5 ms·
Meet the bughunters: the hackers in India protecting your data
- nxzero 10y agoAmazing that all publicly traded companies are not by law required to have bug bounties. Same goes for any major open source project too.
- ludamad 10y agoAt what point should a piece of software have a bug bounty? It seems forcing bug bounties would cause them to become purposefully convoluted to obtain
- nxzero 10y agoJust even having a page, with a small bounty, and a secure means of submitting a exploitable bug. If you want to dig deeper, I'd contact professional bug hunters and ask them how to insure that the value on the bug matches the reward.
- ugexe 10y agoAnd if you can't afford to pay a bounty just don't write software right? Don't you think it's odd your answer to what you are replying to is "I have no idea, ask someone who knows" yet you feel compelled to weigh in on who should not be allowed to write/distribute software?
- nxzero 10y agoUnclear why you believe that a major software project would not be able to find a sponsor for a bug bounty; in fact, many major projects already have bug bounty sponsors. Also, why would it be strange to suggest talking to someone other than myself?
- ashitlerferad 10y agoOpen source projects rarely have a budget for development, let alone bug bounties.
- cderwin 10y agoYes why don't we incentivize companies to keep more software closed source than already is
- hntuesday 10y agoNobody should have to offer bounties. Researchers should not expect to get paid for their unsolicited work. We probably agree that vulnerability reports should be seen as a positive thing. What software owners should have are policies and procedures for transparently handling vulnerability disclosures. At most, I think having some flexible process should be required as part of a certification (PCI, etc). I do think that knowledge of a vulnerability and lack of action to fix it in a reasonable amount of time, which results in a breach should be treated more seriously. At the same time, encouraging reports of breaches is hard as it is and introducing more punishment would make everyone want to just keep quiet or as ambiguous as possible. I'm not sure what a good solution to this would be.
- cmdrfred 10y ago> Nobody should have to offer bounties. Researchers should not expect to get paid for their unsolicited work. The Chinese and Russian exploit markets don't seem to care if the work was solicited or not.
- zhte415 10y agoPublicly traded companies are required to face fines for negligence, for information leaks, fraud, or other. As are all companies. If they choose bug bounties to help with this, good for them. If they choose other measures, also good too. They simply need to show they take effort to protect information as dictated by information security laws, or internal policy, whichever is stricter.
- kevin_thibedeau 10y agoMaybe in Euro-land. In the US companies with data breaches are the hapless victims of those nasty hacker types. You wouldn't want to blame the victim would you? Never mind that they have a column of plaintext passwords in a web accessible server.
- debarshri 10y agoI think guardian didn't do their homework right. Apparently Rahul tyagi just like Ankit fadia is considered to be a con-artist. https://news.ycombinator.com/item?id=4316574 https://news.ycombinator.com/item?id=4316574
- OJFord 10y ago> rupee millionaire I don't wish to put down Mr Prakash's achievements, but is that actually a celebrated figure in India - or at ~£10.6k is the word 'millionaire' just a sensationalism for our benefit?
- ing33k 10y agoapprox 1 year salary for a guy working in IT sector with 2-3 years experience
- zhte415 10y ago~£10.6k is an OK figure in India, but depends where you are and what you do. In an international company, doing UAT type testing and investigation, it would be about average for an assistant manager, but the variance is vast, even between people sitting next to each other. If that figure is per month, then he's really doing well, pulling in the same as an SVP in an international company managing a team doing a similar role.
- OJFord 10y agoRight, he's doing well but it seems odd to say to a predominantly British audience that he's a "multi-millionaire [in rupees]", when actually the implication of that is 'hugely successful, doesn't need to work', rather than 'successfully self-employed/running his own business'. Congratulations and all the best to him, of course, I just think it's a misleadingly sensationalised subtitle.