12 ms·
Beg Bounties (2021)
- scolby33 3y agoWhy is most of the substance of this post giant block quote links to his own Twitter? Clicking through to those is painful; it’s not like the author can’t afford to host some screenshots on his own domain.
- Waterluvian 3y agoI’m less upset about people begging for bounties than I am learning that leaking children’s voice recordings isn’t an instant deathblow to a company.
- thaumasiotes 3y agoWhy would it be? Say you film your kid's birthday party and put it up on youtube. You just leaked voice recordings of a lot of other children. What's the harm supposed to be?
- Frivolous9421 3y agoFeel like recording intimate moments like that should just about be a crime at this point. Sick of every dicknose with an iPhone trying to "remember" a group dinner
- thaumasiotes 3y agoBefore we make it a crime, should we have a theory of the harm it inflicts?
- Frivolous9421 3y agoFace recognition. In terms of govt scale intelligence, and increasingly just plain OSINT. Not everyone is as tight with their pictures as you are, they probably auto upload them on Google Photos or Dropbox or something. You are now irreversibly linked to everyone else in that photo who probably has social media profiles, public contact emails, show up on people search websites etc. I don't want to cause problems for you just because someone wants to blackmail me. I also don't want you to tell people where I live because someone broke into your house and is removing your toenails with a pair of pliers. Subjective opinion time, I just think it's lame. I don't sit back and reminisce over pictures. I don't want to be in your group picture. I want to hang out with the people in the group and have a laugh.
- duskwuff 3y agoAs of 2013, COPPA specifically defines recordings of a child's voice as a type of "personal information" about the child; as a result, operators of online services "directed at children" are required to get parental consent to collect that information, and are required to protect it appropriately. https://www.ftc.gov/news-events/news/press-releases/2012/12/ftc-strengthens-kids-privacy-gives-parents-greater-control-over-their-information-amending-childrens https://www.ftc.gov/news-events/news/press-releases/2012/12/...
- thaumasiotes 3y agoIf the only problem with something is that it's illegal, why not stop making it illegal?
- lost_tourist 3y agowhat are kids voicing that should result in the firing of thousands or even tens of thousands of adults because a corporation got dissolved? Seems a bit overboard
- ipython 3y agoI run a domain for our community association. I had an “ethical hacker” discover that I had neglected to set up spf records for that domain. I had to deal with him sending a bunch of nasty emails to our other board members after I refused to pay him for his “discovery”. (Actually I offered him a cut of my salary as a board member, which at $0, came out to be… less than he was hoping for) I’ll definitely keep a link to this for next time this happens.
- aidos 3y agoAs a general rule, you really do want to set up SPF, dkim and dmarc. Without them there’s a real vulnerability there. The annoying case is when you have them correctly configured but are using ~all instead of -all so you still need to deal with the beg bounties.
- blincoln 3y agoYeah, I'm honestly surprised the organization is able to email anyone else. Even 8-10 years ago, I would have expected the major providers to drop email sent from a host without some or all of those elements configured.
- 0x53 3y agoI guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
- codetrotter 3y ago> I don't think security researchers should work for free I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet. How are you supposed to find customers in the first place? Gotta start somewhere. Quality of the findings is orthogonal to asking for compensation. There will always be people asking for money without providing value. But I don’t think we should throw the baby out with the bath water because of it.
- hn_throwaway_99 3y ago> The OP comes across a bit gatekeepy to me. Hard, hard disagree. I'm glad this "beg bounty" behavior has a name for it, because it's so f'ing obnoxious, and so common, and all it really does is make it that much harder when a serious researcher does need to report a real vulnerability. Let's not pretend there is some sort of gray line between what responsible disclosure looks like, and what bullshit beg bounty disclosure looks like - after all, Hunt does an excellent job showing the difference. He showed an email he wrote that identifies where he's from, and gives clear verifiable evidence of a serious breach. That is night-and-day different from the "I found something naughty on your website, will you pay me??" example from the beg bountier. Point being, if you are a serious researcher and you have actually found a high-value vulnerability, there are proper ways to message that even when you feel compensation is warranted. These beg bounties never look like that because they all have the same achilles heel: the "vulnerability" is such an eye roller that they can't actually give evidence of it before asking for money precisely because they know it's so low value.
