5 ms·
As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn'
by JudasGoat 6y ago
As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.
- sam1r 6y agoEqually curious, even as a developer. Impossible to track in-person knowledge exchange, so code wouldn’t really be the culprit IMO.
- MeinBlutIstBlau 6y agoIs it not something as simple as a try catch unresolved or ignoring an injection attack?
- Mandatum 6y agoThis is why internal bug bounties should pay cash. Most orgs don't even have one.
- lofties 6y agoWe have an interal bug bounty program! But it's more of a retainer when you think about it. We basically transfer a six figure dollar amount, in 12 monthly installments, to our developers. Then in return when they find a bug they bring it to attention and fix it. It works pretty well!!
- kortilla 6y agoIt would be interesting to have a dedicated bug fixer whose only job was hunting bugs. No meetings, no scrum, no design docs, etc.
- jlgaddis 6y agoI've wondered that before as well. If one were sufficiently motivated and planned ahead, you could almost consider it as a future "insurance policy" of sorts.
- marcan_42 6y agoThis isn't a thing, mostly because it's a giant legal risk.
- lawnchair_larry 6y agoMost likely none, but it’s a common conspiracy theory.
- luch 6y agoI don't think this is a thing for two reasons : * firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms. * secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause). That being said, attackers are reaaaaaally interested in getting access to internal bug trackers : https://grahamcluley.com/microsoft-bug-tracking-hack/ https://grahamcluley.com/microsoft-bug-tracking-hack/
- tester756 6y agoI struggle to understand that logic > firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms. All you need to realize its value is read some security related news for a week. Also you can have security_interested people apply to FAANG and then cause harm. >secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause). As you said - around known bugs, so it's irrelevant here
- chillacy 6y agoI didn't think this was true until I read Permanent Record, where Snowden talks about how the agencies could get stuff done through bribes or planted employees. Since knowing that, I've become a lot less certain.