18 ms·
Life as a bug bounty hunter
- crunchlibrarian 8y agoThis has been discussed a few times before on HN and I shared the anecdote that I have attempted to report multiple serious security issues to Google and Facebook and have been completely ignored, 100%. There is a tiered internet nowadays, if you go real name and have a following you are treated quite differently from everyone else. You can't even get a response to emails or forms, much less paid out a bounty if you're not in the former group. The algorithm has made everyone who isn't a minor celebrity irrelevant. I don't care how much it benefits the corporations interested in marketing to me, I don't want a following, thanks. Fortunately being able to "crash google" at will during cocktail parties and job interviews always impresses people, so I guess I'll just keep on doing that until they fix the problem.
- CydeWeys 8y ago"Crash Google" in what way?
- saganus 8y agoHow viable would be to write a blog post about it so it gets some attention? Much like what happens when someone gets banned and posts an article on it, to get someone on the inside to notice and help out. Or is that too risky even if you censor the juiciest details?
- usepgp 8y agoI think your idea of "serious security issue" differs from googles. nobody cares if you can cause a local crash with some bad js in the console.
- phyzome 8y ago"Completely ignored" doesn't sound right. Did they truly ignore you, or did they say "that doesn't qualify"?
- gammateam 8y agoExploiting smart contracts are the ultimate bug bounties these days. Forget these fortunes 500s, governments and startups. And to the cynics? This is perfect for you if you hate cryptocurrencies and everything blockchain. Yeah, they're broken, make some money off of that.
- busterarm 8y agoMy willingness to do this is counterbalanced by the fact that I don't want to relocate to, for example, Thailand.
- gammateam 8y agoYou immediately unlink the transactions with Monero. You convert as much of your reward as you can into something more fungible like Ethereum or Bitcoin. Typically this means having several unverified exchange accounts created where you deposit and trade under the unverified account threshold and withdraw. (This is typically 2 bitcoin worth, per account, per 24 hours... but there is always some new exchange with no withdrawal limits and the decentralized exchanges are pretty robust these days) If that exchange doesn't offer Monero, or they have already blacklisted your Ethereum/Bitcoin addresses, then you Coinswitch or Shapeshift, or XMR.TO the rest. Once in Monero nobody can blacklist any of your addresses. You can stay in Monero forever if you like, as it is good enough for reintegration into the normal economy. Or you can reintegrate slowly in other ways, such as back into Ethereum on new exchange accounts or countswitch/shapeshifting back onto that blockchain, simply because there are more things to buy. And yes, it SHOULD go without saying that you should be doing this on Tails or Whonix, and having funded addresses that are unlinked from your identity to begin with. But everyone ever caught up in a legal action has done this part wrong so far.
- busterarm 8y agoIf it looks like criminal behavior, LEO and the courts are going to treat it like criminal behavior. What you're suggesting carries a very large risk profile for someone living in a country where it can be safely assumed that all communications are captured. Someone who places a high value on their freedom and happens to live in most of the desirable countries probably shouldn't be doing this. OpSec shouldn't be treated lightly -- there's good reasons why folks like the grugq live in Thailand.
- Rotdhizon 8y ago>> Companies like Bugcrowd and HackerOne (both of which Ricafort has worked with) This article is very poorly written. It leaves out a lot of key details that could sway ones take away. It mentions that he has done a lot of bug bounties and not gotten paid for some of them. Were they duplicate reports? Was he doing these on his own merit and not going through the bug bounty programs? The staff at hackerone and bugcrowd will make sure you are squared away when you are submitting reports and dealing with payouts. If a company were to refuse to pay you even though you submitted an in scope report that qualified for payment, these sites would help you resolve those conflicts. This article to me tries to paint a picture of: Here is a hard working bug bounty hunter who's efforts barely go noticed because so many mean companies don't want to pay him, he can only make a meager living. I take it as someone who doesn't go through the proper programs and sites, so he's playing with fire on getting his findings reported. If you are just some random hacker who emails a company out of the blue with a random vulnerability finding, most will not take you seriously. Companies who want to be hacked, have bug bounty programs and disclosure pathways. If he's as good as the article paints him to be, he should be making a ton more money than it says he is. So either he is getting royally screwed out of payments by not going through bug bounty programs, or he isn't as good of a hunter as he may seem.