- thaumasiotes 3y ago
- cperciva 3y agoI get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- which means that Tarsnap shows up pretty quickly when bounty beggars start looking for targets.
- notatoad 3y agomy favourite is "your docker registry is publicly accessible" yeah man, i know that. i made it public. i eventually had to take it down, just to stop the flood of beg bounties telling me about it.
- cperciva 3y agoOh yeah... I don't run a docker registry, but Amazon feels it necessary to remind me periodically that FreeBSD releases are public AMIs, and their filesystem images are public, and I have publicly readable data in S3 (which is mandatory in order to create an AWS Marketplace listing). So much "yes I know it's supposed to be that way".
- adastra22 3y agoIt’s so bizarre that every time I upload something to S3 I have to jump through a hoop to make it publicly readable and Amazon displays a massive warning sign. Like the only thing I use S3 for is hosting open source software binaries. Maybe there’s a use case for restricting access, but I don’t even know what that would be.
- toomuchtodo 3y agoInadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_service_simplified/ https://www.theregister.com/2022/12/14/aws_simple_storage_se...
- deleted 3y ago[deleted]
- appleaday1 3y agoI miss the old internet.
- dilyevsky 3y agoOn the “old internet” someone would just deface your website for lulz instead of asking for bounty
- RockRobotRock 3y agoSomeone hacked my old personal site when I was a kid and posted it to zone-h for the street hahaha
- jeffparsons 3y agoOn the old internet, if you could trick someone into revealing their IP address, you could knock them offline: https://en.m.wikipedia.org/wiki/Ping_of_death https://en.m.wikipedia.org/wiki/Ping_of_death But it was fun because we were young, the "attackers" were our friends, and there weren't billions of dollars on the line.
- matheusmoreira 3y ago> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have literally no choice but to care.
- throwawaysleep 3y agoMy incentives as an employee are similar. Far better to hide a problem than admit and fix it.
- dilyevsky 3y agoCovering up legit vulnerabilities is dangerous - it is a criminal offense. And no “my manager doesn’t like it” is not an effective defense (see uber ciso case)
- Aeolun 3y ago> Covering up legit vulnerabilities is dangerous It is incredibly hard to prove someone else knew about something you didn’t/don’t know about though.
- munk-a 3y agoThat is a sign that you work at a deeply unhealthy company. Even at a moderately healthy company it's usual to have "Don't shoot the messenger" policies in place to avoid blaming developers for doing their job.
- charles_f 3y agoAfter which publication they usually reassure their users that security is their utmost priority, fix the one leak, and go back to doing nothing till the next breach.
- peddling-brink 3y ago
- tptacek 3y agoI don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There's going to be 20 more right behind them. But I mean, just for your own sense of well-being.
- throwaway69123 3y agoI think the article made the argument that beg bounties drown out and train receivers to ignore better more fundamental reports as also being spam.
- StrangeSmells01 3y ago[flagged]
- gowld 3y agoWe don't appreciate allegations without links to evidence.
- ehPReth 3y agofirst time i've heard of this merch thing... sources?
- aniforprez 3y agoWhat an uncharitable and uncalled for accusation. Dude's twitter is him living his life and posting it. No one is asking you to follow him or read his stuff. He's rich and posts about some of it. Who cares. I've never seen him pretend to be a celebrity and the accusation of giving merch for harassing others sounds like an outright lie. I've been following him for years and have seen no such thing
- tkems 3y agoMeaningful or not, some companies and organizations don't understand the difference between a CVSS score of 2.0 and 10.0. Being in the cybersecurity industry myself, there is a wide gap of knowledge in the risk of vulnerabilities. Following a some-what standard way of reporting vulnerabilities is well documented. Begging for a bounty is not standard. I also think that is perfectly fine to document the process in public so that everyone is informed. Also, in regards to your comment on meaningful payouts, you could make the same argument for spam email. Occasionally it works for people in developing countries is, in my opinion, a terrible argument for allowing such behavior.
