• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

February 5, 2026

10 Hidden iPhone Features You’re Missing in iOS 26

February 4, 2026

Apple Watch Ultra 3 review: Incremental, but still superb

February 4, 2026
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Tech News»Google debuts open source bug bounty programme
Tech News

Google debuts open source bug bounty programme

September 1, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Google debuts open source bug bounty programme
Share
Facebook Twitter LinkedIn Pinterest Email

Google has added a strand to its secure of vulnerability rewards programmes (VRPs) with the launch of a devoted open supply software program (OSS) monitor that may reward hackers who disclose bugs in Google’s open supply tasks.

Its present VRP programmes date again to 2010 and have collectively rewarded over 13,000 submissions with pay-outs of greater than $38m (£33m) masking a number of merchandise, together with the Android cell working system (OS) and Chrome internet browser.

Google maintains a number of OSS tasks together with internet improvement platform Angular, working system Fuchsia, and programming language Golang. The launch of its OSS VRP is a major second for the search large, reflecting a rising variety of OSS vulnerabilities uncovered in latest occasions, which give gateways for risk actors into a number of potential victims.

Excessive-impact provide chain assaults enabled by OSS vulnerabilities embrace the April 2021 compromise of code auditing service Codecov, and Log4Shell, the implications of which proceed to echo all over the world 9 months on.

“Google is proud to each assist and be part of the open supply software program group. By means of our present bug bounty applications, we’ve rewarded bug hunters from over 84 nations and look ahead to growing that quantity by this new VRP,” wrote Google’s open supply safety technical programme supervisor Francis Perron, and data safety engineer Krzysztof Kotowicz.

“The group has constantly stunned us with its creativity and willpower, and we can not wait to see what new bugs and discoveries you may have in retailer. Collectively, we will help enhance the safety of the open supply ecosystem.”

See also  Amazon’s putting a three-day pause on reviews for The Rings of Power

The programme has been designed to encourage researchers to reveal vulnerabilities which have the best potential, or precise real-world impacts. It should cowl all up-to-date OSS variations saved within the public repositories of Google-owned GitHub organisations. Additionally in scope are these tasks’ third-party dependencies, though notification to the affected dependency can be required pre-submission to Google.

Apart from Angular, Fuchsia and Golang, the preliminary rollout will concentrate on two different notably delicate tasks – Bazel, a build-and-test platform; and Protocol Buffers, a mechanism for serialising structured knowledge – all of which can obtain the highest awards, doubtlessly as excessive as $31,000. Google stated it was more likely to develop this record in future.

Perron and Kotowicz stated they have been notably eager to listen to about vulnerabilities that might result in provide chain compromise, design points that might trigger product vulnerabilities, and points reminiscent of delicate or leaked credentials, weak passwords, or insecure installations.

Hackers who’re enthusiastic about getting began on the brand new OSS VRP programme are inspired to take a look at the programme’s guidelines, that are set out intimately right here.

Extra broadly, the OSS VRP types a part of a $10bn spending dedication made by Google in August 2021 at a gathering of among the largest tech firms on this planet, together with Amazon, Apple, IBM and Microsoft, which got here collectively at a White Home summit to assist president Biden’s cyber safety motion plan.

Apart from OSS safety Google can be investing in zero-trust and provide chain safety, and plans to assist greater than 100 thousand individuals acquire entry to industry-recognised digital expertise certifications.

See also  I just bought a Nvidia RTX 3070 for MSRP because the GPU shortage is over

Source link

bounty bug debuts Google open programme source
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

I love the Google Pixel wristlet accessory – but it has a big problem

December 6, 2025

I hate to say it, but don’t buy the Google Pixelsnap Stand

October 23, 2025

Google Pixel Watch 4 review: Pebble perfection

October 17, 2025

Google Pixel 10 Pro Fold review: Refinement, not revolution

October 8, 2025
Add A Comment

Comments are closed.

Editors Picks

Hardspace: Shipbreaker console release date confirmed

August 27, 2022

August ’22 a bumper month for high-impact vulnerabilities

September 10, 2022

The Investor’s Pitch Deck Checklist For 2023

February 23, 2023

The Oura Ring 4 and Gen 3 are two of the best smart rings, but which should you buy?

April 23, 2025

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Xiaomi Robot Vacuum 5 Pro review: A robot vacuum you can trust to do its job

10 Hidden iPhone Features You’re Missing in iOS 26

Apple Watch Ultra 3 review: Incremental, but still superb

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.