Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

21–30 of 174 posts

Re: Beg Bounties (2021)

#21

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

My incentives as an employee are similar. Far better to hide a problem than admit and fix it.

Covering up legit vulnerabilities is dangerous - it is a criminal offense. And no “my manager doesn’t like it” is not an effective defense (see uber ciso case)

Re: Beg Bounties (2021)

#22
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

I think the article made the argument that beg bounties drown out and train receivers to ignore better more fundamental reports as also being spam.

Re: Beg Bounties (2021)

#23
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[flagged]

Re: Beg Bounties (2021)

#24
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Meaningful or not, some companies and organizations don't understand the difference between a CVSS score of 2.0 and 10.0. Being in the cybersecurity industry myself, there is a wide gap of knowledge in the risk of vulnerabilities. Following a some-what standard way of reporting vulnerabilities is well documented. Begging for a bounty is not standard.

I also think that is perfectly fine to document the process in public so that everyone is informed.

Also, in regards to your comment on meaningful payouts, you could make the same argument for spam email. Occasionally it works for people in developing countries is, in my opinion, a terrible argument for allowing such behavior.

Re: Beg Bounties (2021)

#25
post #4

I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

> I don't think security researchers should work for free I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet. How are you supposed to find customers in the first place? Gotta start somewhere. Quality of the findings is orthogonal to asking for compensation. There will always be people asking for money without providing value. But I don’t think we should throw the b…

There are thousands of established bug bounty programs on the web. Ones in which companies actually solicit these messages. The reason these beg bounty hunters are sending unsolicited emails instead is because these programs explicitly descope all these stupid and irrelevant findings. If you want to establish your bonafides, this is a terrible way to go about it, especially given the legitimate alternatives.

Re: Beg Bounties (2021)

#26
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[flagged]

We don't appreciate allegations without links to evidence.

Re: Beg Bounties (2021)

#27
post #4

I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

> I don't think security researchers should work for free I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet. How are you supposed to find customers in the first place? Gotta start somewhere. Quality of the findings is orthogonal to asking for compensation. There will always be people asking for money without providing value. But I don’t think we should throw the b…

> Quality of the findings is orthogonal to asking for compensation

This is a terrible take. Orthogonal to having a reputation, sure. Orthogonal to having a particular certification or credential, absolutely. But quality is absolutely non-negotiable. If your work is bad and nobody asked you to do it then you’re not a professional, you’re a charity.

Re: Beg Bounties (2021)

#29
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[dead]

Re: Beg Bounties (2021)

#30
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[flagged]
Post reply on HN