4 ms·
It's cool you guy fixed it so fast and deserve some good PR here for that but I'm surprised you paid out $5k for an RCE. That's unspeakably cheap for something
by Zenbit_UX 6y ago
It's cool you guy fixed it so fast and deserve some good PR here for that but I'm surprised you paid out $5k for an RCE. That's unspeakably cheap for something that could have fucked over many of your users.
I work at a very small company, so small that a security researcher would never accidentally stumble on our products to test them and if my boss asked me what would be an appropriate pay out for this, I'd say easily $25k, but more likely 30-35k if we can afford it.
What you guys have accomplished here is set a precedence that you pay so little that researchers should either a) not bother with discord or b) should sell on the darknet.
As a discord app user, I'm very concerned about both of those cases.
- walls 6y agoThe bug was in Electron, not Discord. That Discord gave anything for a third-party dependency is pretty good.
- sleepybrett 6y agoGiven that discord chose electron as a dependency it's at least partially their responsibility. They are putting their users at risk for choosing that dependency.
- Pfhreak 6y agoYou own your dependencies. An end user shouldn't be expected to investigate and trust your entire supply chain, they expect you to do that. Imagine if a food company was like, "Oh, well, the marble dust sold to us as flour was from a supplier so we're not really responsible."
- PragmaticPulp 6y agoThe issue is that the bug was technically in a 3rd-party dependency: > even though the main fault that lead to RCE was due to a bug in Electron (CVE-2020-15174) This may seem like an irrelevant detail if you’ve never operated a bug bounty program before, but you have to consider the incentives. Paying researchers for bugs in 3rd-party open source software creates misaligned incentives. If you’re a security researcher and you discover a security bug in Electron, you have two choices: 1) Follow proper protocol to create a CVE, coordinate a fix, and properly disclose the issue through appropriate channels. 2) Keep the vulnerability secret and unfixed while you shop it around bug bounty programs looking for kind companies who will pay out for 3rd-party issues. To maximize profits, it’s important that you keep the security issue unfixed and secret as long as possible while you work your way across bug bounty programs. The second option is a little publicized negative externality of bug bounty programs that don’t draw the line at 3rd-party dependencies. I’ve even had bug bounty participants beg us to not fix upstream code yet because they were still trying to collect bounties from other companies. This is also why it’s important to have your security team read every CVE immediately and check against your software. It’s also why bug bounty programs don’t pay out as much, or even at all, for security issues that come from popular 3rd-party dependencies used across the industry.
- cooljacob204 6y agoIt's still an exploit in their app that can be abused on their users. I see nothing wrong with submitting it in multiple places, it's still better then being sold darknet.
- Zenbit_UX 6y agoI appreciate your insight into the 3rd party aspect of BB programs but I fear you're also setting a dangerous precedant of _outsourcing liability_ from major companies to small open source devs. If I get hacked and find out Discord was the vector, I'm not going to let them off the hook when they shrug and say "3rd party code man, it happens". In the end, I'm a discord user, I don't want RCE exploits in software I use.
- ViViDboarder 6y agoIf the bug was instead reported to Electron and given a CVE, Discord could have still implemented the fix. Either a workaround in their app or an upstream patch.