4 ms·
common response to why companies don't pay a ton of money for these exploits [1] [1]: https://news.ycombinator.com/item?id=11249173 https://news.ycombinator.co
by dev1n 10y ago
common response to why companies don't pay a ton of money for these exploits [1]
[1]: https://news.ycombinator.com/item?id=11249173 https://news.ycombinator.com/item?id=11249173
- nickpsecurity 10y ago"Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook? The only vulnerability worth $15,000 or more is one directly impacting a language, a widely used development library/framework or a widely used piece of software." I think that statement might apply here given the FTA issues. Hackers could've gotten plenty mileage out of it. Especially if others at Facebook, like their AI team, used it for something that's a trade secret. That's speculation but it's not like hacking a news feed.
- EthanHeilman 10y agoIts not just the value to the finder but the cost to facebook. Generally the profit an attacker makes is an order of magnitude less than the cost they incur.
- nickpsecurity 10y agoGood point. That should be factored in.
- arcticfox 10y agoAnd I still think that line of thinking is bullshit. The bottom line is that the dollar value for this stuff is arbitrary, and Facebook arbitrarily picking $10,000 for getting COMPLETELY OWNED and exposing any selection of personal data (in the case of the other bug, this one seems to have the potential to be even worse due to credential stealing, although it's murkier) is pretty gross IMO. I don't know what the number should be - again, it's arbitrary - but in my personal book $10,000 is about 10x too low.
- dsacco 10y ago>> And I still think that line of thinking is bullshit. You haven't given any real refutation to the comment linked by the parent. How qualified is your opinion? You're entitled to it, but know that most bug bounty participants and members of the actual security industry disagree with you.
- arcticfox 10y agoMy refutation is in the linked discussion. And I'm reasoning from economic first principles, not experience in the field. From first principles, I don't understand the argument that $10,000 is fair. At least, I don't understand that argument any more than why $10 is fair - which is my point, that it's arbitrary. And in my arbitrary opinion, $10,000 is grossly low compared to the relative work involved and money at stake. The FBI just paid $1M to access one guy's iPhone. The vulnerability in the linked discussion, which was guaranteed access to any FB account, was a $10,000 bounty. IMO those numbers need to be a lot closer together. Edit: $15,000
- EthanHeilman 10y agoGiven that a vulnerability may be exploited by a malicious party and that this could cost facebook X millions of dollars: How much should facebook pay for vulnerabilities to reduce the risk of Such an event? That is, given some cost/benefit model what is the ideal price for a particular class of vulnerability? This suggests two related questions, 1. how does buying vulnerabilities reduce the risk of a malicious use of a vulnerability and 2. by how much? I suggest two answers for question 1: First buying a vulnerability and then patching it prevents that vulnerability from being used by an attacker. It only makes sense to do this if vulnerability are very rare, since the more rare they are the greater the benefit of fixing them. Second someone who discoveries a vulnerability might have a human urge for recognition and/or payment. "I did the work, I deserve some credit/payment". In this case facebook is competing with the vulnerability blackmarket, but facebook has an inherent advantage (all things being equal a legal dollar is more beneficial than an illegal dollar and you get bragging rights which has both intrinsic and monetizable value). I have no idea how to answer question 2 as it is quantitative. Perhaps an economist has written pricing models for bug bounties and how this should impact cyber-insurance premiums?
- andrewprock 10y agoThe usual way to evaluate this is to consider the chance of being discovered (D) times the chance of being used as an exploit (E) times the cost of the exploit (C) with an appropriate discount factor (F). Think of the discount as the wholesale price of the exploit, what a mal actor might pay for the exploit. For example, if there was a 1% chance of discovery, and a 50% chance of the person discovering it using it as an exploit, and it cost them 1 day of revenue ($50m) and they used a discount factor of 10%, that would indicate that the bounty would be worth about C * D * E * F = $25k. If it's likely that the exploit would only last 5 hours, then $10k is a reasonable bounty.
- mkagenius 10y ago> Cost of revenue That itself is pretty vague to determine as a hack could have an impact on reputation and the impact might not be limited to just one day. Future users might be afraid to use the product, current users might leave in few weeks.
- awqrre 10y agoI guess the only way to find out if that's true is to try and use the black market first?
- tptacek 10y agoGood luck with that. "The black market" isn't buying vulnerabilities in 3rd party serverside components at Facebook.