6 ms·
The pricing on these bug bounties always blows my mind. If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billi
by bookshelf11 6y ago
The pricing on these bug bounties always blows my mind.
If this hack had been exploited Tesla market capitalization would've taken a multi-million if not billion dollar hit. And here they are, paying out relative chump change to a guy that alerted them to it.
- salty_biscuits 6y agoMaybe, maybe not. What happened to Garmin's share price?
- amanzi 6y agoHow is that even remotely similar?
- bookshelf11 6y agoGreat question. I think I'd say the big difference is that people, for the most part, aren't putting their/others lives in Garmin's hands when they use their devices. That said, I think they have some hiking/trekking oriented products which could cause problems if you were relying on them. The headline "electric car fleet hacked" is a lot scarier than "smart watches hacked". Then again, maybe people really don't give a shit about this stuff, and these bounties are priced correctly.
- deleted 6y ago[deleted]
- Aeolun 6y agoI think, if this had been abused, Tesla would be out of business. But the fact that $50000 is chump change for Tesla does not mean it's chump change to the recipient.
- falcolas 6y agoIt's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income".
- Talanes 6y agoPeople who assume the world is fair will always find the justifications for why any status quo is valid.
- rtlfe 6y ago> It's funny, we always talk about compensating leaders for the value they provide to the company. Yet when it comes to non-leaders, it's transforms into a question of "value relative to their current/recent income". That's maybe true for founders, but not really for hired executives: > One major consideration that goes into how much a CEO should be paid is what other companies are paying. Compensation committees benchmark CEO pay against a self-selected peer group -- often 12 to 20 companies that may be of similar size and complexity, and have similar business models, according to Robin Ferracone, CEO of Farient Advisors, an executive compensation consulting firm. https://www.cnn.com/2019/10/24/success/ceo-pay-packages/index.html https://www.cnn.com/2019/10/24/success/ceo-pay-packages/inde...
- deleted 6y ago[deleted]
- filleduchaos 6y agoThe bounty was $5,000 not fifty thousand. And frankly that would be chump change anywhere for the opportunity cost.
- sellyme 6y agoIt was $50,000: > He didn’t end up getting a new Tesla, but the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit: You're looking at the $5,000 bounty awarded for exposing Supercharger-related data that Tesla "didn't want [...] out there", which is obviously a much less severe issue than remote control of the entire fleet.
- filleduchaos 6y agoAh okay, thank you. Not sure why the $5000 figure stuck with me
- jefftk 6y agoNo, $5k was for an earlier bug. "the automaker awarded him a special $50,000 bug report reward — several times higher than the max official bug reward limit"
- autisticcurio 6y ago$50k is not alot considering how much it would have harmed the share price with the negative press reports around the world. It could have even taken the company to the brink of extinction. For comparison, to get middle section, right hand side 1/2 page article written in the Sunday Times and Observer would have cost you about £30k 10 years ago to be introduced to the journalists writing your advert masquerading as a story. Multiply that up for all the global news outlets and the $50k bug bounty was a pittance. I wouldnt have been surprised if Musks day to day wine cellar was several times more expensive than that $50k bug bounty. 18 years ago my peak earning rate was £5k an hour so dont knowingly undersell yourselves in your day job or with bug bounty's. Simple letter govt agency's will also cover stuff up, using state broadcasters and other so called free press media outlets to put a spin on things or outright mislead. Seen this twice now.
- StillBored 6y agoHow long do you think it takes for someone to find an exploit? Sure, a long time ago I found problems in web pages by clicking "view source" and going "I wonder what happens if.." and doing POST/GET with a huge buffer, or with "\");...." embedded in it. These days companies that take their security seriously are hopefully harder to exploit. If it takes someone a couple months of slow fuzzing/etc to find an exploit that is probably below market for the persons skills here in the US. Maybe a part of these bug bounties should be not only how critical the bug is, but some metric of how much work the individual put in before finding the problem.
- TheSpiceIsLife 6y agoAny one individual could put in an arbitrarily huge amount of work, or claim to have, in order find a bug. How do we classify what constitutes work to find any particular bug?
- oconnor663 6y agoI wonder if at some level of bounty payment, you run into the problem of encouraging people to introduce bugs to get a bounty. Probably no one with commit access in a major tech company would risk their career for a few months salary. But for ten years' salary...
- brippalcharrid 6y agoIt just needs to be a subtle bug designed by someone much smarter than the comitter, that's plausibly deniable. They certainly don't need to understand how it works, or how it's going to be used months or years later. And I understand that this sort of thing happens with governments, and TLAs, and the people leave after a few years to start their own gig with VC funding and subsequent acquisitions and no-one's the wiser.
- rtlfe 6y ago> They certainly don't need to understand how it works They must need to know something about it in order to verify that it does the malicious thing correctly. It's hard enough to get code right when there's a whole team of people who know exactly what it's supposed to do.
- brippalcharrid 6y agoIt depends on how active the person has been in choosing the target and the exploit. If a nation-state actor has pored over the source code for some time before/after approaching a person in a tech company with commit privileges, they might be in a position to give them code to introduce that's as limited as possible and which does exactly what they need it to, while seemingly being entirely in keeping with that person's prior work and the organisation's development practices. For the attacker, the less exposure their insider has to actively thinking about how to subvert the system that they have access to (which they could later confess to if questioned/arrested/jailed) and the fewer opportunities there are for someone to notice that something's amiss and for the person to come under suspicion, the better.
