Live data from Hacker News

Announcing the Windows Bounty Program

blogs.technet.microsoft.com

31–40 of 121 posts

Re: Announcing the Windows Bounty Program

#31
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

My understanding is that the grey market for exploits is way more lucrative than the bug bounty programs.

It is in the very specific case that:

(1) You are effective at finding the specific kinds of vulnerabilities that the grey market actually purchases. People have _very_ weird ideas about what the grey market wants. In reality, if your bug isn't a drive-by clientside in a popular client, it is unlikely that anyone wants to buy it.

(2) You are willing to get your hands dirty with shady purchasers. If you're talented, you can make good money in the grey market, or you can retain plausible deniability about what your work is being used for, but you can't do both of those things.

That first case is really the limiting factor. And remember, if you can reliably sell bugs to the grey market, that strongly implies you have lucrative options in the legitimate market. Bug bounties are not the most competitive alternative to the grey market!

Re: Announcing the Windows Bounty Program

#32
post #3

It's good to see the bounties increasing to the range you could get on the open market.

Every time you compare a bug bounty payout to the price of vulnerabilities on the open market, tptacek dies a little inside. Please, think about poor Thomas.

A lot of the high-dollar bugs Microsoft is soliciting here actually do have grey-market value.

Re: Announcing the Windows Bounty Program

#33
post #5

Its about time. I hope the incentives stay strong enough, and dont require hoops to jump through. otherwise the gray/blackmarkets could out-bid the bounty and cut the red tape to incentivise their own acquisition of the exploits in question.

Microsoft has been doing this for a long time; they're one of the pioneers of bounty programs.

Re: Announcing the Windows Bounty Program

#34

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Similar behaviors likely exists in OSS they are just called different things.

For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes.

In the case of OSS, the pool of resources is likely far bigger than with closed source software.

Re: Announcing the Windows Bounty Program

#35

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Maybe we should start some sort of foundation dedicated to providing the same incentive to find bugs in OSS

I'd imagine there are a lot of programmers who would be interested in supporting something like this

Re: Announcing the Windows Bounty Program

#36
post #22
post #14

With the increasing number and value of these bounty programs, how viable is a career in professional free lance security bug hunting?

It's doable, but if you're good enough to somewhat routinely find bounty-worthy bugs but not spooky good at it, it's not the most lucrative way to put bug-hunting skills to work.

I've noticed a spike recently in bug bounties going to people who using a combination of fuzzing and code analysis tools. It may be that we're moving to a point where bug-hunters' ability to use sophisticated tools will be what earns them the most money, rather than their ability to eyeball code and see the bugs.

Speaking just for myself: A few years ago I was saying "I should really set aside a few months to learn to use fuzzing tools"; now I'm saying "it's easier to just offer bounties and let someone else do the fuzzing for me".

Re: Announcing the Windows Bounty Program

#37
post #18

Earlier quoted context omitted.

The NSA will just have to pay more.

They have an almost unlimited budget, as far as we know.

Eh, I don't know anyone who when faced with managing billions of dollars has said, "OK, this is enough money".

Re: Announcing the Windows Bounty Program

#38
post #25

Earlier quoted context omitted.

The NSA will just have to pay more.

Which is actually sort of a worst-case scenario (not that I think this bounty is bad), because NSA's primary objective is in fact not to hack all your Windows machines, or even to hack anyone's Windows machine. NSA's primary objective is to secure more budget/headcount for NSA.

While that's true, the NSA's secondary objective is to be the only people who have an arsenal of exploits. Since they have the largest budget, having the price of exploits go up only helps this goal.

Re: Announcing the Windows Bounty Program

#39

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

OSS already had bug bounties a long time ago.

Re: Announcing the Windows Bounty Program

#40

I wonder what impact this will have on open source software (OSS). OSS can't afford to pay people to look for bugs and improve the overall software. But commercial companies can. I wonder if there will exist a date/time in the future where closed-source software, because of these bug bounties, will yield better (less buggy) software vs OSS.

Similar behaviors likely exists in OSS they are just called different things. For example, ACME Co uses open source project XYZ. Acme Co uses resources to make sure that XYZ is secure and bug free. Acme Co is then incentivized to contribute any changes they have found, because they would like to stay in sync with the master branch of XYZ so they can get any updates the community pushes. In the case of OSS, the pool o…

That's how the theory goes, but how often does this really happen though? See: OpenSSL
Post reply on HN