4 ms·
> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we. so it should be fought by giv
by r_lee 20d ago
> The follow up arguments will be that since billion dollar companies ultimately only care about their bottom line, so should we.
so it should be fought by giving them free work in the hopes that they'll finally feel guilty and then start paying proper bounties?
like to me that just seems funny, as if they'd change anything if we'd keep rewarding them for not doing the right thing
like, there's a reason regulation exists for all kinds of shit because otherwise companies would do all kinds of atrocities in hopes of cutting costs
- sublinear 20d agoAt some point, you will realize two things. First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial. What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging pessimistic groupthink and bad faith. This is why businesses can't be more open about their flaws. It's not that they're stupid and incompetent, but that the pitchforks come out. These are the seeds of dystopia. They would have eventually figured it out, but as an unfortunate incident with an outsized effect. As much as you wish it to be true, even the worst of these incidents will not kill their business. As much as you hate these businesses, their financial momentum will eventually cause the public to depend on them more. There's more at stake here than anyone's personal gain. It's naive to think otherwise. You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar.
- cindyllm 20d ago[dead]
- r_lee 20d ago> You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar. are you replying to the right person? I'm not hating on any business or trying to "kill" any business. I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best. is that "ghetto punk ass behavior"? what are you on about?
- sublinear 20d ago> I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best. is that "ghetto punk ass behavior"? Yes. If you have say, managed to find an overlooked passage into an ostensibly high security building, "doing what serves you best" such as selling the information to some thugs, is in fact that kind of behavior.
- r_lee 19d agoI think that's a bit different. for real security bugs, like, you can literally sell them to brokers who sell them to governments. would selling stuff to the CIA be ghetto? morally, it depends. but after seeing so many posts of e.g. Google cheapskating on bug reports, it really makes no sense to me to participate in such a broken system. this case however is quite different as it was a B2B encounter and during vendor vetting like to me it just seems like a fair deal, if Google wants their bugs patched (which they can definitely afford to do) they'd just pay properly for serious bugs and so on, and everybody would be happy. it's not some kind of thing where they can't do anything about. maybe you can understand the angle I'm coming from?
- DonHopkins 19d agoMaking Nazi salutes, and defending people who do, is ghetto punk ass behavior.
- manquer 20d ago> free work Don't know if I would call it that ? This was a potential customer reporting a result of an audit of a tool they are evaluating. This is frequent and normal activity in enterprise deals. Most of the time such reports are not critical vulnerabilities it would things like tenant configuration -what business would like versus what CISO will accept or risk acceptance of the product they are buying with monitoring or other prescription on access restrictions or a DPA and so on. It would be novel business model to spend ton of money in getting a prospect to late-deal stage where they are ready to do a security audio for you just so that part is "free" . Most companies wouldn't disclose(to the public) even if it was serious , that is not their job, they will report to internal teams and re-review on fix. Strix.ai has a benefit in doing so as they sell a scanning tool for this purpose so we get to hear of this.
- sellmesoap 19d agoBut don't forget there are also regulations so the regularly scheduled atrocities can keep happening!