Live data from Hacker News

VirtualBox E1000 Guest-to-Host Escape

github.com

21–30 of 118 posts

Re: VirtualBox E1000 Guest-to-Host Escape

#22
post #2

I enjoyed reading the author's motivation for posting as a 0day vs Bug bounty. https://github.com/MorteNoir1/virtualbox_e1000_0day#why

With regard to this, maybe there’s an opportunity for a market maker to step in. An “Uber for vulnerabilities”. Having said that, I do tend to think “slap a market on it” can often lead to perverse outcome.

> Having said that, I do tend to think “slap a market on it” can often lead to perverse outcome.

Yeah. Just look at where we are today. But calling it "perverse outcome" is sugar coating it.

If it wasn't for profit being the king of all (and being the current common sense). Then we would've put more time into making software more secure.

Re: VirtualBox E1000 Guest-to-Host Escape

#23
post #3
post #2

I enjoyed reading the author's motivation for posting as a 0day vs Bug bounty. https://github.com/MorteNoir1/virtualbox_e1000_0day#why

The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.

You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?

Re: VirtualBox E1000 Guest-to-Host Escape

#24

huh. is the author a known “security researcher”? i agree more or less with his 3 points.

The author here just blindly assumes a lot of things about VirtualBox's bug bounty program. Many, like Google, put a very strict limit, and they will release the details when that time is over. I think it's more respectful to at least give them a chance, rather than throwing a hot shit on their lap and making hundreds of people's life a living hell for a week.

The engineers in charge quickly patching this up aren't the ones who came up with the bounty program. Making them pay for it seems like a pretty shitty move.

Re: VirtualBox E1000 Guest-to-Host Escape

#25
post #5

Not to discount the work done here. Big high five. But I am surprised hundreds more of these bugs haven't found every week. It's Oracle. Their mission statement might as well be "we make security vulnerabilities and charge you a shitload" I would never trust any Oracle product in any form in production environment.

I hate Oracle and consider them among the most evil of companies out there. However, I don't think that's a very fair characterization of their mission statement.

It's called exaggerated sarcasm. But it is absolutely fair of the products they build. They are complete garbage. It's like Adobe and Oracle have a side bet on who can introduce the most vulnerabilities. That is how terrible of a track record they have. I will be extreme here and say all of their products, especially Java, flash, and acrobat should outright be banned from a corporate network. It should be considered a liability and insurance companies should actually build it into their models.

Re: VirtualBox E1000 Guest-to-Host Escape

#26

huh. is the author a known “security researcher”? i agree more or less with his 3 points.

> is the author a known “security researcher”?

By definition, he absolutely is a “security researcher”, and as of today, I would say he is also a known security researcher. This work is excellent.

Re: VirtualBox E1000 Guest-to-Host Escape

#27
post #19

Earlier quoted context omitted.

With regard to this, maybe there’s an opportunity for a market maker to step in. An “Uber for vulnerabilities”. Having said that, I do tend to think “slap a market on it” can often lead to perverse outcome.

These already exist. There are darknet firms that independently verify that an exploit is real (staking their reputation that they won't take it and run once shown), and then open it to the market. The main trouble is that for it to fully work, you need to have the big corps bidding against black hats in this market. I can't see that happening. It'd have big corps dirtying their hands too openly. The other trouble is…

> There are darknet firms that independently verify that an exploit is real (staking their reputation that they won't take it and run once shown), and then open it to the market.

Is this really a thing? Who are these firms and what is their take?

Re: VirtualBox E1000 Guest-to-Host Escape

#28
post #23
post #3

Earlier quoted context omitted.

The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.

You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?

Even the the author publishing this 0day clearly believes there is a place for that; their protest is calling attention to that this time-to-fix period is, they believe, in practice abused to be a great deal longer than it should be.

Putting aside the ethics of publishing this 0day, I feel like it's important to critique the more nuanced point the author is making, rather than critique a caricature of it.

Re: VirtualBox E1000 Guest-to-Host Escape

#30
post #23
post #3

Earlier quoted context omitted.

The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.

You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?

The security of the product is the responsibility of the vendors. If they want to control how exploits are handled, then they should compensate security researchers for that service, just like anything else. The poster of the exploit outlined some reasonable steps to that end.

I'm no security expert, but the feeling I get from other discussions is that big players have acted dishonestly with regards to proper compensation of bug bounties. It seems that sad state of affairs is being protested.

Post reply on HN