Major tech companies like Meta, Google, and Apple invest significant resources into ensuring the utmost security of their digital platforms. They allocate billions of rupees to defend cyber threats. In a bid to enhance security measures, these companies value and reward tech-savvy individuals who detect hidden dangers and security breaches. Recently, Malayali student Sreeram KL and his friend Sivanesh Ashok were rewarded in the Google Cloud VRP (Vulnerability Reward Program) for their contributions to identifying security flaws within Google's systems and proposing solutions. Sreeram and Shivnesh secured second, third, and fourth places, respectively, in the Google Cloud Vulnerability Reward Program 2022, receiving a total prize of $133,000 (approximately Rs 1 crore).

Participants in the Google Cloud Vulnerability Reward Program can report security breaches discovered in Google services such as search engines, websites, and apps. Anyone can report a breach at any time, and the Google development team promptly addresses the discovered bugs, rewarding and recognizing contributors on the prestigious Leaderboard. The Google Cloud Vulnerability Rewards Program stemmed from this collaborative approach, with participants submitting essays highlighting security vulnerabilities and proposing remedies. 

Membership in the Google Leaderboard is a highly regarded achievement in ethical hackers' careers. Earning a spot on this list is no easy feat.

The ranking and reward amount vary based on the severity and impact of the discovered vulnerabilities, with the top-ranked individual receiving the highest recognition. In 2022 alone, over 2,900 security issues were identified and resolved through this program, with Google investing around 12 million U.S. dollars (approximately Rs 98.4 crores) exclusively for this purpose. In 2022, Sreeram secured the 17th rank globally and the first position in India, a remarkable achievement considering he accomplished this while still being a student. Sreeram reported more than 10 security breaches to Google, cementing his expertise in this field.

The Vulnerability Rewards Program aims to incentivize researchers to enhance Google Cloud security and deliver better services to users. This program includes a report and write-up to identify flaws in Google domains and propose effective solutions. The submitted articles must outline the discovered vulnerabilities, provide solutions, guidelines, and demonstrations. 

They reported and resolved a security breach that could enable hackers to infiltrate Google's data centres and gain access to Compute Engine virtual machines, and a security loophole that could have facilitated unauthorised access to Google's cloud workstations and compromised customer information, and security issues that could leak customer information from Google's Vertex AI. 

Sreeram, a computer science student at HITS Chennai, attended an international conference held at the Google office in London. Out of the individuals who identified a technical error, only one hundred were selected for this prestigious event. Sriram, along with his friends, runs a startup called Squadron Lab in cybersecurity. Hailing from Kanyakumari, Sriram is the son of Krishnamoorthy and Liji and has two brothers.

Understanding ethical hacking

Even seemingly secure websites can fall victim to hackers, resulting in information leaks. However, ethical hackers play a crucial role in safeguarding such platforms. They covertly explore software and hardware systems to uncover vulnerabilities and rectify them legally, ensuring enhanced security. Ethical hackers report any security weaknesses they discover to the responsible authorities, without exploiting them for malicious purposes. Their meticulous approach ensures that even the smallest loopholes are detected to defend against potential cyberattacks from external sources.