- gloyoyo 3y agoVery informative.
- benrockwood 3y agoI love the term, it's appropriate. In my experience many of these beg bounties are automated and non-sensical. Script kiddies looking for a quick and easy buck. Generally when they are directed to an actual bug bounty program on HackerOne or the like they don't follow through.
- _lvbh 3y agoI just got my first beg bounty today about an exposed hugging face token. It was intentional and read only.
- gillig 3y ago[flagged]
- paranoidrobot 3y agoe: I just noticed, this post was from 2 years ago. It should have (2021) in the header. --- I help run a bug bounty program, we get a lot of submissions. Way too many of them are zero or low effort. The SPF meme one definitely resonates with me, we get it a whole lot. Occasionally we will get someone who submits a half dozen variations of the same zero/low-effort report. When we turn around and deny them all (because there's no actual exploitable issue). There's a good chance they will then spend the next week replying to our emails asking for money because they put a lot of effort into it, and/or disputing our evaluation. It's frustrating dealing with that, and I can certainly sympathise with wanting to reply to someone who's begging you for money with a "no, go away". Perhaps Troy just needed to blow off some steam, but I think he'd be better having a saved reply in his email saying he doesn't pay bug bounties for personal projects/sites, and just send that. I think it'd go over better than having what seems to be an overly aggressive post.
- billy99k 3y agoHere is another perspective: I have been making money through bug bounties for the past 5 years (I'm a researcher on the major bug bounty sites and multiple private ones). More times than I can count, I have found major, non-low effort bugs, and the company will spend time deflecting, and I just won't end up getting paid. Luckily, this is less than 10% of the valid bugs I've found. I've learned to just move on after a certain point. This behavior from these companies nearly made me quit 2 years ago. I was so frustrated that I completely stopped for 6 months. I found 50 bugs in a week for one major company and they spend 2 months trying to tell me that they don't own the site anymore, and weren't going to pay me. It was in scope at the time I found the bugs. These weren't just minor bugs either. It allowed me to break into all private rooms on the service in multiple ways, get access to back-end network settings, and even takeover accounts. I pushed back and they were in violation of their SLA. I got a nice payout a few weeks later.
- billy99k 3y agoTo add to this (because I can no longer edit my post). An excuse I saw just last week is that although I found vulnerabilities, the company doesn't believe it's a security issue and have no interest in fixing it, so the reports will be closed as informative. Keep in mind the bugs I found allows a lower-privileged group to not only access, but updated privileged information and other sections in the account with no user interaction. Definitely a security issue (multiple, in fact). This is why security issues never get fixed and people like me stop looking. I suspect they will fix it and are again trying to find ways not to pay me.
- hn92726819 3y ago> I don't know how many disclosures I've done ... (100+, surely), but I have never, ever - not even once - asked for money. But Hammad isn't me I agree with everything in this post except this line. It's nice that the author doesn't need the money, but some people do. To me, the problem is not sharing after the answer is no, or not asking up front, not the fact someone is asking for money.
- jackson1442 3y agoI don’t think asking for money is the issue- it’s the overall handling of the situation on the researcher’s side. If you’re only trying to collect bounties, you should go to a bug bounty website and work on sites that are explicitly soliciting bounties - that way you aren’t wasting your time finding vulnerabilities on sites that have no interest in paying out, and you can see which types of vulnerabilities are in- and out of scope. On the other hand, I don’t think it’s particularly rude to shoot an email over explaining the vulnerability while at the same time requesting compensation. But gating information on the vulnerability behind a request for compensation is not appropriate.
- mgaunard 3y agoI remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.
