4 ms·
...intrigued by the bold sentence on Facebook's security researcher page "There is no maximum reward" I went out and started giving Facebook's code another peak
by epenn 13y ago
...intrigued by the bold sentence on Facebook's security researcher page "There is no maximum reward" I went out and started giving Facebook's code another peak.
I'm not surprised that you feel this wasn't enough since it appears the reward is your motivation for finding an exploit in the first place. The reward shouldn't be viewed as payment for services rendered, but rather as a gesture of good will for performing your duty of responsible disclosure.
Without the disclosure of whitehat hackers, like I did, these exploits can also become available to dubious parties who could wreak (digital) havoc.
If you are truly a white hat then you aren't motivated by money. You are principally motivated by wanting to make the world a better, safer place. Since you're well-versed in computer security, that motivation will propel you to apply that knowledge to the web (or really to any vulnerability) when the opportunity presents itself.
If the reward is your motivation then at best this makes you a grey hat. You did the right thing, but for the wrong reasons. Note that for the following I'm not saying you personally will necessarily do this; but it would be easy from that position to start treating the group of people who you're willing to disclose a vulnerability to as a marketplace. Facebook will pay $4,500? Fair enough. L33tBotNetHaxz0r will pay $20,000? Done.
If you're someone who possesses the skill to discover security vulnerabilities, I think it's important to think through what your real motivations are. Is it for the rush capturing the flag? Is it for the money? Is it to help people? Your actions can affect many, so act wisely.
Edit: I should clarify that I mean that money can't be the principal motivation for a white hat hacker. I believe it's fine as a secondary motivation. I give an example in another comment below.
- deleted 13y ago[deleted]
- jonahx 13y ago>If you are truly a white hat then you aren't motivated by money Says who? People who would never commit a criminal cyber-act are still allowed to care about money.
- epenn 13y agoI never said they weren't allowed to care about money in general; only that it shouldn't be their primary motivation for disclosing a security vulnerability. Even if it is, I'm not saying that makes them a bad person either; only that they can't use the white hat label as the author did in my second quote.
- chm 13y ago> performing your duty of responsible disclosure He has no duty. Facebook engineers do, but it was him who found the bug. My understanding of the article is that he doesn't care how much money he gets from Facebook. The 4.5K is representative of how much they care about customer privacy. That's what, I think, his only point is.
- epenn 13y agoHe has no duty. If he is going to use the white hat label, which he does, then he does in fact have that duty. If he chooses to hide the vulnerability or sell the knowledge and/or exploit to another party, that's his choice of course, but then he cannot use the white hat label. The 4.5K is representative of how much they care about customer privacy. That's what, I think, his only point is. I understand that's the point he's trying to make, but I respectfully disagree since as previously stated I view the reward as a gesture of good will and not as a payment for services rendered.
- tomjen3 13y agoResponsible disclosure isn't a requirement for white-hat status, white-hat status just means you don't do any harm. Full disclosure can also be white-hat as can sitting on the bug.
- epenn 13y agowhite-hat status just means you don't do any harm This definition falls short. For example, the hacker who spends time searching for a vulnerability with the intent to do harm, but fails to find one. The hacker has done no harm, therefore by your definition he or she is a white hat despite the fact that they would do harm given the opportunity. For that reason, a person's motivations need to be taken into account in order to provide a proper assessment.
- chm 13y agoHis only duty was to report the bug. He didn't have to look for it. That's what I meant.
- tripzilch 13y ago> If you are truly a white hat then you aren't motivated by money. False. > You are principally motivated by wanting to make the world a better, safer place. Probably true. That's not contradictory. And neither is wanting to disclose a vulnerability responsibly, wanting Facebook to be secure against the vulnerability you just found (even only because it affects you, your friends, family, people you care about) and at the same time feeling that $4,500 is a bit of a meagre bounty for a find of some particular severity. You can argue about whether $4,500 is, or is not, reasonable. But as you may notice, it's not like he held the bug "hostage" threatening to sell it to the black market otherwise, or even hinting at perhaps doing that the next time. He can be wanting to make the world a better place (or Facebook a safer site), and still be dissatisfied with the reward he got. Even rationally: for instance, one could reason that even though they could sell the bug for $20k on the black market, this could cause damage and harm to innocent people on a scale (and with a certainty, because they won't buy the bug to just sit on it) that isn't worth the extra money he could gain (and for people with a decent moral compass that threshold is passed easily without even having to consider the risks of dealing with the black market etc). Then, having come to this conclusion, one could say "Well, I did the right thing, and I am disappointed that Facebook isn't offering more incentive for others to do the same". Also, the incentive is not just for convincing people to give the bug to the good guys instead of the bad guys. It's clear from the article that he spent a deliberate and non-trivial amount of effort on finding this bug, he didn't just stumble across it. This Facebook bug was found because they offered a mystery prize, prompting him to search for a bug and dig deep, then he got disappointed that the prize was less than he anticipated. It's not so much a question of "will he sell it to the bad guys next", rather it's "will he bother going through that much trouble again to help fix a flaw in Facebook, knowing what the payoff will be?" That said, my question: is $4,500 really too little? How much hours did this cost him (times a price appropriate to his specialist knowledge, of course), so how much should it have been, for doing the right thing? 2x, 3x this? I don't think straight up matching it up to black market prices really makes a lot of sense, there's too many external factors that make it a very different deal.
- __david__ 13y ago> is $4,500 really too little? How much hours did this cost him (times a price appropriate to his specialist knowledge, of course), so how much should it have been, for doing the right thing? 2x, 3x this? I don't think that's the right way to look at it—it's not a straight manual labor thing ($/hour * hours = $). The question is, how much money is it worth to Facebook to fix a potentially embarrassing vulnerability. For a complete profile exposure type bug, I would expect that's more than $4.5K.