3 ms·
> So far, for the vulnerabilities I have reported to Google, ASUS, AMD, TP-Link, Netgear, MSI (and more), they have paid out a total of $0 in bug bounties. Why
by aucisson_masque 3mo ago
> So far, for the vulnerabilities I have reported to Google, ASUS, AMD, TP-Link, Netgear, MSI (and more), they have paid out a total of $0 in bug bounties.
Why bother reporting to them ?
You could just as well sell it to third parties if it doesn't interest them.
- lnenad 3mo agoYou understand the concept of doing something that doesn't bring direct monetary benefit?
- dev_hugepages 3mo agoHe makes a point, though: bug bounties exist to incentivize people to find and report bugs to a company. We talk about white, gray, and black hats, roughly based on their level of ethics. For black hats – and some gray hats – money is one of the big reasons they look for vulnerabilities.
- nicman23 3mo agoyou understand the concept of zero days ? companies should be better and if not, criminally liable for their bad code.
- dist-epoch 3mo agoI don't think you thought this through. does this also apply to individual developers? should Linux Torvalds or the ffmpeg developers go to jail if they merge a RCE zero-day into the Linux kernel or into ffmpeg?
- nicman23 3mo agogross negligence / honest mistake if you cannot differentiate the 2, :insert rude thing here:
- dist-epoch 3mo agook, so you agree that if Linus merges code due to gross negligence, for example he was warned in an email that it contains a RCE and he laughs it off, and still merges it, he should go to jail glad you are consistent in your beliefs
- lnenad 3mo agoOk? I agree with everything. What does that have to do with reporting exploits that don't have bounties?
- userbinator 3mo agoIn other words, bootlicking the corpo-authoritarians?
- lnenad 3mo agoYou're actually helping the people that use the software from getting pwned, companies are secondary beneficiaries.
- userbinator 3mo agoKeep toeing the line and help them put the nooses around your necks.
- lnenad 3mo agoWhat wild regurgitation of some generic sentence is this lol?
- aucisson_masque 3mo agoYes I do, but we are speaking of companies with billions. If they can't take this seriously enough that they pay for the vulnerabilities, they deserve to get the bad press. When all MSI computers get exploited in the wild, I bet that these execs will find money.
- lnenad 3mo agoBut it's not "MSI computers" it's actual people getting pwned.
- aucisson_masque 3mo agoI know but I don't think there is any other solution. These companies speak money, if you don't speak money they ignore you. Getting your users computers infected and having to deal with bad buzz, prosecutions, loss of sales, would most likely wake them up. Sending them a mail ? They don't care.
- lnenad 3mo agoIf it's my data/money getting stolen, I'd give no fucks about MSI getting a fine or whatever the usual reaction to these fuckups is. On the other hand, if I found an exploit and there wasn't a bounty available, I'd still report it. Betterment of the world and all that.