4 ms·
> paltry $15k The tech/security community is crazy.
by bracewel 11y ago
> paltry $15k
The tech/security community is crazy.
- malka 11y agoNo. YOu have to compare that number to how much you could get for that exploit on the black market. 15K seems cheap for a critical bug on a major platform.
- aianus 11y agoFor many qualified technical people, $15k + recognition is worth more than $500k + guilt + possible prison / looking over your shoulder for years.
- nostrebored 11y agoWell the parent seemed to miss the point -- the real calculus is cost to the company if the exploit were to be used effectively, monetary benefit to the person who finds the bug, and the recognition you'd get in the blackhat community.
- Dwolb 11y agoYes the payout calc by company is cost to the company of an exploit, but with a repeated game scenario. i.e. you can't look at the bug and payment in a vacuum, you have to factor in future bugs. So the cost is the value to the company for the exploited bug if used properly plus the expected value of future bugs. Which is weird, right? This shows companies can be internally incentivized to reduce bug bounty payments to show 'they are improving' when in fact, developers are leaving their bug bounty program.
- tptacek 11y agoIn virtually every case for these bug bounty programs, that number is zero dollars.
- acomjean 11y agoObligatory: "I'm going to write me a new minivan" or "lets hope this drives the right behavior" [1995] http://dilbert.com/strip/1995-11-13 http://dilbert.com/strip/1995-11-13
- dsacco 11y agoTo be clear, it's not all researchers who believe this. It's just an (annoyingly) vocal minority.