Beg Bounties (2021)
11–20 of 174 posts
Re: Beg Bounties (2021)
#12Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have literally no choice but to care.
Re: Beg Bounties (2021)
#13I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
There's no problem with that. Anyone who does report anything is doing them a favor. Which they often repay with lawsuits.
Re: Beg Bounties (2021)
#14I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
> I don't think security researchers should work for free I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet. How are you supposed to find customers in the first place? Gotta start somewhere. Quality of the findings is orthogonal to asking for compensation. There will always be people asking for money without providing value. But I don’t think we should throw the b…
Hard, hard disagree. I'm glad this "beg bounty" behavior has a name for it, because it's so f'ing obnoxious, and so common, and all it really does is make it that much harder when a serious researcher does need to report a real vulnerability.
Let's not pretend there is some sort of gray line between what responsible disclosure looks like, and what bullshit beg bounty disclosure looks like - after all, Hunt does an excellent job showing the difference. He showed an email he wrote that identifies where he's from, and gives clear verifiable evidence of a serious breach. That is night-and-day different from the "I found something naughty on your website, will you pay me??" example from the beg bountier.
Point being, if you are a serious researcher and you have actually found a high-value vulnerability, there are proper ways to message that even when you feel compensation is warranted. These beg bounties never look like that because they all have the same achilles heel: the "vulnerability" is such an eye roller that they can't actually give evidence of it before asking for money precisely because they know it's so low value.
Re: Beg Bounties (2021)
#15I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…
Re: Beg Bounties (2021)
#16Re: Beg Bounties (2021)
#17Re: Beg Bounties (2021)
#18> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…