Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

131–140 of 174 posts

Re: Beg Bounties (2021)

#131
post #100

Earlier quoted context omitted.

> 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. I have a hard time sympathizing with this. Our project gets a handful of these "beg bounty" things a year; usually they're repeats -- SPF and "clickjacking" are common ones, but we also get o…

at $DAYJOB we get multiple beg bounties a week, it's a massive waste of everyone's time and it's literally never been a real issue.

At my previous job it was about 10 per days after we started having an official process. I gather that people would just Google us.

It was very easy to filter the bad reports, though. About 10 minutes of work per day, since most were repeated issues. We had a default "reply" email with information.

The issue however was those people would get extremely angry when their security issue was deemed invalid, so we started just blocking recipients that would threat us or demand payment for invalid issues. Some would stalk me and other developers in LinkedIn and would demand immediate payment. Of course that only happened about 4 times.

Another issue was caused when some invalid issues would get SO MANY REPORTS from automated scanners, that we would actually decide to change to prevent the reports. In some of those we actually paid and credited the first person, but then the other 30 would demand payment too and accuse us of lying.

Huge shitshow.

Re: Beg Bounties (2021)

#132
post #35
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

“But I already washed your window while sitting at the stop light” It’s one thing to go begging, it’s another when they feel entitled to some sort of payout. I never asked for their “services” - and in my limited experience, they lash out at you too, when you explain you’re not paying.

And? You're not accomplishing anything by pushing back on them.

Re: Beg Bounties (2021)

#133
post #61
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Bad behaviour should not be tolerated just because it comes from the third world

You don't have the option of tolerating or not tolerating it. You're seeing one of these people, but there are a thousand more behind them, and they don't care what you tolerate or don't; it's a numbers game to them.

Re: Beg Bounties (2021)

#134
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Another thought on this, coming from someone whose phone number has ended up on some large number of scammer lists, to the point where I would have about 1000 scam calls per month around open enrollment time (think targeting seniors): You are advocating for feeding the troll. The troll will not be satisfied with table scraps. Larger trolls will see the opportunity and scale up. I get what you’re saying. I don’t have…

Whoah, I am definitely mot telling you to pay these people.

Re: Beg Bounties (2021)

#135

Earlier quoted context omitted.

You really need to think carefully about whether you want to expose an S3 bucket publicly. There are probably some valid reasons out there, but if you're not an AWS expert, it's likely that you're making a mistake. If I find out the name of your bucket I could cost you thousands of dollars of egress tonight before you wake up in the morning. It's _especially_ likely to happen to hosters of open source binaries becaus…

Hosting a file on a url anyone can access from anywhere is the whole point…

Public S3 buckets are not a good choice for that because of the "anyone could bankrupt you" reason above. That is generally NOT the use case for S3, and it's the reason why private is the default and there are alerts for public buckets. For public access, within AWS, you'd want to put CloudFront in front of the bucket and only allow external users to access CloudFront. However, there's a better option...

Outside of AWS, Cloudflare has a service called R2 which is just like S3, except you DON'T pay egress! It's the same thing, but without the "anyone could bankrupt you" aspect. You pay for the storage but you don't pay per download. I highly recommend this for hosting open source binaries. You can still keep a copy in a private S3 bucket for safe keeping if you don't trust Cloudflare long-term.

Re: Beg Bounties (2021)

#136
post #81

Earlier quoted context omitted.

I run a bug bounty program and I don't mind report for small issues. It's true that most report from "beg bounty" hunters are noise, but we've acted on some reports a few time. One time, in particular, a researcher broke something which alerted us to a serious issue, while not understanding themselves what they had found, we still paid a fair bounty on the finding since we would not have found the issue without the a…

In my experience paying out once to a bug hunter resulted in an avalanche of useless "beg hunter" reports in the following weeks. Understandably security researchers brag about their finds on their resume but that has the side effect that other guys apparently crawl those and start targeting you. I'm not saying this is good or bad, but just a warning that you should be prepared to read a lot more reports once you sta…

The flip side is we've had some very serious, legit security researchers test our application as a result of our reputation for paying out bounties.

Re: Beg Bounties (2021)

#138
post #35

Earlier quoted context omitted.

“But I already washed your window while sitting at the stop light” It’s one thing to go begging, it’s another when they feel entitled to some sort of payout. I never asked for their “services” - and in my limited experience, they lash out at you too, when you explain you’re not paying.

And? You're not accomplishing anything by pushing back on them.

I simply said “thank you for the report but I’m not paying”. The “researcher” responded by spamming the rest of the board and the property manager for the community with hundreds of messages filled with expletives.

I didn’t write a blog or do anything to “trigger” anyone. Heck the only reason I replied is because they kept emailing the other non tech people in an attempt to extort money out of them.

I don’t find their behavior excusable and have no problem calling them out.

Re: Beg Bounties (2021)

#139

Earlier quoted context omitted.

Force isn’t even required in some places, apparently! This page expands on the differences in a few countries: https://en.m.wikipedia.org/wiki/Burglary Canada > Breaking and entering is defined as breaking into a place with intent to commit another indictable offence England & Wales > A person is guilty of burglary if they enter any building or part of a building as a trespasser with intent to steal, inflict grievous…

It seems that in many places intent to commit another crime is a key.

But trespassing is (presumably in those jurisdictions) a crime.

Re: Beg Bounties (2021)

#140

Earlier quoted context omitted.

Oh yeah... I don't run a docker registry, but Amazon feels it necessary to remind me periodically that FreeBSD releases are public AMIs, and their filesystem images are public, and I have publicly readable data in S3 (which is mandatory in order to create an AWS Marketplace listing). So much "yes I know it's supposed to be that way".

It’s so bizarre that every time I upload something to S3 I have to jump through a hoop to make it publicly readable and Amazon displays a massive warning sign. Like the only thing I use S3 for is hosting open source software binaries. Maybe there’s a use case for restricting access, but I don’t even know what that would be.

Given the amount of data breaches that have happened from S3 buckets being accidentally publicly accessible, it definitely makes sense to me.
Post reply on HN