By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Google Pauses Open Source Bug Bounty Rewards

Google has halted its bug bounty program for vulnerabilities found in its open-source software products, a change that took effect on October 1. This decision means security researchers can no longer submit reports detailing security flaws discovered in the code of widely used projects like Go, Angular, and Protocol Buffers to receive monetary rewards. The company stated that the pause is a response to a significant increase in invalid reports, many of which are automated submissions that do not represent genuine security vulnerabilities. While bug bounty submissions for open-source product vulnerabilities are paused, Google continues to accept reports related to supply chain compromises. Furthermore, any valid vulnerability reports that were submitted and accepted before the October 1 deadline will still be processed and rewarded according to the program's existing terms. This move impacts the ecosystem of developers and security researchers who rely on bug bounty programs to identify and fix security issues in open-source projects, often contributing to the overall security posture of the software supply chain. Open-source software is a critical component of the modern technology landscape, underpinning many applications and services. Google's decision to pause these rewards raises questions about the future of security research incentives for its open-source contributions and could potentially affect the speed at which certain vulnerabilities are discovered and addressed. The company has not yet provided a timeline for when the bug bounty program for open-source products might resume or what specific changes might be implemented to address the issue of invalid reports. The bug bounty program, in general, is designed to incentivize ethical hackers and security researchers to find and report security weaknesses in software before malicious actors can exploit them. Rewards can range from small sums to tens of thousands of dollars, depending on the severity and impact of the vulnerability. The pause specifically targets vulnerabilities within the code of Google's open-source projects, distinct from vulnerabilities in Google's own products and services, which are typically covered by separate bounty programs. The increase in automated, low-quality submissions has been a growing concern across various bug bounty platforms, as it consumes valuable time and resources for program managers who must sift through these reports. Google's action highlights the challenges in managing large-scale bug bounty programs effectively, particularly when dealing with the vast and diverse landscape of open-source software. The company's commitment to open source remains, but the mechanism for incentivizing external security research for its OSS products has been temporarily suspended.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.