5 ms·
If you want hackers to report you vulnerabilities via Yahoo Bug Bounty Program, at least pay more than 50$ for a minimum bounty, 50$ is a joke https://hackerone
by somebugbounty 12y ago
If you want hackers to report you vulnerabilities via Yahoo Bug Bounty Program, at least pay more than 50$ for a minimum bounty, 50$ is a joke https://hackerone.com/yahoo https://hackerone.com/yahoo ...
- tptacek 12y agoThat's the minimum bounty. It's what they'll pay for an off-brand CSRF. They'll pay up to $15,000. Wild guess: RCE doesn't get the minimum bounty.
- somebugbounty 12y agoRCE is 3000$ for *.yahoo.com https://hackerone.com/reports/6674 https://hackerone.com/reports/6674. I forgot, they want RCE on https://login.yahoo.com https://login.yahoo.com, and then maybe, but maybe, they will pay 15000$ Thank you
- tptacek 12y agoThat one single instance, in those circumstances, was $3k. Which (a) is much, much more than $50, and (b) is not bad for a bug that dies the instant the vendor learns about it.
- suyash 12y ago$50.00 is a joke, I'm sure they can do better.
- tptacek 12y agoMe too. I am sure, too. You know how I'm sure? Because I clicked the link the parent commenter helpfully provided alongside their gripe about Yahoo's bug bounty and read that they do, in fact, do better.
- byerley 12y agoI view bug bounties as more of a conscious nod towards responsible disclosure than anything else. I sincerely doubt anyone could make a competitive living off of bug bounty programs (even accounting for the legal grey area of selling vulnerabilities) so the economic incentive argument seems really silly to me. In contrast, if you've ever tried to responsibly disclose a vulnerability and gotten a threat from the legal department in response (still common practice in a lot of companies), a bug bounty program can be a very encouraging show of good faith.
- f- 12y agoI think there are quite a few people who do make a living by participating in vulnerability reward programs (well, not at $50 level, obviously). Now, I have not seen too many people who would be doing it consistently for many years - simply because it gets tiresome. But it's the same thing for security consulting - at most consultancies, pentesters come and go.
- secalex 12y agoWe have several participants in our program who are making a pretty decent living, especially the ones for whom a US$5000 reward is comparable to their nation's per-capita GDP. We are hoping to highlight some of these people in a future talk. I personally think that the opening created for those without the educational or economic opportunities available to developed world researchers is the best side effects of bug bounties.
- JonathanDHall 12y agoI bypassed the bounty program because I had better things to do with my time than fill out a form to get a $25 T-shirt, regardless of that shirts worth in GDP... Yahoo! contact information is generally hard to come by, and even when it is used, it's generally ignored. Anyone on NANOG could certainly confirm this. For example, the phone number on your whois information does not even land at a voicemail, and is a business-hours only phone number.