9 ms·
I know this is a joke, but I am unsure if you're pointing it directly at Tesla. To clarify, Tesla does not have a bug bounty program that I was able to find for
by beeboop 10y ago
I know this is a joke, but I am unsure if you're pointing it directly at Tesla. To clarify, Tesla does not have a bug bounty program that I was able to find for their car software.
- askafriend 10y agoHaha no, I was just poking fun at high profile bug bounty programs like Facebook/Google's which routinely offer pennies for very very serious vulnerabilities. I'm not in a position to discuss bug bounty ethics or judge what the right thing to do is given the market circumstances, I'm only in a position to make an opportune joke. But you gotta admit...it is amusing seeing very critical vulnerabilities like ubiquitous user login being reported by researchers whom get 5k or 10k for doing the right thing. These holes could instantly cripple the trust of a company's userbase and yet the people reporting them get pennies.
- lobotryas 10y agoI'm not seeing what point you are trying to make. What other option do these researchers have? Try to sell the vuln on the black market (illegal) or to a state actor (unethical and likely illegal)? Keep quiet about what they found and not get any money/recognition? Companies are under no obligation to pay and researchers are under no obligation (except ethics, I guess) to turn over their findings. By having some non-trivial payment the companies are encouraging people to provide cheap sec audits for them.
- hrehhf 10y agoIs it actually illegal to sell information that a particular bug exists and can be exploited? What if it is sold to the company which owns the software? What if it is sold to one's own government?
- TeMPOraL 10y ago> What other option do these researchers have? Try to sell the vuln on the black market (illegal) That's probably what GP is alluding to. They do have this option and I can imagine they could get much more money this way, with little or no way to trace the source of a 0day back to them. > Companies are under no obligation to pay and researchers are under no obligation (except ethics, I guess) to turn over their findings. By having some non-trivial payment the companies are encouraging people to provide cheap sec audits for them. Well, of course. The question is, whether the amount companies chose to pay is enough to get most people to report vulnerabilities instead of selling them elsewhere, or if those companies are just putting a lot of trust in the strong morals of security researchers?
- bpchaps 10y agoYeah, I can attest to that. Found a github page with ssh keys, home directories, infrastructure scripts, configs, etc for Comcast that could've been used to do just about anything within their infrastructure. I raised the issue as ethically as I could, particularly since someone with an "infosec background" already forked it a bit before I found it. The engineers who I got in contact with were hugely appreciative, got the issue fixed almost immediately (seriously, kudos again), and brought up the possibility of starting a bug bounty program with me as a pilot of sorts. Cool, right? Well, after talking to their CISO, it sounds like no such thing will happen. Her reason was, "It's not actually a 'bug', so it's not going to be included in a bug bounty program". So there goes that idea. I really don't get it. I could have just as easily sold everything in there for big monies, or could have personally done havoc of my own. There's a certain point where "thanks" just doesn't feel enough, especially after the bug bounty comment.
- melvinmt 10y agoLook at it this way, you could also have been "rewarded" with a 30-year jail sentence. Please don't mess with big corps.
- TeMPOraL 10y agoIf bpchaps would mess with Comcast directly then maybe; if he sold the knowledge somewhere else than not really. I don't recall hearing of any case where a hack was traced all the way back to the third party that found and sold the vulnerability.
- sigmar 10y agoWell it is "pennies" + public recognition. I am also of the opinion that small bounties are much better than no bounty (cough apple cough)
- Titanous 10y agoTesla does have a bug bounty program: https://bugcrowd.com/tesla https://bugcrowd.com/tesla
- beeboop 10y agoI specified they didn't have one for their car software, but I missed the part of that webpage that does actually list "vehicle" as a potential target. I was thrown off by the "This program is focused on Tesla's public facing web application" statement. So you're correct.