Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

1–10 of 174 posts

Re: Beg Bounties (2021)

#3
I run a domain for our community association. I had an “ethical hacker” discover that I had neglected to set up spf records for that domain. I had to deal with him sending a bunch of nasty emails to our other board members after I refused to pay him for his “discovery”. (Actually I offered him a cut of my salary as a board member, which at $0, came out to be… less than he was hoping for)

I’ll definitely keep a link to this for next time this happens.

Re: Beg Bounties (2021)

#4
I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

Re: Beg Bounties (2021)

#5
I get a lot of these but I have to admit I have a few favourites:

1. "I can download archives of your public mailing list from your website!"

2. "I can download tarsnap source code from your website!"

3. "I can telnet to port 25 on your mail server and send you an email!"

I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- which means that Tarsnap shows up pretty quickly when bounty beggars start looking for targets.

Re: Beg Bounties (2021)

#7
post #5

I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…

my favourite is "your docker registry is publicly accessible"

yeah man, i know that. i made it public.

i eventually had to take it down, just to stop the flood of beg bounties telling me about it.

Re: Beg Bounties (2021)

#8
post #4

I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

> I don't think security researchers should work for free

I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet.

How are you supposed to find customers in the first place? Gotta start somewhere.

Quality of the findings is orthogonal to asking for compensation.

There will always be people asking for money without providing value. But I don’t think we should throw the baby out with the bath water because of it.

Re: Beg Bounties (2021)

#9
post #4

I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

nobody's asking security researchers to work for free. the people asking security researchers to work are paying them for that work.

if you're doing un-asked-for work, you can't expect to get paid

Re: Beg Bounties (2021)

#10
post #7
post #5

I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…

my favourite is "your docker registry is publicly accessible" yeah man, i know that. i made it public. i eventually had to take it down, just to stop the flood of beg bounties telling me about it.

Oh yeah... I don't run a docker registry, but Amazon feels it necessary to remind me periodically that FreeBSD releases are public AMIs, and their filesystem images are public, and I have publicly readable data in S3 (which is mandatory in order to create an AWS Marketplace listing).

So much "yes I know it's supposed to be that way".

Post reply on HN