• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Android and Google Play Security Rewards Programs Surpass $3 Million in Payouts

cageymaru

Fully [H]
2FA
Joined
Apr 10, 2003
Messages
22,839
For the past 3 years, Google has been paying top researchers for submitting vulnerability reports about flaws and bugs in the Android ecosystem. Recently the Android Security Rewards (ASR) just exceeded the $3 million mark in rewards to researchers. This year alone 470 qualifying vulnerability reports were filed and the average pay per researcher increased by 23%. The ASR average is $2,600 per reward and $12,500 per researcher. One researcher received $105,000 for a remote exploit chain submission.

In October 2017, we rolled out the Google Play Security Reward Program to encourage security research into popular Android apps available on Google Play. So far, researchers have reported over 30 vulnerabilities through the program, earning a combined bounty amount of over $100K. If undetected, these vulnerabilities could have potentially led to elevation of privilege, access to sensitive data and remote code execution on devices.
 
Cheaper than paying for employees, hobbyists have something fun to do, bugs get fixed. Win win for everyone.
 
"these vulnerabilities could have potentially led to elevation of privilege, access to sensitive data and remote code execution on devices"

Good. Now how do we stop Google from exploiting access to sensitive data? Oh, right. We can't.
 
"these vulnerabilities could have potentially led to elevation of privilege, access to sensitive data and remote code execution on devices"

Good. Now how do we stop Google from exploiting access to sensitive data? Oh, right. We can't.
Report it as a bug and get paid :)
 
Back
Top