Ally Fashion

Wednesday, March 29, 2017

Project Zero Prize Conclusion

 ana05     March 29, 2017     No comments   

Posted by Natalie Silvanovich, Project Zero

On September 13, 2016 we announced the Project Zero Prize. It concluded last week with no prizes awarded. The purpose of this post is to discuss what happened and what we learned about hacking contest design.

Throughout the contest, we did not receive any valid entries or bugs (everything we received was either spam, or did not remotely resemble a contest entry as described in the rules). We did hear from some teams and individuals who said they were working on the contest, but they did not submit any bugs or entries. Based on our discussions with them, as well as our general observations during the contest, we suspect that the following factors led to the lack of entries.

Entry Point Difficulty

It is rare for fully remote Android bugs to be reported, and it is likely that this was a sticking point for participants. The majority of Android bug chains begin with some user interaction, especially clicking a link, which was not allowed in this contest. While this type of bug is not unheard of, it is likely difficult to find quality bugs in this area. This means that the timeframe of the contest or prize amount may not have been adequate to elicit this type of bug.

Competing Contests

The Project Zero Prize rules were intended to encourage participants to file partial bug chains in the Android bug tracker during the contest, even if a full chain was not complete. In designing these rules, we underestimated the impact of other contests on participants’ incentives. The contest rules allowed for bugs that had already been filed to be used by the first filer at any point during the contest, and receive Android Security Rewards if they were not used as a part of a chain.  We expected these rules to encourage participants to file any bugs they found immediately, as only the first finder could use a specific bug, and multiple reports of the same Android bug are fairly common. Instead, some participants chose to save their bugs for other contests that had lower prize amounts but allowed user interaction, and accept the risk that someone else might report them in the meantime.

Prize Amount

It’s difficult to determine the right prize amount for this type of contest, and the fact that we did not receive any entries suggests that the prize amount might have been too low considering the type of bugs required to win this contest.

Overall, this contest was a learning experience, and we hope to put what we’ve learned to use in Google’s rewards programs and future contests. Stay tuned!
Also, if there were any aspects of the Project Zero Prize that affected your participation that we could improve, we would like to hear from you, either in the comments, or at project-zero-prize@google.com.

  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook
Newer Post Older Post Home

0 Comments:

Post a Comment



Popular Posts

  • READY FOR FALL! MY RECOMMENDATIONS
    Autumn is around the corner which means darker tones for makeup! In this post I will be sharing my favourite products for lips, cheeks and e...
  • A tan really completes a make-up look
    We have been obsessed with tanning since we were around 13/14 because we live in England and there is barely any sun here and we look so was...
  • Adobe Photoshop 7.0 Full Version Free Download | Adobe Photoshop 7 Final Version Download | Photoshop 7 Professional Version Download 32-Bit and 64-Bit
    Adobe Photoshop 7 Full Version Free Download Original Adobe Photoshop 7.0 +License Key. Adobe Photoshop 7 Professional Version Free Download...
  • Virtually Unlimited Memory: Escaping the Chrome Sandbox
    Posted by Mark Brand, Exploit Technique Archaeologist. Introduction After discovering a collection of possible sandbox escape vulnerabiliti...
  • Did the “Man With No Name” Feel Insecure?
    Posted by James Forshaw, Taker of Names Sometimes when I'm doing security research I'll come across a bug which surprises me. I disc...
  • Driver Pack Solution 2018 Latest Version Download
    Driver Pack Solution 2018 Latest Version Download Driver Pack Solution 2018 Latest Version Download ISO for Windows User 32 bit & 64 bit...
  • [Ezoteryka PL] Węzły księżycowe - The North Node & The South Node
    Jaki jest cel naszego życia? Patrząc na swoja datę urodzin, możesz wyczytać z niej więcej niż znak zodiaku czy numerologie. Jako, iż postano...

Copyright © Ally Fashion | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates