3 ms·
You let the market decide. Google could purchase the bugs on the same market blackhats do.
by quotemstr 21d ago
You let the market decide. Google could purchase the bugs on the same market blackhats do.
- jsw97 21d agoIn the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.
- eru 21d ago> In the past I would have thought this would incentivize finding bugs that might never be found. Isn't that a good thing? > However it is now clear that all bugs that can be found will be found. So this makes a ton of sense. If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.
- deleted 21d ago[deleted]
- tptacek 21d agoGoogle directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions: * They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable). * They don't require you to actually build a reliable exploit chain. * They pay up front, not in tranches. * They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.
- jeffbee 21d agoThey pay in plain old money, too. On the market your counterparty will be a criminal who is trying to scam you every step of the way.
- tptacek 21d agoNot so much, the grey market is pretty well structured.
- paulhebert 21d agoIs there anywhere I could read more about this? Sound very interesting!
- nbk_2000 21d agoThe Grugq has done several interesting interviews/articles on the industry. There's also a couple of Darknet Diaries episodes with similar interviews.
- asdfaoeu 21d agoBlackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.
- quotemstr 21d ago> Blackhat markets will always be able to pay better. ... than Google? > Selling to Google though you aren't chancing jail time. Why would you go to jail for selling a vulnerability? It's free speech.
- ajkjk 21d ago"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.
- quotemstr 21d agoHas anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.
- deleted 21d ago[deleted]
- ndriscoll 21d agoIt would be absurd to jail someone for accurately describing a bug on their blog or whatever. Not so much for taking money from someone who the buyer should know has no reason to be interested in buying the information. And either you know who your counterparty is, in which case you know that they are using it nefariously, or you don't know who your counterparty is, in which case you know that they are using it nefariously. Any court and any jury should see straight through this. Similarly if you figure out how to get the ATM down the street to give you free money, and you "accurately describe the bug" to people who pay you, and they use it to steal money from the ATM, expect to be charged for participating in, and in fact being an instrumental enabler of their crime. Because it is beyond all reasonable doubt that you could've believed they could have been interested enough to pay you for any other reason.
- bawolff 21d agoWell, someone did decide to tell google about this in exchange for a thousand dollars (albeit unclear how much the money was the motivator). Doesn't that mean the market did decide in google's favour?
- drdexebtjl 21d agoSomeone decided to tell Google about this in exchange for an unknown amount of money, chosen unilaterally by Google at a later date, at which point the market value of the vulnerability is $0. There's no way money is the motivator.
- bawolff 21d agoMoney is not the only coin to pay someone in.
- ajkjk 21d agowe really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.
- Alive-in-2025 21d agoCompanies sometimes reward their employees with important bug fixes. When I worked on a big dev team, we'd even decide what were the most important fixes and give people a special 5k bonus or something. But they weren't security issues necessarily. I never thought about it, fixing a huge performance issue is big. A security fix that gets caught early makes no noise so you just don't know how important it would have been. We also once had a really terrible bug that lead to lots of customers getting effectively attacked.
- vova_hn2 21d ago> Companies sometimes reward their employees with important bug fixes. Potentially creates a misaligned incentive to intentionally hide bugs in the code you write so that later you can fix it and get the bounty.
- flutas 21d agoFinding bugs is hardly a crime, selling them even isn't. Now exploiting them? Yes that's a crime.
- codedokode 21d ago"Crime" is very flexible term. One country's criminal is another country hero. Maybe the author would sell the vulnerability to an organization making exploits for government use. "Safety" is also a relative thing, when the world is safer for one party, it is usually worse for another.
- allendoerfer 21d ago
- readme 21d agoThey would be broke quick.