- phyzome 8y agoA number of companies have bug bounty programs that do not go through HackerOne and such, and the quality really varies, from what I hear.
- Rotdhizon 8y agoWhich is why it's irritating that the article left out how he's going about this. I want to know if a majority of his finding were on a site like bugcrowd or if he's trying to do the freelance thing and just getting shot down. I have no input or information about experiences from freelance bug hunters, so I don't know if being ignored is a common thing or if this guy just isn't that good to warrant himself attention.
- 8y ago
- usepgp 8y agoI used to work on the android VRP doing report analysis; I can confidently say that we never intentionally ignored or downgraded reports to save money. There were a few cases of things slipping through the cracks by missing bug assignees, but the majority of the engineering staff really did want those researchers to get as large of a payout as we could justify, and I imagine other companies/VRPs are in a similar position. I think the true root cause of the payment discrepancy issue we see in this article is the bias towards believing the vulnerabilities that we find are more significant than they may be. It often can be either a matter of pride, or sometimes just a misunderstanding of the severity guidelines as published.
- Gasparila 8y agoI had one experience reporting a security vulnerability to a bug bounty program and never want to do it again. I reported an issue to United Airlines that I could reset anybody's MileagePlus number by only guessing their Security Questions ("what is your favorite sport", etc), bypassing any email confirmation or anything like that. After 3 months of back and forth with their security team, they released an Android update that patched the issue. I was then told "It turns out this fix was pushed by the QA team and was actually unrelated to your Bug Bounty submission" and that my submission was ineligible. Your mileage may vary, but the headache for me is not worth the payout
- wolco 8y agoFeel like one could make more than $500 a year doing anything else with the skills required for bug hunting.
- Tloewald 8y agoNode he's making about that much a month, which is apparently around the average income where he lives. Still, it seems low.
- zulln 8y agoThere is people making way more on average doing it on the side. It is really hard to judge how skilled someone is (what is the framework to compare with?), but it is not like nobody actually makes real money.
- strictnein 8y agoThere are some people who make a living doing this, but 99% of people are just making some side cash and messing around. I've made some money doing it, not a lot, and to be honest, most of the submissions I've sent have been to unpaid programs (but through Hackerone, Bugcrowd, and some companies own bug bounty systems). Why? It's fun to be able to poke at large orgs, find issues, report them, and not have some pissy response like I used to get before bug bounties were a thing. You'll actually see them get fixed and you're doing stuff that may prevent unsavory types from screwing people over. My favorite response though is still the "This is a duplicate from [random date six months ago]". Oh, so you're purposefully just leaving an XSS live on your corporate SSO? Makes sense! Nobody ever tries to phish corporate logins at large organizations.
- update 8y ago> My favorite response though is still the "This is a duplicate from [random date six months ago]". Oh, so you're purposefully just leaving an XSS live on your corporate SSO? Makes sense! Ug. I've submitted 2 bugs to Vimeo that gave this exact response. I even followed up a few months later to see if they'd patch it and they responded, "the developers are aware and working on it" ... Seriously? Leaving 2 XSS bugs open on your website that you run a bug bounty program for?? for a year? I really wish hackerone would punish this sort of behavior as it's a waste of every hacker's time to find a bug, write a report, only to be told it's a year old known bug so it's not eligible for a bounty.
- SandwichTeeth 8y agoI found an submitted a bug once through bugcrowd to a very well known company where a session cookie could be used for complete account takeover even after the user had signed out etc. I was blown away when I got the "duplicate" response for a submission that was almost a year old. I wonder if they've ever fixed it...
- introvertmac 8y agoBug bounty literally changed my life. In 2013 Facebook paid me $5000, because of it I was able to pay my education loan(in India) and avoided all those compound interest. I started way before when it was popular and actually got my current job from this thread “list of YC companies I’ve worked with(Hacked)” https://news.ycombinator.com/item?id=10463286 https://news.ycombinator.com/item?id=10463286 Bug bounty is really hard these days, you are competing with the whole world - whoever report first, wins(even when you have put equal efforts) It’s good for side hustle but you can’t do it full-time these days.
- justevan 8y agoI'm still doing bug bounty as my full time job these days and planning to invest some of my bounty for a business in the future :)
- claudiulodro 8y agoAre you in the US? It seems like it may be possible to live on the bug bounty rewards in places with cheaper cost of living, but you would need to get, like, 10 $5,000 bounties a year to survive in the US wouldn't you?