- 6y ago
- sellyme 6y ago> If this hack had been exploited But that's the point. Who's out there that would exploit this because they thought $50,000 wasn't worth it, but would change their minds for $1,000,000? Realistically there's only two types of people who would maliciously exploit something of this magnitude: the mentally unstable (people who just like to cause chaos), and state-sponsored actors attempting to disrupt other nations. Neither of those groups seem particularly likely to change their mind for an extra zero or two. The "pay more than the black market will" model works for smaller bugs, but for ones like this that would immediately get every three letter agency on the planet trying to find you, the $50,000 isn't a valuation of the worth of that bug report, it's a gratuity. And for the average bug reporter, that's an extremely nice one. Can they pay more? Yes, absolutely. Should they? Probably, yeah. Do they have any reason to? No. The solution to this is to have legal requirements for security, and extremely heavy fines for having released dangerous software (some portion of this fine financing a similar bug bounty program). Take the option of how much money to hand out away from the companies, and they'll be incentivised to take security much more seriously in the first place. Of course, this requires lawmakers to have a basic understanding of technology, so we're at least 20 years and 3 major catastrophes away from getting anywhere near that actually occurring.
- ssss11 6y agoSurely there’s more than 2 types. Another off the top of my head - competitors.
- sowbug 6y agoOP meant two types that are indifferent to consequences.
- warent 6y agoAgreed. Another could be solo blackhats who just want to make money, who have no state sponsorship. Tangental, but I also hesitate to create such a massive bucket for "mental instability" like that. It's easy to find when someone who does something difficult to understand, or against what we would do ourselves, and then just say "well they're mentally unstable." Definitely the case for some, but it seems like a lazy dismissal with no attempt or interest at understanding.
- bookmarkable 6y agoI wonder why they aren’t paid in vesting stock. $50k in Tesla stock in 2017 would be a nice pay day. It would also align hackers interest with the businesses they are helping secure.
- rtlfe 6y ago> I wonder why they aren’t paid in vesting stock. Most people would far prefer cash
- everfree 6y agoI wouldn't necessarily want the stock of a company that I just found a critical vulnerability with.
- tptacek 6y agoThen you wouldn't want the stock of any tech companies, because people find critical vulnerabilities in all of them.
- wglb 6y agoIt's not very often that serious vulnerabilities affect the stock price. Check out the stock price of Bank of America after their servers got rooted several years back. Or that Breach that Deloitte had. How about Cloudflare?
- dheera 6y agoYou can always take the $50K and buy Tesla stock with it. How is it any different?
- deleted 6y ago[deleted]
- dheera 6y agoThey only need to pay out as much as is necessary to incentivize you to be upfront and report it in private rather than starting a media fuss around it (you get fame and $0) or exploiting the bug yourself (you might get a jail term). Compared to these alternatives, $50K and a clean record isn't a bad deal.
- tptacek 6y agoWe probably need to stop having these threads, because they're repetitive, usually pretty ill-informed, and prevent us from having discussions about the vulnerabilities themselves. All we do is recapitulate the same tedious discussion about how bounty prices work. That's fine, but maybe we should only have those discussions on stories about bug bounties, not any story where a bounty makes an appearance. For the moment, rather than re-having this discussion, we can just note that bounty prices are what they are, and that no tech firm pays "existential" rates for new vulnerabilities (except, perhaps, Uber, where literally everyone involved in that story is now in the federal criminal court system).
- oska 6y agoOr you could just minimise this part of the discussion, which HN makes trivially easy to do.
- cactus2093 6y agoYet this person did the right thing anyway and reported the vulnerability responsibly. So seemingly the level of the bounty was reasonable enough that it worked as intended, and a much higher bounty would have been a waste of money for Tesla. I think the high likelihood of being caught and going to prison is also already a pretty big deterrent for people. Just think of all the challenges of actually pulling a hack like this off without being caught. For one thing, just the poking around that led to the discovery of the vulnerability has probably already logged a bunch of potentially suspicious activity linked to this guy's VIN number. So even if he sold it to someone else who did the hack he could probably be caught already. If he tried to orchestrate the hack himself, not only does he need to not be caught directly, but he'd also have to make a very large, very suspicious short trade right before the hack without it being traced back to him. Plus there's always a possibility that Tesla would have been able to lock him out quickly anyway or had some other kind of rate-limiting or other measures in place to prevent significant damage, or that even if he pulled off the hack perfectly the stock price wouldn't drop as much as expected.
- kypro 6y agoWhat would be the legality of sharing the hack publicly and allowing someone else to exploit it while shorting the stock? I also wonder when something becomes a "hack". Some systems are so insecure you can almost accidentally exploit them. In this case the API just required an ID for access. How would someone know if that was by design, or a mistake?
- cactus2093 6y ago> I also wonder when something becomes a "hack" As soon as you access something you're not supposed to. If a house is left unlocked and you walk in and take a look around, you're trespassing and it's a crime. And of course if you cause any damage or steal something, that's an even bigger crime. Except with hacking, the punishments can be even more severe relative to the actual crime committed, because almost nobody in the legal system will understand the details of what happened so they can make you seem as dangerous as they want. Just look at Aaron Swartz and countless other examples of the heavy charges that have been given out for very minor, borderline cases of "hacking".
- gorgoiler 6y agoWhen you sell to the bad guys you have to factor in the risk-price of 20 years in the US prison system. Bounty payers enjoy a hefty discount when they waive their right to prosecute.
- abnry 6y agoI get that it doesn't seem to make a lot of sense, but is there some market principle that can be used to explain why so many companies act as they do, and that it is in fact rational? Must it be a black swan fallacy?
- perl4ever 6y agoI don't know, but it makes me think of how armored truck drivers aren't (as far as I know) paid in proportion to the money they're responsible for.
- mmaunder 6y agoI’ll bet a few QA engineers would like to be paid based on how much a bug they reported would have cost the company if released into production.
- simple_bot 6y ago"would have" is pretty hard to measure. I do admire the idea to incentivize QA engineers on discovery of niche bugs.