I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
21–30 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#22I definitely do have respect to this guy named Santiago Lopez, while I'm literally twice as old as him.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#23I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Then again, I can imagine some teams would get utterly spammed with inane, wrong or non-bounty-able reports, which could be an issue.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#24Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#25I wish I had a knack for this type of work. That's quite a bit of cash. I do feel I am a competent software engineer, but understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities.
> understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities. No, but it does suggest that you're likely capable of learning security work. Just like your data structure and algorithm knowledge didn't come for free, nobody is born knowing how to find security problems. You need to work for it.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#26Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#27I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Google, for example, pays out bug bounties regularly, but their main security expense is wages/etc of security professionals, and that is probably in the neighborhood of a billion dollars a year.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#28I like the picture at the beginning of some CLI novice trying to git push his home directory
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#29I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
> Moussouris, who created the bug bounty at Microsoft, warned that if badly implemented such programmes could see talent leaving organisations in favour of pursuing bug bounties, and thus damage the talent pipeline.
I've seen her argue this on Twitter before - the argument IIRC is that bug bounties should always pay less than getting a job helping the blue team / writing secure code in the first place, otherwise the incentives are all wrong. It's great that you know about bugs, but it would be better not to have them. And, also, there's a bit of a prisoner's dilemma involved in that you don't want to let the rest of the industry drive up the expected payouts of bug bounties beyond the expected salaries of secure developers, but you also don't want to lose out on vulnerability reports either.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#30I definitely do have respect to this guy named Santiago Lopez, while I'm literally twice as old as him.
What does the second part of that sentence have to do with the first?
I expect there are languages where a word that translates neatly into "while" would be most appropriate, while actually meaning something more like "because". It's been a while since the last time I had to speak any foreign, but I remember stuff like this being very common - a large part of the reason I refuse to do it any more.