5 ms·
No bounty for bug report? Should at least have a nominal fee of $100 (else no one would bother to report it).
by d_luaz 11y ago
No bounty for bug report? Should at least have a nominal fee of $100 (else no one would bother to report it).
- squiguy7 11y agoI agree. If I had my own company I would surely provide some incentive for bugs found in the product. Whether that incentive was monetary, a free membership, etc. I think it's important to acknowledge that all software systems are imperfect.
- reagan83 11y agoThe economics of bug bounty programs could lead to misaligned incentives. Because the overhead cost to validate and communicate around bug reports isn't zero, the % of non-bugs submitted could become imbalanced because it is free to submit. In most systems the reward is zero, so you can infer if a person has taken the time to submit a bug report it is because he/she is invested in seeing it fixed. Context: I work at a decent sized company in SV on this type of problem.
- d_luaz 11y agoSo the best solution is not to have a reward? Or not to have a publicized reward? Or don't depend on the public on bug hunting? Or just hope on goodwill?
- nmjohn 11y agoSo when I find a bug in say Paypal which allows complete account takeover and could sell it to an organized hacker group for say $100,000 or report it to Paypal "because I'm invested in seeing it fixed" and receive nothing - that is only an easy decision for the whitest of white hat hacker. Properly designed bug bounty programs are a cornerstone to any company who remotely cares about the security of their product, period. The idea of misaligned incentives due to poor bug reports being free to submit is ignorant - and worse toxic, because it sounds so true to an executive who has no actual understanding of the issue. A quality bug report should take no more than 1 minute for a reviewer to look at and know if it's really a bug or not. If it can't, it should be rejected saying provide more clear details. For example a dom based xss attack could be reported with just a target URL and it is quite clear what the problem is. That would take 10 seconds to analyze. Additionally, most bugs reported to most decent sized companies are reported by someone who has previously reported a bug to the company before. If someone is constantly reporting good bugs or the opposite, its quite easy to prioritize which of those individuals gets their emails read first.
- smitherfield 11y agoIt's hard to think of an easier decision. Get $100,000 for a couple months before you go to federal prison for 30 years, or hire a publicist and get featured on every tech blog in existence as "the guy who found the PayPal complete account takeover bug," and let the 7-figure job offers roll in.
- dsacco 11y agoAs someone who has found several arbitrary account takeover bugs impacting >100M users, I can tell you this will give you job offers, but only in the low 6 figures. With the state of the media in the infosec industry, having your finding widely publicized doesn't mean much, either.
- nmjohn 11y ago> let the 7-figure job offers roll in. I would know far more millionare engineers/hackers if that was actually true > go to federal prison for 30 years If one was talented enough to find such a vuln, it is hardly a stretch to say they would be smart enough to avoid getting caught.
- MichaelGG 11y ago>If one was talented enough to find such a vuln, it is hardly a stretch to say they would be smart enough to avoid getting caught. ... This is plainly not true. First, the ease of finding a bug in a web app varies considerably. This article, for instance, was simply about resending requests quickly. It doesn't necessarily require amazing intellect to come across such a bug. Look at famous "hackers" that dicked around with querystrings and got into all sorts of fun. Second, even if someone is smart and figures out how to solve a certain problem to gain root, it does not mean they're clever, aware, or dedicated enough to maintain opsec. One mistake, any time, and you're toast.
- comex 11y agoBut not all real security issues are reported by a competent person, or by someone who has even a vague idea what the true nature of the bug is; ignoring reports for not making sense on their face is dangerous. Some companies feel they have a duty to do due diligence... http://blogs.msdn.com/b/oldnewthing/archive/2011/12/15/10247870.aspx http://blogs.msdn.com/b/oldnewthing/archive/2011/12/15/10247... (I've never been on the receiving end of a security mailbox, so I have no personal testimony as to the reasonableness of this approach.)
- diminoten 11y agoClearly not, though.