Outsourcing the security

[Google spokesman]: "Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, Control Flow Integrity or LibFuzzer."

Begs the question: why doesn't Google use these free tools to check their code?

Is it cheaper to dish out perhaps $200K a year to these hackers than to do it in-house?

