Site icon Auspreneur

Bounty seekers are drawn to open source projects by Google

Google Plans to Land New Subsea Cables at Maroubra Beach

Image Credit The Indian Express

A bug bounty programme for Google’s open source projects has been added.

A tip of the hat to calculator-speak for “eleet,” the company’s open source projects include well-known software such as the Go programming language, the Angular web development environment, and the Fuchsia operating system, with confirmed bugs to earn their discoverers between US$100 (A$147) and US$31,337.

The Bazel build system and Protocol Buffers, which are used to serialise structured data, are two more well-known projects that are now eligible for the reward.

Francis Perron, manager of Google’s open source security technical initiative, and Krzysztof Kotowicz, an information security engineer, wrote: “After the initial release we hope to expand this list.”

According to the couple, the program’s current primary concerns include “vulnerabilities that result in supply chain compromise, design flaws that result in product vulnerabilities, and other security issues including sensitive or leaked credentials, weak passwords, or insecure installations.”

“Supply chain compromise” refers to “the ability to compromise the Google OSS source code and create artefacts or packages that are distributed to users via package managers.”

Simple problems like memory corruption, sanitization failure, path traversal, poor defaults, or even insecure code samples in documentation constitute product vulnerabilities.

Sensitive credentials, weak passwords in third-party goods, or installation and usage instructions “that compromise the security of the developers working on the product” are some other categories of defects that will be recognised.

Because Google is aware of the dependencies that support open source projects, it specifically includes third-party vulnerabilities in the program’s purview.

Google will accept a vulnerability if it may be used to trigger or exploit a Google open source product and is disclosed no sooner than 30 days after the upstream fix is ready, as long as a researcher tells the maintainer of the third-party package.

However, third-party “services or platforms” are not included.

There are three project tiers: regular OSS projects; low-priority OSS projects; and flagship projects (Bazel, Angular, Golang, Protocol buffers, and Fuscia) (these may be experimental, samples, small, or low-activity projects).

Exit mobile version