, not the software is downloaded by the computer researchers. Thus, while conducting research, those who do this risk violating the law or may even disrupt Google services.
To prevent these things happen, Google has given some guidance on what satisfies the criteria and what is not in the program. The company will not pay for the error from denial of service (Dos) or for errors in the infrastructure of the company's business. The participants should not use automated tools to find vulnerabilities.



Reply With Quote
Copyright Techfuels
Bookmarks