5 ms·
Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pon
by jtdev 5y ago
Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
- disgruntled101 5y agoYou are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.
- wffurr 5y agoOr sell it to the NSA (or insert your national intelligence service here) as a defense contractor, which some might call your “patriotic duty”.
- cosmodisk 5y agoI doubt the rates are that good tbh..
- alwayseasy 5y agoYou need to setup as a defense contractor (and jump through all the hoops) just so you can sell a Zoom zero-day and realize the NSA will give you 50k?
- amoshi 5y agoYou're overcomplicating, Zerodium exists.
- 14 5y agoA lot of the time we see someone getting like 10k. Also 200k is over 3 years my wage so I have to say no it does not seem low to myself but to others perhaps that is a low number but I value things differently. I hold high morals so I would not ever just sell an exploit to "the bad guys" so realistically I was never going to get the most money for said exploit so it is not all about money.
- rvz 5y ago> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.
- esnard 5y agoVery few bounty programs offer that much for a single vulnerability. I'm not saying it's worth $200k, but $200k is definitively a huge payout in the security industry.
- tyingq 5y agoI can't tell much from the gif, but perhaps. RCE for anyone that runs Zoom, or RCE for anyone in a meeting you're in or something else?