Facebook rewarded a 10-year-old for finding Instagram security flaw
1–10 of 90 posts
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#2Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#3It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me.
Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#4It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#5Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#6It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
The same reasons people don't steal from shops or commit other crimes:
1. Morals
2. Risk of getting caught and subsequent punishment
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#7It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#8Earlier quoted context omitted.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
>> "Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me." The same reasons people don't steal from shops or commit other crimes: 1. Morals 2. Risk of getting caught and subsequent punishment
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#9Earlier quoted context omitted.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
He's 10. Who is he going to sell this to? $10,000 is probably a gigantic amount of money to him.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#10It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff.
From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way to monetize the exploit, or some other motivation. And you really have no way to know how long your exploit will remain functional.
(Or, you know, people could be basically good.)