Live data from Hacker News

Teen Becomes First Hacker to Earn $1M Through Bug Bounties

digit.fyi

21–30 of 178 posts

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#21
post #13

I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?

Believe me- these programs don’t even scratch the surface of the amount of security vulns companies have hiding in their code base. Having a good bug bounty program, internal product security team and a continuous third party audit process are all parts of having a good security posture.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#23
post #13

I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?

Only the biggest companies can really afford to have the scale and skill available from the vast range of people working for bug bounty money - and as one of the other posters mentioned - you still have to have internal staff to confirm and patch the bugs. It's almost like the best side of outsourcing, where the outsourced talent is driven to do their best work because otherwise they'll never get paid.

Then again, I can imagine some teams would get utterly spammed with inane, wrong or non-bounty-able reports, which could be an issue.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#25
post #18

I wish I had a knack for this type of work. That's quite a bit of cash. I do feel I am a competent software engineer, but understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities.

> understanding data structures and algorithms doesn't necessarily correlate to one's ability to identify security vulnerabilities. No, but it does suggest that you're likely capable of learning security work. Just like your data structure and algorithm knowledge didn't come for free, nobody is born knowing how to find security problems. You need to work for it.

What's a way to learn security work? Genuinely curious.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#26
post #22
post #8

I definitely do have respect to this guy named Santiago Lopez, while I'm literally twice as old as him.

What does the second part of that sentence have to do with the first?

He had half the time to learn than many older people that also live off bugs bounties?

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#27
post #13

I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?

No serious company makes that choice, which misunderstands what companies use bug bounties for.

Google, for example, pays out bug bounties regularly, but their main security expense is wages/etc of security professionals, and that is probably in the neighborhood of a billion dollars a year.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#29
post #13

I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?

This is similar to Katie Moussouris's argument from the article:

> Moussouris, who created the bug bounty at Microsoft, warned that if badly implemented such programmes could see talent leaving organisations in favour of pursuing bug bounties, and thus damage the talent pipeline.

I've seen her argue this on Twitter before - the argument IIRC is that bug bounties should always pay less than getting a job helping the blue team / writing secure code in the first place, otherwise the incentives are all wrong. It's great that you know about bugs, but it would be better not to have them. And, also, there's a bit of a prisoner's dilemma involved in that you don't want to let the rest of the industry drive up the expected payouts of bug bounties beyond the expected salaries of secure developers, but you also don't want to lose out on vulnerability reports either.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#30
post #22
post #8

I definitely do have respect to this guy named Santiago Lopez, while I'm literally twice as old as him.

What does the second part of that sentence have to do with the first?

Mx Armamut is perhaps not a native English speaker. Let us suppose that the first part of the sentence is a statement, and the second part is the rationale - then, by way of conjunction, a native speaker would probably choose something like "because", or similar.

I expect there are languages where a word that translates neatly into "while" would be most appropriate, while actually meaning something more like "because". It's been a while since the last time I had to speak any foreign, but I remember stuff like this being very common - a large part of the reason I refuse to do it any more.

Post reply on HN