- j-a-a-p 3y agoValuable lesson for a teenager to discover how people really are. I hope the police was more reasonable!
- mgaunard 3y agoThe police allowed them to contact my ISP to get my name and location, not that I was hiding or anything. Apart from that they just logged the incident and there was no follow-up.
- deleted 3y ago[deleted]
- waihtis 3y agoNo criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.
- geek_at 3y agoOh yes. In 2011 I got raided by the police because I clicked a link someone sent me over IRC [1]. You don't even need to be destructive to become a target for prosecution sometimes. Being stupid or incautious is enough. [1] https://blog.haschek.at/2015-that-not-so-awesome-time-the-police/ https://blog.haschek.at/2015-that-not-so-awesome-time-the-po...
- deleted 3y ago[deleted]
- throwaway231113 3y agoThrowaway account for obvious reasons. I've been employed as a triager on two primary bug bounty platforms for over seven years. The circumstances are distressing and carry tangible real-life consequences. I'm open to answering questions within my personal comfort zone.
- OsrsNeedsf2P 3y agoThis comment would be a lot more interesting if it wasn't so vague
- Ayesh 3y agoI get that Troy is probably tired of receiving beg bounties, but as a security researcher himself, I find this post a bit distasteful and discouraging towards the people who could as well be on their way to finding bigger vulnerabilities. Reports on lack of SPF/DMARC records on security headers can be annoying, and often false, because there are some legitimate cases an SPF record with `~all` is necessary, or you have to have a permissive CSP for whatever reason. I would have just deleted their email and moved on.
- eknkc 3y agoYou receive 20 mails each day and when you delete them you receive follow ups. You receive emails getting angry and the tone shifts to threats (as if the bug they are reporting warrants it). These bury any legitimate reports. We have missed a legit one because of the sheer amount of beggers at some point. Luckilty the person on the other end contacted us again and was understanding that we missed it. And there are some who do not disclose and act like there is a really critical issue, fishing for replies first and then dropping a pile of shit as a critical security issue. I'm also fed up with these.
- Ayesh 3y agoQuoted from the post: > It was _immediately_ clear that Hammad was going to beg for a bounty, but it was a quiet Saturday night here and I thought it would be entertaining to see just how far down the rabbit hole he wanted to go. So, I responded, positively: I suppose most of these useless bounty reports are quite easy to tell. From the comment above: > 20 mails each day If you receive 20 mails a day to your security email address, then, perhaps it's time to setup a proper bug bounty program? They will weed out low impact vulnerabilities and only elevate the reports above a certain threshold. Isn't this a solved problem already?
- blincoln 3y agoFrom what I've seen secondhand, a bug bounty programme can actually increase the overhead vs. an email address, because now someone has to log in and deal with each ticket instead of ignoring emails that don't seem interesting. There are some significant advantages to having a bug bounty programme, but they still attract a lot of noise. I know of at least one software company that has an entire team just to triage the queue. Not fix anything, just validate whether a report ia reproducible or not and if so, route it to the responsible party.
- oliwarner 3y agoI understand the problem, beggars add noise to an important contact signal point… But this idea that people 'did actually already do the "work" for free' so don't deserve remuneration… isn't great. Lot's of people do spec work to try and get paid, or to get more work. The recipient is free to negotiate, rebuff or simply ignore it, but this idea that time sunk is valueless is unhelpful. Not defending "Hammad" here. If you do spec security work you need to lead with what you've got, even if that's just a rough CVE severity rating, and your price. But I think I'd rather have people checking my configuration and taxing me for my errors than not to know at all.
- Etheryte 3y agoThis makes no sense. Imagine someone shows up at your house, paints the fence and then asks you for compensation. They already did the work, but you never even asked for it. The same thing is happening here.
- oliwarner 3y agoYes. The part you've missed from what I said is you have the right to negotiate or ignore. You don't have to pay. But you shouldn't expect to get the result for free.
