4 ms·
$1000 for the bug bounty? This is incredibly stupid! How can you make a living off that? You could make hundreds of thousands of US$ from exploiting this. You c
by jacobsladder 10y ago
$1000 for the bug bounty? This is incredibly stupid! How can you make a living off that? You could make hundreds of thousands of US$ from exploiting this. You could sell it on the black market. I am surprised that most of the corporations, even respectable ones, are awarding peanuts for something that is so important to their business process. This makes my blood boil. I operate a small business website and I awarded $3k just because someone found a way to brute force passwords without getting rate limited. This is quite simply unacceptable.
I think the company should have paid $100,000.
- Domenic_S 10y agoSomeone always makes a comment like this. Honestly, the black market value (if any) has nothing to do with the whitehat bounty amount. Why should it? The person who's going to do legitimate whitehat work isn't the same person who's going to sell on the black market. I think of it like drugs. $50k street value of cocaine is not going to do me a lot of good because 1) I'd have no idea where to sell it, 2) if I did know where, I wouldn't have the relationships built and would probably get ripped off/killed/what-have-you, and 3) selling drugs isn't something I'd like to do. So, if there were an option of turning in the drugs to the police for $500, I would take that instead.
- mod 10y agoYour logic is sound. I agree with the GP post about the increased value, though not for his same reasoning. Fixing this bug before an exploit is worth a LOT to the company. I think they have a moral obligation to pay more than 1k to fix it. I also think it makes sense to award good-sized bounties, as at this point I would have no interest in their bounty program, were I hunting bounties.
- arcticfox 10y agoBut if the police want to incentivize you to find cocaine, how hard are you going to look for only $500? In the sense that "Oh yeah, I just casually stumbled on an enormous exploit of security software" the bounty is a good deal. In the sense that "Should I look for holes in this thing? Is it worth my time?" it's absolutely not unless the person is interested in it academically or for reputation.
- Domenic_S 10y agoI see it more like gun buybacks -- "we're not going to ask too many questions, you already have this dangerous thing, give it to us and here's some cash." In other words, I don't believe bug bounties incentivize people who would otherwise not already be looking, but it gives them a safe outlet and official validation that they can put on their resume/website/whatever.
- skizm 10y agoI think the point is 1) it encourages more people to go the black hat way and 2) $1000 just isn't worth all the time people spend not finding bugs before finding one. So no one is encouraged to look in the first place except maybe the few who find it fun to do in their free time. Side-note: isn't there a grey market that buys exploits (for sums of ~$100k depending on the exploit) and sells them to government agencies or larger corporations? I think I remember one company charged $500k / year to companies and government agencies who wanted access to their "exploit database". Seems like this is the best route to go with these kinds of exploits since it is completely legal.
- edanm 10y ago"I think the point is 1) it encourages more people to go the black hat way". How many times have people had to pay you not to commit felonies that are a) immoral, and b) could land you in jail? I think most people don't need monetary encouragement not to turn black hat.
- astrodust 10y agoFinding $50K worth of drugs is one thing, converting that to cash would involve a lot of effort on your part. This is more akin to finding the accounting records of a drug kingpin that could be used as evidence to bring them down. This could have destroyed Lastpass.
- mod 10y agoI tend to agree. LastPass is literally in the business of securing passwords, and was giving them away. I think the bounty should be: 10000 < bounty <= 100,000 This bug would have been exploited, sooner or later, and would have had massively disastrous results. Those results are now avoided, and that's worth a lot more than 1k.
- thieving_magpie 10y ago>You could make hundreds of thousands of US$ from exploiting this. And all you have to do is risk your freedom.
- x0x0 10y agoNo, you can sell to the appropriate folks who will effectively launder the legal risk for you. Someone like Hacking Team.
- dmix 10y agoHacking Teams exploits were released and they are nothing like the one in this blog post.
- x0x0 10y agoThere is a gov (or close enough for Hacking Team/peers work) out there interested in stripping passwords from the most privacy sensitive individuals, who likely heavily overlap with activists.
- thieving_magpie 10y agoThat's disingenuous. It's still illegal for a citizen to do this.
- x0x0 10y agoSelling it to sketchy vendors and doing "see no evil" appears to be perfectly legal. Unless you have some data otherwise?
- dmix 10y ago> You could make hundreds of thousands of US$ from exploiting this Oh no, not this type of comment again. Infosec people always make fun of HN for this exact type of comment. The total lack of understanding of the economics of bug hunting doesn't stop people from commenting here. Noone is paying $100k in some imaginary black market for web exploits. I mean have you even considered who buys exploits and what type of attacks they conduct? There isn't an active market looking to noisily grab passwords from a low-grade consumer password manager that no enterprise or governments uses. Your XSS/SQLi are only worth a marginal amount of money to the corporation you're pen testing. And supply/demand is always what drives prices, not the potential damage (or benefit) you can imagine a particular exploit doing. This is as true for vulnerabilities as it is for some business software or mobile app your create. Just because in a perfect situation it could generate x value for a customer doesn't mean there is either demand or an untapped market for it. A browser-based iPhone zero-day on the other hand can fetch some money. But even then your grey market for this is tiny and most likely not going to be some criminal overlord paying out $100k in bitcoin to kids on a darknet forum.
- wyager 10y ago>Noone is paying $100k in some imaginary black market for web exploits. You're right, it's usually in low-mid $10ks for this sort of thing. >low-grade consumer password manager that no enterprise or governments uses Can't speak to government, but multiple large companies I have worked for have mandated LastPass as the password manager. > But even then your grey market for this is tiny and most likely not going to be some criminal overlord paying out $100k in bitcoin to kids on a darknet forum. In fact that's almost exactly what it is, except you've underestimated the price. A really juicy iOS RCE or Privesc can fetch almost half a million. These transactions aren't usually done on forums, though. Not enough trust. There are middlemen who buy exploits from researchers and sell to the big customers.
- jacobsladder 10y agoOk, you are right, it was naive for me to pull out this "black market" number from the ass, especially because I should know better, coming from Russia where there are many of these forums. However, I still stand behind that this corporation should have paid $100,000. There are so many opportunities to exploit this vulnerability. LastPass is seen as something "advanced" users use, so it's highly probable that you could PM link to this page to some computer celebrity, and you would have access to his inbox in no-time, because most people don't use annoying second-factor authorization. This could result in a huge amount of new leaks, etc, etc. $1000 basically screams - "fuck you, we don't care about our security, and we are not going to encourage future white hat future bug reporting".