3 ms·
According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Mariss
by Zirro 12y ago
According to this[1] article about the current issue:
"Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.
It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme."
[1]: http://www.independent.co.uk/life-style/gadgets-and-tech/news/shellshock-romanian-hackers-are-accessing-yahoo-servers-claims-security-expert-9777753.html http://www.independent.co.uk/life-style/gadgets-and-tech/new...
EDIT: The quote previously included "Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise." but I moved it here as it caused confusion regarding which issue the article was referencing.
- elliottcarlson 12y agoPlease read the follow up: http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the-guy-who-sent-the-t-shirt-out-as-a-thank-you http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the... (and HN discussion: https://news.ycombinator.com/item?id=6488897 https://news.ycombinator.com/item?id=6488897)
- deleted 12y ago[deleted]
- scrollaway 12y agoThey keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.
- kjjw 12y agoAre these people concerned with security or are they running a protection racket? The way you put it is starting to sound like the latter.
- scrollaway 12y agoThis has nothing to do with "protection racket" and downvoters are going to be in for one hell of a reality check if you don't believe that this will happen. Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
- eli 12y agoI frankly don't believe you. I think you vastly overestimate how much you can sell a vulnerability for and vastly underestimate the morals of white hat hackers reporting bugs for a bounty. There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.
- otakucode 12y agoMitnicks security company recently started a vulnerability marketplace. For vulnerabilities that meet the criteria (they have to be of a certain severity, not already known, etc), they are sold for a minimum of $100,000.
- tcheard 12y agoMicrosoft will pay up to $100,000 plus $50,000 bonus for defense submissions (http://technet.microsoft.com/en-us/security/dn425049 http://technet.microsoft.com/en-us/security/dn425049) Facebook has paid $12,500 for one (http://techcrunch.com/2013/09/02/security-researcher-discovers-bug-that-would-let-hackers-delete-any-photo-off-facebook/ http://techcrunch.com/2013/09/02/security-researcher-discove...) Google will pay up to $20,000 for one (http://www.google.com/about/appsecurity/reward-program/#rewards http://www.google.com/about/appsecurity/reward-program/#rewa...) Forbes even posted an article a couple years ago on the market of zero day exploits and listed prices someone could get for zero day exploits with prices in the tens/hundreds of thousands. (http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/ http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...) It should be noted that they state in this article that the groups that will buy these exploits for these prices are generally western governments.
- eli 12y agoThat article is poorly reported. Yahoo didn't have a bug bounty program at all at that time. And their response was blown totally out of proportion.