Google Halts Open Source Bug Bounties Following Deluge of AI Slop
Google has announced a pause in its Open Source Software Vulnerability Rewards Program (OSS VRP), which encourages white-hat hackers to find bugs in its open-source projects. Why? Because its reviewers are drowning in AI slop. Per the VRP's recent X post, the program has been inundated with poorly put-together submissions relying almost exclusively on AI, making it impossible to continue.
The pause could ultimately be temporary, but it's described as indefinite, and though existing reports will continue, no new bounties will be awarded for future submissions.
Bug bounty systems typically reward pen-testers and altruistic hackers with money for finding a flaw or exploit in a software platform. But with the advent of AI cybersecurity tools, anyone can now use an AI model to find exploits and bugs and submit a report. These kinds of low-effort submissions often contain AI hallucinations, erroneous data, or just verbose coding solutions which...
Copyright of this story solely belongs to www.extremetech.com. To see the full text click HERE