5 ms·
Wow, an ATO exploit that only received a $6,500 bounty? This signals to grey-/black-hat researchers that their research efforts or Slack bug disclosures are bes
by fiberoptick 7y ago
Wow, an ATO exploit that only received a $6,500 bounty? This signals to grey-/black-hat researchers that their research efforts or Slack bug disclosures are best directed elsewhere..
- edoceo 7y agoHow much should they have been paid? This seems like a week of pay for a pretty good software dev. That's not fair comp?
- penagwin 7y ago> This seems like a week of pay for a pretty good software dev. Wait, 6500 * 4 * 12 = 312,000/yr Might be a bit high for a week :P EDIT: Okay turns out that if you live in the Bay area this isn't unheard of - the rest of us make 4x to 5x less then that (Saying this as a mid-level software dev from West Michigan).
- randlet 7y agoSalary information on HN is skewed by Bay area engineers where $312k is not out of the realm of possibility for a senior developer afaik.
- moneromoney 7y agoIn Germany you will be VERY lucky making 100,000 euro / year. Germany has the lowest software dev. salary / average country salary ratio of all countries on planet.
- foepys 7y agoUnless you are doing anything more or less related to SAP. Then you can make $150k/a easily. If only other companies would realize that that's one of the reasons why SAP is Germany's no. 1 software company.
- sciurus 7y agoThat matches up with the mid to senior range you'll see for FAANG at https://www.levels.fyi/ https://www.levels.fyi/
- bluedino 7y ago60-75k is on the low side for a qualified dev, even in Michigan.
- tptacek 7y agoIt is, as the bounty reporter says themselves, eminently fair. People on this site have very weird ideas of what the going rates for bounties are.
- sarakayakomzin 7y agoThe bounty hunter isn't a source of truth for the value of the bug. If you don't think you could sell an exploit to takeover any slack account for more than $6500 then you aren't familiar with what the market values in the first place.
- vlovich123 7y agoThe value is not about the time spent finding the bug. It's about the severity of the issue, the scale, & the competitive cost of me selling it on the black market. If Apple left open a 0-day rootkit exploit that took me somehow 1 day to find it's still worth hundreds of thousands of dollars.
- vasco 7y agoWell yeah if your comparison is that the person's morals allow them to just turn around and sell it in the black market, maybe they could've paid more. But the reality of HackerOne is that most people are really just doing it as a hobby or side project that happens to generate cash. Some people build 10 different static website generators, others do bug bounties. It doesn't mean they'd go on to sell these exploits and risk going to jail.
- QuinnWilton 7y agoIt's not the people using HackerOne to be concerned about. It's the ones who don't use HackerOne because they realize they'd get more money on the black market. When it comes to vulnerabilities with a large enough impact it isn't enough to learn about most of them, because all it takes is one financially motivated actor to weaponize things.
- tptacek 7y agoThere is almost certainly no liquid black market for this bug, even though Slack is very important to lots of businesses. It had no half-life at all (the fix was one-and-done) and doesn't fit into any existing business/operational model (nobody has an infrastructure where different targeted Slack bugs are pin-compatible drop-ins).
- floatrock 7y agoThis thread is interesting because it shows different ways people value their work. This is reasonable if you look at it as "just another job" -- you're being paid to build Good Software, so just another day at work. Or you're doing a Good Thing by helping a lot of people not get pwned. This is unreasonable if you look at is as value-creation: "how much is this worth on the black market" or "what is this worth to Slack as a company". Other people can get into the socioeconomic or means-of-production or entrepreneuring implications of all this, but I just think whether you downvoted or upvoted this provides a useful mirror into how one values one's own professional work.
- lonelappde 7y agoIf he worked a week and didn't find a vuln, he'd get 0. Average that in. Bug bounties are the uberification of security research.
- NikolaeVarius 7y agoThe literal hacker themselves indicated it was a fair payout. I don't understand unsolicited complaining for other people.
- kjaftaedi 7y agoThey're not 'complaining' about the amount in the way that you're thinking. They're suggesting that the severity of such a bug warrants a larger payout, because not doing so creates possible incentives for future explorers to consider selling these sorts of things on the black market. This person may be satisfied, the next person that finds something similar may think twice.
- whiskeykilo 7y agoIt's a free market. Don't like the payout? Don't submit the bug. Someone else probably will anyway
- pathseeker 7y ago>I don't understand unsolicited complaining for other people. If you observe someone getting paid a much lower-than-market amount for something you can complain that the company is being cheap and likely driving away a lot of potential sellers (security researchers in this case) regardless of how happy the one person is.
- tptacek 7y agoThis is not a below-market rate.
- fiberoptick 7y agoI noticed that throughout this thread you have been making this assertion. Could you share any data or citations to support this? Would you feel any differently about the value of this bug if it affected, e.g. Google or Facebook?
- 7y ago
- xyst 7y agoProbably took weeks to build his own suite of automated tests for these types of exploits. All he has to do at this point is reconfigure the scripts to point to a new site/app with a bounty program, post report, and reap the benefits. Assuming he has done this for several other companies, I would say he has effectively earned more than what is put in