VirtualBox E1000 Guest-to-Host Escape
21–30 of 118 posts
Re: VirtualBox E1000 Guest-to-Host Escape
#22I enjoyed reading the author's motivation for posting as a 0day vs Bug bounty. https://github.com/MorteNoir1/virtualbox_e1000_0day#why
With regard to this, maybe there’s an opportunity for a market maker to step in. An “Uber for vulnerabilities”. Having said that, I do tend to think “slap a market on it” can often lead to perverse outcome.
Yeah. Just look at where we are today. But calling it "perverse outcome" is sugar coating it.
If it wasn't for profit being the king of all (and being the current common sense). Then we would've put more time into making software more secure.
Re: VirtualBox E1000 Guest-to-Host Escape
#23I enjoyed reading the author's motivation for posting as a 0day vs Bug bounty. https://github.com/MorteNoir1/virtualbox_e1000_0day#why
The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.
Re: VirtualBox E1000 Guest-to-Host Escape
#24huh. is the author a known “security researcher”? i agree more or less with his 3 points.
The engineers in charge quickly patching this up aren't the ones who came up with the bounty program. Making them pay for it seems like a pretty shitty move.
Re: VirtualBox E1000 Guest-to-Host Escape
#25Not to discount the work done here. Big high five. But I am surprised hundreds more of these bugs haven't found every week. It's Oracle. Their mission statement might as well be "we make security vulnerabilities and charge you a shitload" I would never trust any Oracle product in any form in production environment.
I hate Oracle and consider them among the most evil of companies out there. However, I don't think that's a very fair characterization of their mission statement.
Re: VirtualBox E1000 Guest-to-Host Escape
#26huh. is the author a known “security researcher”? i agree more or less with his 3 points.
By definition, he absolutely is a “security researcher”, and as of today, I would say he is also a known security researcher. This work is excellent.
Re: VirtualBox E1000 Guest-to-Host Escape
#27Earlier quoted context omitted.
With regard to this, maybe there’s an opportunity for a market maker to step in. An “Uber for vulnerabilities”. Having said that, I do tend to think “slap a market on it” can often lead to perverse outcome.
These already exist. There are darknet firms that independently verify that an exploit is real (staking their reputation that they won't take it and run once shown), and then open it to the market. The main trouble is that for it to fully work, you need to have the big corps bidding against black hats in this market. I can't see that happening. It'd have big corps dirtying their hands too openly. The other trouble is…
Is this really a thing? Who are these firms and what is their take?
Re: VirtualBox E1000 Guest-to-Host Escape
#28Earlier quoted context omitted.
The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.
You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?
Putting aside the ethics of publishing this 0day, I feel like it's important to critique the more nuanced point the author is making, rather than critique a caricature of it.
Re: VirtualBox E1000 Guest-to-Host Escape
#29Re: VirtualBox E1000 Guest-to-Host Escape
#30Earlier quoted context omitted.
The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.
You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?
I'm no security expert, but the feeling I get from other discussions is that big players have acted dishonestly with regards to proper compensation of bug bounties. It seems that sad state of affairs is being protested.