- machomaster 3y agoThis analogy is wrong. I have better ones. 1. Imagine a painter on the street, who made a quick painting of youand your partner in your natural state while being unaware of the process. Then he comes and asks if you are willing to pay and get it to yourself. No, you don't have the right to get it for free only because it was already painted. 2. Imagine that while you are on your walk, a guy comes to you and informs you that your bag was open and some stuff may have disappeared (dropped and/or stolen) from it. He went out of his way to detour and catch up to you (he had to run!) to report the issue. It was voluntary, but it is a good behavior. In physical world that alone should be rewarded (at least with sincere thanks). But if you are not willing to compensate, he has no duty to go spend even more of his time and energy in order to walk back, show you all the places where your stuff dropped and to stay and document all the details for your police/insurance application. He already did you a favor and is not required to put any more effort into it for free. It would be nice, but not a duty; especially because we are not talking about the private person or a hobby project, but about a company business. Discovering vulnerability is one thing, but properly writing and documenting it is a totally another expenditure of time, energy and opportunity cost. It is not free.
- gitgud 3y agoSurely "false positives" for security vulnerabilities are better than no emails at all... "If you put an email on a website, you will get spam" - A fundamental law of the internet
- throwaway2037 3y agoA bit off topic: I am genuinely surprised that he gets to blog (regular and micro via Twitter/X) with such a savage style. In many mega corps, even tech, they would eventually curtail this type of blogging. Steve Yegge is a pretty famous example where even Google was trying to curtail his blogging topics and style.
- DylanSp 3y agoBeing self-employed has some benefits - https://www.troyhunt.com/about/ https://www.troyhunt.com/about/.
- machomaster 3y agoIn his email signature he writes that he is a "Microsoft Regional Director". Even thought that is formally correct, in practice it is highly misleading, because it alludes that he works for Microsoft at the highest C/Director level, while in reality he is a mere advisor and this is a vanity title he got. This is very sleezy behavior and way worse than the guy he criticized did.
- throwaway2037 3y agoOn his about page, he clearly explains his title: https://www.troyhunt.com/about/ https://www.troyhunt.com/about/ Literally, the first two sentences: I'm Troy Hunt, an Australian Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. I don't work for Microsoft, but they're kind enough to recognise my community contributions by way of their award programs which I've been a part of since 2011.
- machomaster 3y ago1. Even here he explains is badly. 2. He doesn't explain it at all in his email. This is akin to writing a misleading news title and say that you are innocent because people should not be gullible and believe everything on the Internet, and should do their own research. 3. He purposefully chooses to use that bad title, even though nobody forced him. It was his personal choice to mislead people.
- tsak 3y agoAfter reading this HN post in the morning, I've received one of those SPF ~all beg bounties via email today. It ends with: From: whiteboxtesting01@gmail.com > Waiting for your response and hoping for a bounty reward for responsibly disclosing this issue to your website. Furthermore, I may attempt to contact you again if I do not receive a response to ensure that my message has reached you.
- bluedino 3y ago> Want to be a bounty beggar? It's dead simple, you just use tools like Qualys' SSL Labs, dmarcian or Scott Helme's Security Headers, among others. Easy point and shoot magic and you don't need to have any idea whatsoever what you're doing You've described 90% of our cybersecurity department.
- omginternets 3y agoI think this falls squarely under the adage that “90% of everything is shit.” Want to be a developer? It’s dead simple. You can just install node.js and pull in a bunch of random dependencies.
- unforgivenpasta 3y agoReading the accompanying cloudpets article is very similar to my experience with reporting exploits. Found a XSS vulnerability on a very popular danish website and 0 contact since reporting. The vulnerability still exists and even found a few less severe bugs
- billy99k 3y agoI know someone that would find security holes in random company sites and email them about it. They never asked for money. Most of the time, the company sent an angry response with threats of calling the police. I always thought this was stupid. I would never look for security vulnerabilities on a company site, unless I'm hired to do so. The main issue is that you have no idea if what you are doing will affect a production sites.