Skip to content

Comment on How I could delete any video on YouTube

Comments

I don't think we should correlate the reward with the impact of the bug. Going that route, even 20k is not really enough.

I don't see your point. If such a vuln could cause damage massively bigger than 20k, why is it so stupid to reward the one who found it with a corresponding amount?

I actually agree $20K would seem fairer here, but to answer your question, one reason it may not correlate closely is that you're only referring to the demand side, ie how valuable is this discovery to Google?

The compensation level also comes down to the supply side - how many other people might have discovered this bug shortly after this?

For this reason, there's probably a good argument to increase the reward according to how long the vulnerability was present, to the extent that's knowable. (More so with an open source libraries under version control than a website.)

if a bug is found that can do $1 billion of damage to Google (easy to imagine, they operate at a huge scale) would you expect it to be worth any significant percentage of that? at some point incentives stop scaling.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.