5 ms·
“Beg bounty” ppl have already made it a major pain in the ass to have a bug bounty program, even when they were real people who had to take the time to craft “b
by yashap 3y ago
“Beg bounty” ppl have already made it a major pain in the ass to have a bug bounty program, even when they were real people who had to take the time to craft “bug reports” about basically nothing. But if you mix in LLMs, generating bogus reports at essentially no cost, this could get really out of control. Could be the end of bug bounty programs IMO.
Or, maybe we just need to lock them down more? Like you need to apply to become part of the bug bounty program, which involves some sort of cheap-to-perform check that you’re a real person and actual security researcher, looking to find real, impactful security bugs. And only ppl admitted into the program can submit bugs and collect financial rewards.
- masklinn 3y agoThere are platforms which do that yeah, they have "pools" of known researchers with tracked statuses, and you can tune how open your program is. Some also have triage staff, but depending how typical your project is that can be very hit or miss.
- yashap 3y agoYeah, a decently locked down program seems like a good idea! At the startups I’ve worked at, the programs have been very open (basically “email us”), and it does lead to a fair bit of beg bounty spam, even without LLMs in the mix.
- donmcronald 3y agoMaybe have a submission fee? I don't know if that helps, but it would be a deterrent for massive amounts of machine generated garbage. The worst case in my opinion is massive amounts of AI garbage being submitted which will require equally bad AI filtering to "solve" the problem with the result being an overall reduction on quality for everyone trying to participate in good faith.
- yashap 3y agoThat’s an interesting idea, though I’m sure you’d be inviting some scathing blog posts! But you could maybe mitigate that by donating all fees to a charity? Or even a hybrid: - If you’re a “trusted security researcher”, you can submit for free - Else, there’s a small fee (on the order of a few dollars per submission)
- sensanaty 3y agoI can see a world where something like this works, if you implemented some caveats. - It has to be a low monetary amount, like a couple of bucks at most, though even this is tricky. People aren't willing to sheir their account details (for good reason) with any random entity, and a CC number gate will also block many well meaning reporters. It's probably the trickiest part here to justify (though presumably many Reporters want to get paid at which point they'd have to provide these details anyways, but oh well) - Refunds for well intentioned bug reports that get denied, so if you send blatant spam you lost out on the 5 bucks or whatever it'd cost you, but if you're making a legitimate report that wasn't accepted for whatever legit reason, you get it back. Makes it so incentives are still there, though I guess this can be abused (not like it's not already) - Fee waivers and a whitelist system. After all, if you've sent in multiple reports and they turned out to not be spammy, then you deserve the benefit of the doubt to freely send in reports. This can also be extended to a chain of trust in the wider bug reporting ecosystem, which encourages people to stick to a "main" account where their identity and reputation is established Though I still expect lots of people wouldn't like this system, and for good reasons as well. Not sure what a perfect system would look like though, to be honest
- nucleardog 3y agoNot hugely different but seems easier on my brain to instead set up an “account deposit” or something. Put $5 in to register your account. * If you have a report validated as “not junk” (not “a valid vulnerability”, just “not spam / good faith”) we send it back and your account is whitelisted. * If you submit a junk report your account is closed and we keep it. * If your account hits 30/60 days with no submissions, we refund and close it for inactivity. The extra charge per submission seems largely unnecessary. If someone signs up and creates two dozen spam reports, just close their account and all their reports. How well this would work would largely, I imagine, hinge on the success rate of these guys. If they’re sending in 100 reports to get a single $1000 bounty, then there’s still a positive ROI if your time is cheap enough. At least requiring a unique payment method for each attempt would cut down on repeat offenders.
- yencabulator 3y agoOne challenge is that if you refund many payments, your credit card processor will increase your fees. Confirmed donations to chosen charities might work.