I get a lot of these but I have to admit I have a few favourites: 1. "I can download archives of your public mailing list from your website!" 2. "I can download tarsnap source code from your website!" 3. "I can telnet to port 25 on your mail server and send you an email!" I have the misfortune of being an early offerer of bug bounties -- and being unusual in offering bounties for all bugs, not just security bugs -- w…
Beg Bounties (2021)
31–40 of 174 posts
Re: Beg Bounties (2021)
#32I miss the old internet.
Re: Beg Bounties (2021)
#33Re: Beg Bounties (2021)
#34---
I help run a bug bounty program, we get a lot of submissions. Way too many of them are zero or low effort. The SPF meme one definitely resonates with me, we get it a whole lot.
Occasionally we will get someone who submits a half dozen variations of the same zero/low-effort report. When we turn around and deny them all (because there's no actual exploitable issue). There's a good chance they will then spend the next week replying to our emails asking for money because they put a lot of effort into it, and/or disputing our evaluation.
It's frustrating dealing with that, and I can certainly sympathise with wanting to reply to someone who's begging you for money with a "no, go away".
Perhaps Troy just needed to blow off some steam, but I think he'd be better having a saved reply in his email saying he doesn't pay bug bounties for personal projects/sites, and just send that.
I think it'd go over better than having what seems to be an overly aggressive post.
Re: Beg Bounties (2021)
#35I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
It’s one thing to go begging, it’s another when they feel entitled to some sort of payout. I never asked for their “services” - and in my limited experience, they lash out at you too, when you explain you’re not paying.
Re: Beg Bounties (2021)
#36Earlier quoted context omitted.
My incentives as an employee are similar. Far better to hide a problem than admit and fix it.
Covering up legit vulnerabilities is dangerous - it is a criminal offense. And no “my manager doesn’t like it” is not an effective defense (see uber ciso case)
It is incredibly hard to prove someone else knew about something you didn’t/don’t know about though.
Re: Beg Bounties (2021)
#37I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers.
Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" create.
----
Security is a never ending game of cat and mouse. If you can pay out a small amount to people who might, just might, catch something all of your other processes miss, it's a pretty easy decision.
Re: Beg Bounties (2021)
#38I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm.
2. The second reason is the approach that the beg bounty uses: that of fearmongering. If the beg-bountier disclosed the vuln and asked for the bounty that would be ok, but withholding the vuln until payment is assured is a scam.
3. How can one even properly valuate how much the vuln should be worth without knowing what it is / capable of doing?
Re: Beg Bounties (2021)
#39> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…
Re: Beg Bounties (2021)
#40I agree with everything in this post except this line. It's nice that the author doesn't need the money, but some people do. To me, the problem is not sharing after the answer is no, or not asking up front, not the fact someone is asking for money.