Earlier quoted context omitted.
Beware survivorship bias, I wonder what the average hourly rate of bug hunters is?
Trail of Bits has a nice summary[0] on that (they're discussing this[1] book). > As productive as the top 1% are, their earnings are equally depressing. The top seven participants in the Facebook data set averaged 0.87 bugs per month, earning an average yearly salary of $34,255; slightly less than what a pest control worker makes in Mississippi. --- [0] https://blog.trailofbits.com/2019/01/14/on-bounties-and-boff...…
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
171–178 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#172Earlier quoted context omitted.
The company posting the bounty. Third party verifies the bug. Why sarcastic?
Why doesn’t the third party publish the data themselves then?
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#173Earlier quoted context omitted.
Why doesn’t the third party publish the data themselves then?
The third party doesn't know about the vulnerability. Company C posts bug bounty B in contract. Researcher X discovers vulnerability. Validator Y confirms the vulnerability and X gets paid (1-f)B where f is validator fee.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#174I wonder if anyone has "cobra effect"ed the bug bounty world yet.. whereby they leave vulnerabilities in their code in order to obtain a bug bounty.
I have never once heard of a bug bounty being paid to a former employee let alone to the same person who wrote the code. It strikes me as something that is likely to do damage to ones reputation far out of proportion the few thousands of dollars one might hope to gain.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#175Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#176Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#177Earlier quoted context omitted.
Well no, they’d have to publish all reports which most companies don’t like doing because it makes them look very bad.
They wouldn't have to by the nature of how a Merkel tree works.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#178Earlier quoted context omitted.
They wouldn't have to by the nature of how a Merkel tree works.
Could you elaborate precisely how this scheme works to stop a company claiming reports are duplicates when they’re not?