I co-manage https://hackerone.com/googleplay and the top contributor there probably makes 5x - 10x of an average software engineering salary for his home country.
Not a lot of hackers care about Android app security so there's barely any hackers participating and little competition. Most apps have never had anybody do a security review.
Additionally the scope of the program is so wide that you can look through hundreds of apps from companies that have no security posture at all. Finding bugs is easy and payouts are more than generous.
Great summary! By nature of my job (eng lead of a major mobile malware detection team) I have a lot of startups pitch their ML solutions to me. A couple of thoughts:
- There are no publicly available data sets for training available. There are a few small ones and a few old ones, but they don't reflect the reality of 2016. Companies that approach me and pitch me solutions to the malware of 2012 are not useful.
- The majority of mobile malware is based on some kind of social engineering. On a code level these are indistinguishable from legitimate applications (the same APIs are used in the same fashion). The only difference is whether app behavior meets user expectations or not. Making this decision automatically seems intractable so far.
- Malware is not really a well-defined term. There is phishing, toll fraud, Trojans, privilege escalation exploits, ... If you generically look for malware, the signals you will look for are going to approach the complete set of APIs made available by your OS. Your results will just be a giant blob where everything is connected. Pick a single malware category and focus on just that at a time. ML signals for priv esc will look very different from those for phishing.
- ML is sexy. Malware analysis is not. Startups seem to hire too many ML people and not enough malware analysis people. I've had startups pitch to me that had literally zero people on staff who knew what mobile malware actually looked like. They just did anomaly detection and then tossed the results over to my team to verify the results. That's not how it works. We're not your QA team. :)
I've had the exact same experience with Vint (https://www.joinvint.com/) - Go through personal trainers until you find one you like and then move off the app. The hourly cost will be lower but the personal trainer will still make more money.
I've also had Uber Black drivers give me their personal limo service business cards. The difference is that a cab is a commodity while a personal trainer is something that needs to click on a personal level.
I see no future for Vint even though I loved it when I used it.
The website a weekend project, not something I care for whether people use it. On average it has five to ten visitors a day unless linked to from somewhere big which only happens like twice a year.
Possibly, but not on the free tier. Anyway, our current plan can only handle 20 concurrent connections to Postgres and I am not planning to pay more to satisfy spikes.
I got the silent treatment twice when trying to interview at Yahoo and once with Google. In all cases it was at the stage between initial recruiter contact and agreeing on a date for the first phone screen. I later found out (by looking up the recruiters on LinkedIn) that both of the Yahoo recruiters had left Yahoo and now worked at Apple. Ever since then I started wondering how big the impact of recruiters turnover is on candidates getting stalled.
When you say you're an international student, do you mean you're in the US on an F-1 visa? If yes, you might be in violation of your visa terms. If you have not researched this, please start reading at http://www.justanswer.com/immigration-law/330cd-holding-f-1-...
They do report the actual wage. Except that's the employer can choose to specify it as a range between a minimum and a maximum. This is optional, it's also possible to specify just one number.
Not a lot of hackers care about Android app security so there's barely any hackers participating and little competition. Most apps have never had anybody do a security review.
Additionally the scope of the program is so wide that you can look through hundreds of apps from companies that have no security posture at all. Finding bugs is easy and payouts are more than generous.