- wepple 8y agoThere are still folks doing it full time in expensive cities. The main aim of the game is to have extensive infrastructure and code to do asset identification & delta. When Facebook puts a new host live without ACLs, you’ve gotta wake at 3am and hit it.
- tptacek 8y agoIf you're genuinely good at finding vulnerabilities, and you can legally work in the US or Europe, you're pretty eminently hirable, and the impression I have is that the rate you'll command will probably swamp what you make on (ordinary) bounty submissions. I think most people who are really good at this either (a) use bounty programs as a way to liquidate extraordinary vulnerabilities, and are well compensated for it, or (b) do it as a side hustle.
- badrabbit 8y agoBounties are one thing but how about selling exploits to organizations like zerodium? Since you won't disclose,won't they pay a lot better?
- tptacek 8y agoIf you can repeatably find the kinds of bugs Zerodium claims to buy, you probably already know what your best financial options are.
- eterm 8y agoAt least hackerone still feels focused around disclosure so if you have a dupe you get linked to the original report. With bugcrowd you can get closed as duplicate and never get to see the original report so just have to trust it's really a dupe. With hackerone you can push for disclosure which puts a clock on companies (unless they completely disappear from the platform which has happened). Neither feel like a route to riches but both are good for finding companies which probably won't aggressively react to researchers finding something. Both major platforms feel like they've lost momentum though, on both platforms though it feels like there isn't much in-flow of new companies, and on bugcrowd most companies go through private programs first which really limits how much you can find as a casual well-meaning amateur. The participating companies probably get a better experience that way but the early days of hackerone were more fun.
- tptacek 8y agoMost H1 companies start "private" as well; the impression, and H1 amplifies it, is that the general public bounty programs are really noisy.
- RyJones 8y agoMy experience is hackerone reports are almost 100% low effort spam, managed in an opaque manner. I would not choose it as a platform for a new bug bounty program.
- tptacek 8y agoThat is not at all my experience with H1, and we manage (and have managed) a bunch of H1 programs for our clients. I wouldn't advise most startups to do bug bounty programs at all, but if I was, I'd recommend H1.
- RyJones 8y agoYou have more experience than I have, obviously, because I'm only involved in running one bounty program on H1. I have not been impressed with H1. Perhaps my opinion will change as our program matures, but I am not optimistic. I think there's a lot of space in this market for competition. I suspect if I was driving as much revenue as you are, they might be more responsive. That's life.
- shiado 8y agoI once found a bug for a company and reported it on Hackerone. Then they said it was a duplicate bug report and paid nothing but also immediately fixed it. My problem is most bug bounty programs put the power completely in the hands of the company. I think there is probably a market for a site where users post the bounties with a detailed and accurate description and their desired price or the community and affected company bid to determine the value of a bug. The affected company could then "purchase" the bug and then the person who filed the report would pay an authoritative trusted third party like a professional security firm to verify the vulnerability. Then the person who found and reported it gets paid if the third party verifies it exists. The company would only get the vulnerability description if the third party verifies it to exist.
- cablej 8y agoAs a bug bounty hunter, this is nowhere near normal. The average payout for a single vulnerability is over $500, so even finding just one vulnerability a month would be more than mentioned in the article. Full-time bug bounty hunters often earn thousands to tens-of-thousands per month, making it far from a "struggling" profession.
- a_imho 8y agoWhy do people do that? Selling their findings for chump change, possibly very serious vulnerabilities highly paid architects missed? Obviously they want to do The Right Thing, but they are very much in a position to negotiate.
- muzani 8y agoI guess it's like fishing or hunting. You don't necessarily want to eat the catch, but there's a certain thrill to it.
- BrandoElFollito 8y agoMy team runs the bug bounty program for our company. What we get is a lot, lot of garbage reports (with public programs) and we spend a lot of time on basic communications with people who barely speak English. At some point we had to mention that we acknowledge the reception of each report and if you do not hear from us then it means that it is not accepted. And then there are the good reports and, boy, some are really neat. We gladly pay for them and keep having many of the hunters coming back. Making things clear from the start and keepingvyour word makes a long way. Bug bounties are great when well organized and a hell on earth for the unprepared.