needs a third way
Google needs to add a third technique to their algorithmic and manual ones: bounties.
Offer substantial sums for evidenced exploits.
That way, you've got some of the good guys being rewarded for debugging Google's own code; plus some of the bad guys will find it more profitable to sell their exploits to Google rather than to the bad guys who monetarise exploits.
A couple of million paid out in public QA bounties will radically change the balance of power,


