10 ms·
What's XSS an usually worth? I'm guessing it varies by product and company but, I would venture to say about $500-1000. Really puts the $12.50 in company store
by uncoder0 13y ago
What's XSS an usually worth? I'm guessing it varies by product and company but, I would venture to say about $500-1000.
Really puts the $12.50 in company store credit into perspective.
- theboss 13y agoIt depends on severity but I believe at google the minimum is $1337. With that being said, $12.50 is $12.50 more than PayPal's. I don't know anyone who has reported a vulnerability to PayPal that has actually received a reward.
- mythealias 13y agoI wonder if not paying would be better than paying a small amount.
- agwa 13y agoDefinitely. Paying such a small amount, especially in credit that can only be redeemed in a company store, is patronizing and gets you mentioned in a negative light on Hacker News. If you don't pay, you're just like one of the many companies that doesn't have a bounty program. Edit: this reminds me of the "eBay goodies" offered to researcher Neal Poole in return for delaying disclosure of a vulnerability [https://nealpoole.com/blog/2013/03/bad-changes-to-ebays-responsible-disclosure-policy/ https://nealpoole.com/blog/2013/03/bad-changes-to-ebays-resp...]. I would probably not have remembered that story if not for that "eBay goodies" line, just as I probably won't forget this story thanks to the screenshot of Yahoo-branded socks in the company store.
- StavrosK 13y agoI agree with you. This reminds me of a 4-hour delay I had while flying with Delta, where they gave me a food voucher for two and a half dollars as an apology (only redeemable at the airport cafeteria, where the smallest sandwich cost $5). Now I will hate them for ever. I believe that not paying is better than paying little, because if you don't pay I can at least consider that you owe me one. Giving me a pittance removes the obligation from you for almost nothing. Even though this isn't very applicable to companies, I think that's the reason why we consider it insulting.
- im3w1l 13y agoI seem to remember having read that when something is done for free it is handled by the brains "maintain reputation and make friends" system, while when money is involved it is handled by the "make a profit, don't be screwed" system. My google-fu is failing though.
- shalmanese 13y agohttp://en.wikipedia.org/wiki/Overjustification_effect http://en.wikipedia.org/wiki/Overjustification_effect
- chc 13y agoWell, what an XSS is worth on the black market is not necessarily the same as what companies offer to researchers who report vulnerabilities. Many companies will offer nothing more than a "Thank you, so-and-so" somewhere on their site or in the release notes for the fix. I think the problem with Yahoo's response is that it looks like they are actively being cheapskates. Almost universally, cheap is worse than no-money-involved. A "thank you" might be appreciated, a reasonable monetary reward will probably be appreciated, and even sending some free swag might read as a warm gesture, but offering a $12 store credit pretty explicitly says "I value this very little."