3 ms·
I really hate this take. If a company refuses to pay more than the gray market is offering, then they are the ones at fault for putting their users at risk. Go
by saltyspaghetti 3y ago
I really hate this take. If a company refuses to pay more than the gray market is offering, then they are the ones at fault for putting their users at risk. Go and guilt trip the entities who are undervaluing the time and effort spent finding vulnerabilities. I place zero blame on researchers selling vulns unless the software company is willing to pay at least as much as the gray market.
- piva00 3y agoAnd I really hate this take. It's basically a hostage situation then "pay us as much as those criminals there would pay or else... Your users will suffer the consequences". Yes, it's the company's fault for putting the users at risk by creating an exploitable issue, there's the other side of the coin where it will be the "researcher's" fault for selling it to the highest bidder damned be the consequences. Both sides have their ethical issues, I think the company should pay but also that researchers should look quite deep into their souls if it's ethical to fuck with users because an entity they have no control over (the company) fucked up. To me it sounds like an immature tantrum, unfortunately from my experience with security researchers it feels to be a field with quite a few rage-tantrums. Ethics do matter, on both sides.
- saltyspaghetti 3y agoWhy shouldn’t there be bidding wars to determine the value of an exploit? These large software companies have zero issue with exploiting capitalism when it benefits their bottom line, and yet it’s suddenly unethical for a researcher to demand to be paid market value for their work? Look at Google, a 1.6 trillion dollar company. They have virtually limitless resources when it comes to paying for secure software, and yet they offer less than half the $ for an Android zero click when compared to Zerodium. Pay people the fair market value for their work and all of this becomes a non-issue. They can afford to do it.
- piva00 3y agoThe ethical issue is when this capitalist fight between market prices for exploits have very real damaging consequences for unwitting users that have nothing to do with the bullshit. Why should they pay the ultimate price because a company is trying to fleece security researchers? Is that the only way to make them pay, to cause damage to what amount to "civilians" in this war? That's my point, these people, very real people, have nothing to do with the whole bullshit, they trusted in a 3rd party to use their product, they can't audit every single 3rd party they use for security holes, even less research themselves ways to exploit them before using their products, you are saying that it's ok for these people to suffer because Google didn't want to pay for an exploit that was discovered. It boils down to the same question: why are the researchers doing this job? If it's because they believe they are helping make software more secure then ethically they shouldn't be putting unwitting end users into harm. If they are just looking for a paycheck then it's just morally corrupt to use users as hostages to get a ransom. I repeat what I said: this is the ethical discussion I'd like to see happening, not this immature "they didn't pay me, so fuck all the users, I will blow it all!", that just sounds like children throwing tantrums. Again: why do researchers do this job? Underneath that you can judge if it's ethical to just sell to the highest bidder, capitalism is amoral, we as humans imbue some sense of morality into it... This approach of "pay what the market is paying or else I will fuck your users" is, in my opinion, ethically wrong, if a researcher is serious about the job they are performing to make the world a less shit place then they need to have some moral guideline to follow, if not it's all bullshit and they are just mercenaries, and I don't support mercenaries.
- pierat 3y agoPerfect example of the guilt-tripping crap seen in infosec. Where I come from, when you say if you do X, I'll pay you Y, it's unethical and a tort NOT to pay Y if you do X. You can do whatever contortions around 3rd parties (users). As long as the exploit vendor doesn't say they're doing anything illegal, I'm in the clear. I've had 1 vendor say that they were engaging in illegal activities, and refused to sell. Again, some may want to auction to highest bidder. Whereas I just like to eat. The companies are the ultimate unethical entities here, that summarily made everyone else look bad, all the while they're hitting users and saying "quit making us hit users!"
- pierat 3y agoTheses less of an ethical issue than what's argued. I have been screwed by 2 different companies over "proper" reporting. They came back and said I didn't qualify for bug bounties. Then they turned around and PATCHED said bugs that didn't qualify for stated bug bounties. The issue isn't "who's the highest bidder" but instead "who will actually pay what they say". And frankly, the whole of infosec is full of holier-thsn-thou's and corporate scamming. I'll sell to who will pay. (NOTE: what I type only applies to closed source and corporate websites. FLOSS gets free and discrete reports. No 0days for FLOSS. I'm just done being screwed by corporate interests who claim to pay and then screw you over.)