2 ms·
The idea with responsible disclosure is that you want to maximize safety of the public by incentivizing vendors to fix problems while not letting malicious acto
by mkjones 15y ago
The idea with responsible disclosure is that you want to maximize safety of the public by incentivizing vendors to fix problems while not letting malicious actors exploit them: http://en.wikipedia.org/wiki/Responsible_disclosure http://en.wikipedia.org/wiki/Responsible_disclosure. Once the vendor has fixed the flaw (or refused to, or taken longer than a reasonable time to do so), it's generally accepted as OK to publish details. You can of course get whatever media coverage you want at that point.
I'm curious - do you think responsible disclosure is a bad idea? Or is the "badness" of this bug small enough (compared to malware) that you think it's better for the common good to publicly post the repro instructions and enable many users to exploit it?
I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat disclosure program, let alone a bug bounty program. It's worth noting that this is just the base bounty - I've seen us pay out a lot more for good discoveries. $500 is also the base that Google and Mozilla offer for their programs (http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w..., http://www.mozilla.org/security/bug-bounty.html http://www.mozilla.org/security/bug-bounty.html). What would be a good price, do you think? I'm not hooked in enough to know what black market prices are like for bugs like this.