6 ms·
The bounty could be very high. Last year one bug’s reporter was rewarded $250k. https://news.ycombinator.com/item?id=44861106 https://news.ycombinator.com/item?
by naeioi 7mo ago
The bounty could be very high. Last year one bug’s reporter was rewarded $250k. https://news.ycombinator.com/item?id=44861106 https://news.ycombinator.com/item?id=44861106
- duozerk 7mo agoMaybe google is an exception (but then again, maybe that payout was part marketing to draw more researchers).
- throwaway150 7mo agoSo is there anything that would actually satisfy crowd here? Offer $25K and it is "How dare a trillion dollar company pay so little?" Offer $250K and it is "Hmm. Exception! Must be marketing!" What precisely is an acceptable number?
- hsbauauvhabzb 7mo agoAn increase in the average bug payout. Bounty programs pay low on average.
- idiotsecant 7mo agoA number better than what the exploit could be sold for on the black market
- i_am_jl 7mo agoI don't believe those numbers will ever come close to converging, let alone bounty prices surpassing black market prices. It seems like these vulnerabilities will always be more valuable to people who can guarantee that their use will generate a return than to people who will use them to prevent a theoretical loss. Beyond that, selling zero-days is a seller's market where sellers can set prices and court many buyers, but bug bounties are a buyer's market where there is only one buyer and pricing is opaque and dictated by the buyer. So why would anyone ever take a bounty instead of selling on the black market? Risk! You might get arrested or scammed selling an exploit on the black market, black market buyers know that, so they price it in to offers.
- seanw444 7mo agoNot sure why you're getting downvoted. It's the unfortunate reality.
- gbalduzzi 7mo ago> So why would anyone ever take a bounty instead of selling on the black market? Risk! I like to believe there are also ethics involved in most cases
- idiotsecant 7mo agoSystems that rely on ethical behaviour to function generally dont last long
- gbalduzzi 7mo agoThat is why I said "also", it should not be the only factor. The conversation was moving between two possibilities only: either collect bug bounties or sell on the black market. I believe most (again: most, not all) security researchers collecting bug bounties right now would not start selling on the black market in case bounties disappeared. They would change their focus to something else to sustain themselves
- bri3d 7mo agoEven though I agree with the conclusion with respect to pricing, I don't think this comment is generally accurate. Most* valuable exploits can be sold on the gray market - not via some bootleg forum with cryptocurrency scammers or in a shadowy back alley for a briefcase full of cash, but for a simple, taxed, legal consulting fee to a forensics or spyware vendor or a government agency in a vendor shaped trenchcoat, just like any other software consulting income. The risk isn't arrest or scam, it's investment and time-value risk. Getting a bug bounty only requires (generally) that a bug can pass for real; get a crash dump with your magic value in a good looking place, submit, and you're done. Selling an exploit chain on the gray market generally requires that the exploit chain be reliable, useful, and difficult to detect. This is orders of magnitude more difficult and is extremely high-risk work not because of some "shady" reason, but because there's a nonzero chance that the bug doesn't actually become useful or the vendor patches it before payout. The things you see people make $500k for on the gray market and the things you see people make $20k for in a bounty program are completely different deliverables even if the root cause / CVE turns out to be the same. *: For some definition of most, obviously there is an extant "true" crappy cryptocurrency forum black market for exploits but it's not very lucrative or high-skill compared to the "gray market;" these places are a dumping ground for exploits which are useful only for crime and/or for people who have difficulty doing even mildly legitimate business (widely sanctioned, off the grid due to personal history, etc etc.) I see that someone linked an old tptacek comment about this topic which per the usual explains things more eloquently, so I'll link it again here too: https://news.ycombinator.com/item?id=43025038 https://news.ycombinator.com/item?id=43025038
- DiggyJohnson 7mo agoYou can work your day job and make $20-500k/yr or pursue drug dealing and make $5-5000k/yr. I don’t think that’s actually a compelling argument for the latter even if the opportunity cost is better.
- hsbauauvhabzb 7mo agoDrugs are illegal, exploits are not illegal. Selling them to someone associated with illegal activity is probably illegal, but there is a legitimate fully legal exploit market with buyers like intelligence agencies, and an illegal market with buyers that run oppressive regimes and commit genocide.
- cwillu 7mo agoOne is a lament that the industry average is so low, and the other is… a lament that the industry average is so low. What's the problem?