6 ms·
It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right
by Debug_Overload 5y ago
It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.
- _wldu 5y agoI do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.
- nostoc 5y agoHow about selling legally to a state actor for 100k ? Bug bounties need to be higher, because the black market is not the only alternative.
- deleted 5y ago[deleted]
- Debug_Overload 5y agoThe legal/ethical question is important, but I was just stressing OP's point about the disparity between bug bounties and what the actual exploits are worth. IANAL, but for the specific cases I mentioned (nation states and vendors who work with them), I think the legal aspect would be very different from selling it to regular black market cybercriminals (I used the generic "black market" in the first part of the original comment but I was mostly talking about those two cases).
- pixl97 5y agoAssuming you live in a place where you can get a high paying job and/or leave the country to get one. Taking a US centric view on this is a great way to ensure nation states have compromised your security.
- tw04 5y agoSo if you take a non-US centric view and assume there's no legal repercussions and the person finding the bug has no moral compass, what exactly would prevent them from sharing the bug with a nation state and you at the same time? Sure they may get slightly less from the nation state because the bug would have a shorter shelf life, but it would still make it into the wild long before every system could be patched. Paying more money isn't going to make someone do the right thing.
- darkwater 5y ago> but isn't selling bugs on the black market illegal? Noob question: is there any specific law that punishes describing how to get into a software/electronic system but not actually doing it? Something that is just not purely US-centric.
- ensignavenger 5y agoHere is UK specific answer, and as they point out, if you sell to some one knowing they are going to commit a crime with it, you can be considered an accomplice in many jurisdictions. https://law.stackexchange.com/questions/11552/is-it-illegal-to-create-and-sell-a-exploit-of-a-zero-day-vulnerability https://law.stackexchange.com/questions/11552/is-it-illegal-...
- kube-system 5y agoSounds like a market opportunity for middlemen in other jurisdictions.
- msoad 5y agoBitcoin solves this!
- voakbasda 5y agoOr, sell it on the black market, and use that connection to get a better job on the black market. Reputation is just as important for criminals, and crime pays better (until you get caught).
- rafale 5y agoIt's probably illegal in many jurisdictions, no? Not to mention unethical. You are not just harming Microsoft here in this instance, but potentially millions of people.
- gopher_space 5y agoIf we’re looking at ethics, what’s the morality of Microsoft not paying market rate for exploits.
- adolph 5y agoBug bounties probably act as a price discovery mechanism on the part of bug finders. They should also have a negative price premium bye to decreased risk.
- anonymousDan 5y agoHow does the black market price compare to the 'nation state' price?
- saruken 5y agox = y. Where do you think nation states purchase their tools?