5 ms·
Please see https://news.ycombinator.com/item?id=17860480 https://news.ycombinator.com/item?id=17860480 before downvoting. From her website - http://sandboxesca
by mockingbirdy 8y ago
Please see https://news.ycombinator.com/item?id=17860480 https://news.ycombinator.com/item?id=17860480 before downvoting.
From her website - http://sandboxescaper.blogspot.com http://sandboxescaper.blogspot.com:
> I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas".
- - -
w.r.t. the 0-day release: Well that's some seriously irresponsible stuff right there.
I think she has a tough time (she's transgender and doesn't have support from her peers). It's sad that she hasn't found a way to live a happy life although she clearly has serious skills. I hope she'll be fine.
It's just annoying that a lot of users are now at risk, I hope the patches will be installed ASAP.
- daxorid 8y agoFull disclosure is not "irresponsible", and plenty of researchers do it even in the absence of armchair psychoanalysis by the Internet.
- mockingbirdy 8y agoMost of them follow specific timelines for those disclosures which are communicated with the affected vendor.
- throwawayjava 8y agoAnd also don't follow up a disclosure with an offer to sell exploits to the highest bidder. Is selling an exploit to a foreign government even 100% legal? (Serious question; that seems like the sort of thing that could get one in trouble.)
- LinuxBender 8y agoIf you sold to a country with standing sanctions, that could be an issue. 0-day's can also be considered munitions in some interpretations of law, though I am not a lawyer nor a weapons dealer.
- deleted 8y ago[deleted]
- Kalium 8y agoIt's honestly extremely difficult to get by in the first world as a white hat security researcher. Bug bounties payouts look big, but unless you're hitting a 10K bug a month you're better off with a Rails gig. And that will be very hit-or-miss, because who the hell knows if $COMPANY will play ball this time or not? Or if you're the first person to find the bug you spent weeks searching for? Exploit development security research is something that there's a surprisingly small market for... unless you're selling vulns. And buyers are usually either government intelligence services or organized crime (skipping right past "what's the difference hyuk hyuk hyuk").
- icebraining 8y agoIsn't the way to make money to find contracts from companies that want you to look into their security? Doing the work first and selling it later is always inherently risky, be it writing a novel or bug hunting.
- Kalium 8y agoYou're right! Penetration testing is one way to make money! It sometimes can be perhaps slightly less lucrative than you might expect, with your average pen tester paid significantly less than your average SWE. And often somewhat different than the kind of specialty skills someone focused on (say) Windows Internals might have. Compare with selling exploits, where a month's worth of highly enjoyable work might turn into mid-five-figures. Or higher. You're absolutely right. Penetration testing and code auditing are ways to make money. It's possible that there may be some relevant differences in both subject and compensation is all.
- EthanHeilman 8y agoFinding exploits and performing a security audit are often very different tasks. A person that can do one is not always able to do the other. Companies, such as companies that sell surveillance software to governments, do hire people to just find exploits, but judging by leaked emails that can be a stressful job as you are expected to regularly deliver new exploits.
- mockingbirdy 8y agoI see, downvotes incoming. Maybe I should explain: > I think she has a tough time (she's transgender and doesn't have support from her peers) This is from her website, I don't like armchair-psychoanalysis, either: > I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas". from http://sandboxescaper.blogspot.com http://sandboxescaper.blogspot.com Seems I was the only one who clicked on her website. The first question I've had in my mind: "What does this person feel? It's weird to publish 0-days on Twitter with a little bit of rant" For the downvoters: Would love to know why you downvoted me. Maybe I can clarify some aspects.
- EthanHeilman 8y agoI think you got downvoted for saying that full-disclosure is irresponsible. Many people I've talked are in favor of full-disclosure and think that coordinated disclosure is long term dangerous as large companies with the resources to actually develop secure software are not sufficiently incentivized to do so under coordinated disclosure. Edit: I've also noticed on HN that sometimes I will get downvoted really hard for no clear reason and then two weeks later HN will magically transform my downvotes into upvotes. Not really sure why that happens, maybe a wave of bot banning?
- pwaai 8y ago> Edit: I've also noticed on HN that sometimes I will get downvoted really hard for no clear reason and then two weeks later HN will magically transform my downvotes into upvotes. Not really sure why that happens, maybe a wave of bot banning? Yup, I've seen this more recently but now the cycle is faster. My comments regularly get downvotes but then later in the evening they turned into upvotes. Also back in Dec 2017, there was a huge wave of people shilling on reddit for ICOs and subreddits would regularly post what "HN users think" and "how to correct them".
- soared 8y ago