Google and the open source community have a strong relationship. Google has contributed significantly to the open source code available, including through programs like the Google Summer of Code where open source developers are given a cash stipend to help them continue their project. Further, much of Google’s internal development is created as open source, with assistance in debugging and security being provided from the open source community.
One of the most powerful ways this manifests is in the Google Chrome web browser, which is broadly seen as the most secure browser around. To secure this browser fully, Google offers a “bounty” to anyone who can discover a security hole anywhere in the development sandbox. In 2010, the company gave over $14,000 in bounties, with cash out amounts ranging from $500 to $3,133.70. The “high end” figures of $1,337 and $3,133.70 are both based on gamer terms (“leet” and “eleet”).
Google made so much progress that in the Pwn2Own hacking competition last year, theirs was the only browser not be to hacked. Meanwhile, competing browsers were fully accessed remotely thanks to security holes. Hackers, who stood to gain up to $10,000 for hacking Chrome, even complained that the amount was insufficient for how difficult it was to break through Google’s security. As a result, and thanks to the presence of so many other more hackable browsers, the Pwn2Own competition decided to exclude Google this year.
On hearing this news, however, Google made an appeal to the competition hosts, offering $25,000 in prize money for a successful hack of their browser — on top of the $15,000 offered by the competition itself as a maximum this year. This is the polar reverse of how most companies behave in the Pwn2Own competition, since many companies appeal to have their software removed from the competition each year, not wanting the exploits to be found, spread, or publicized.
