8 ms·
Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in mo
by gnl 8y ago
Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.
- jcims 8y agoAs someone who worked in a bug bounty program, the skill and age of this individual isn't what sets them apart. It's the write up.
- sethherr 8y agoAs someone who has been on the other end of receiving incoherent and inaccurate bug bounty reports, this! To find the bug is impressive. To write about it so well is truly exceptional.
- bitexploder 8y agoI always "joke" to people we are professional writers. Actually professional infosec consultants, but our life blood is coherently documenting everything we find and making pretty executive summaries. It is hard to overstate how much I have seen the reporting differentiate infosec consulting firms over then years. Which is not to say we don't value the hard technical skills, but writing is really, really important too.
- jcims 8y agoThe best part is when your kids complain about having to write a 1500 word essay and you show them what's up.
- tptacek 8y agoLet's try a thought experiment. To make things easier, imagine you're 21 years old, not 18, and have made up those 3 years working in the industry. You found this vulnerability, and have decided not to submit it for a bounty, but rather to the black market. Who do you sell it to? I assume your answer will involve putting it up on some darknet version of Craigslist. That's fine, but then tell me: who's paying for it? What price do they assign to it? For instance: if you think you can sell it for $50k, who's paying that, and for what purpose? Finally, what are the steps you take to safely complete the transaction? (This is intended only to clarify arguments about the market for vulnerabilities like these, and not to suggest that the finding and the writeup aren't excellent, which they sure appear to be.)
- was_boring 8y agoYou don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/ https://www.zerodium.com/
- tptacek 8y agoFirst, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'm skeptical of it). Those are vulnerabilities that all have half-lives after patches are issued --- that's a ceiling for what anything like this could be worth. Second, Zerodium isn't "the black market".
- gnl 8y agoI was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere. My experience with the field is limited and considering yours, if you are suggesting that this particular exploit would not fetch a significantly higher price, I shall stand corrected.
- ggg9990 8y agoI’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.
- mixedCase 8y agoHis bounty is equivalent to a year's salary for a very good senior developer in here. So I believe his point stands.
- ggg9990 8y agoYes, but I don’t think you find a ton of highly skilled 18 year old software engineers in the US selling RCEs in the black market for $200K, so I’m not sure you find that in Uruguay.
- tptacek 8y agoYou don't find a ton of people of any age anywhere selling serverside RCEs in individual websites for $200k, or $20k, or --- I will go out on a limb here --- $2k. The $2k limb is shaky because I guess in theory you could buy a GCE RCE for $2k and flip it to Google for their bounty payout, which will probably be at least $3,133.70.
- deleted 8y ago[deleted]
- GFischer 8y agoThere's been a bit of salary inflation here, but yes, it's a very good payout and probably a year's salary for a mid-level developer (I'm a developer in Uruguay). He'll have to pay taxes on it though (if he has no other income it won't be that bad, maybe 20%).
- gnl 8y agoI'm not familiar with South America at all really, just assumed that in a country with a GDP per capita a third of the US, the incentive to not do this the official way will likely be higher. It's certainly possible that I may have overestimated the wealth differential and its effect in this particular situation.
- mapmeld 8y agoThere's some backstory in his Google Code-In article (Summer of Code for younger students) https://opensource.googleblog.com/2016/11/stories-from-google-code-in-2015.html https://opensource.googleblog.com/2016/11/stories-from-googl... > a student from Uruguay who worked with Sugar Labs. Sugar Labs is the organization behind Sugar, the operating system for the [One Laptop per Child] XO-1 which the Uruguayan government has distributed to public primary schools. The XO-1 was Ezequiel’s first computer. > Ezequiel’s curiosity in computer science was piqued when a technician came to his school to solve a simple bug that was affecting most XO’s. The technician used the command line which, up to that point, Ezequiel thought was useless. Realizing that the command line offered him a lot of power, Ezequiel began his exploration.
- rplnt 8y ago> the integrity to not sell something like this on the black market Wouldn't the investigation lead to him? He noted he did not know, at the time, that it was an RCE. So he would need to research further (where he might trigger an alarm). He also noted he utilized staging environment, which he had access to due to previous found vulnerabilities (so Google had his personal details). So, now imagine he found something and he had sold it. If it was used, Google would do a thorough investigation to find if given vulnerability was abused in the past. And they find this guy using it exploratory and nothing else. It's not hard to put 1+1 together after that. While the idea of finding an exploit and selling it for hundreds of thousands of dollars on black market sounds exciting, it wouldn't be so easy in this case.
- gnl 8y agoThere are companies who buy vulnerabilities/exploits and sell them to the highest, supposedly non-criminal - to whatever extent that can be applied to governments, law enforcement and intelligence agencies - bidder. That's mostly what I had in mind and black market is a misleading term for it, but I can't edit the comment now. See also tptacek's comments in this thread.