Live data from Hacker News

The Chrome VRP Panel has decided to award $250k for this report

issues.chromium.org

201–210 of 292 posts

Re: The Chrome VRP Panel has decided to award $250k for this report

#201
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

Why not collect from both of the sources? First collect with your black hat and then with your white.

First, it's not "black market" vs. "non-black market"; most remunerative sales outside of bounty programs are grey-market --- mostly lawful, but all under the table, largely because they're to agencies that are protective of their sources and methods.

The mechanism grey-market buyers have to protect their interests against over-selling bugs is tranched payments. Sellers make much of their returns from bugs on the back end through "maintenance agreements", which both require the seller to keep e.g. the offsets in their exploits current and reliable against new patch levels of the target, and also serve to cut off payment once the vendor kills the bug.

If you sell to both sides, you quickly kill the back end business from the grey market buyers. If you sell to too many or too sketchy grey market buyers, the bug leaks --- vendors see it exploited "in the wild", capture samples, kill the bug; same outcome: tranched payments stop.

This is one reason it can make sense to take a bounty payment that is substantially smaller than what a bug might be worth on the market: you get certainty of payment. Another reason is that the bounty program will only want POC code (perhaps proof of reliability in addition to just exploitability), while the market will want a complete enablement package, which is a lot of work.

Re: The Chrome VRP Panel has decided to award $250k for this report

#202

Earlier quoted context omitted.

Selling something to the black market doesn't magically make it tax free. It's almost the opposite. The money is going to show up in your auditable accounts sooner or later, so it's best to pay tax on it, but you'll also have to come up with a fake but auditable story of where it came from, meaning you'll have to engage the services of professional money launderers. They will also take a cut. So, it's like paying tax…

Up to here you weren't committing any crimes. > but you'll also have to come up with a fake but auditable story of where it came from And now you did.

Dubious; seems like if you know you're selling exploits to criminals you could be done on a conspiracy charge.

Re: The Chrome VRP Panel has decided to award $250k for this report

#203

Kind of life changing money, good to see such rewards

the first time I got a bonus that big, $240k, I thought it would be life changing. the gov took $100k in taxes. I paid off my car $20k. then when I really thought about it there wasn’t much I could do. It was not a down payment on a house in LA/SF/NYC. it was not enough to start a company and hire people. If I’d changed my life style to be like a college student and live with roommates then it might have given me 2-3…

> it was not enough to start a company and hire people.

It is in Taiwan, Vietnam, Indonesia, Cambodia...

Re: The Chrome VRP Panel has decided to award $250k for this report

#204
post #31

Sandbox escape with high-quality report in Chrome: $250k [1], yet Mozilla will offer you $20k [2] for that... [1] https://bughunters.google.com/about/rules/chrome-friends/574... [2] https://www.mozilla.org/en-US/security/client-bug-bounty/

The grey market also offers much less for Firefox vulnerabilities, for reasons of both supply and of demand.

Re: The Chrome VRP Panel has decided to award $250k for this report

#205

Earlier quoted context omitted.

Chrome has 15-20 times the users that firefox in the blackmarket the bug would sell for similar ratio. Safari might go for more as it has more rich and tech security illiterate users.

disagree. more marketshare does not mean juicier targets, which, in this case, would be tor users. in addition, you don't buy an exploit to use it en masse, that would get it burned really quickly

More market share does in fact impact availability of targets, but in the case of Firefox it's just as much a factor that there are more bugs and exploits floating around.

Re: The Chrome VRP Panel has decided to award $250k for this report

#206
post #106
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

> pretty sure it he could have gotten more tax free on the black market. How? I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to. I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worrie…

Mostly the best market is intelligence agency vendors. As a US citizen, I would only be comfortable selling to US contractors. There are a bunch; if you go to conferences you probably meet the people there (look at the sponsors...).

It won't be tax-free, though; you'd probably get a 1099, but if you're smart could set it up as corp to corp and deduct a bunch of other expenses from it. Part of the sale is signing a bunch of NDAs, etc so you can't then release it to others.

Re: The Chrome VRP Panel has decided to award $250k for this report

#207
post #14

He had a pretty reliable exploit on the most used browser, pretty sure it he could have gotten more tax free on the black market. Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...

Everybody here is coldly evaluating the financial profit comparison. How about being a decent human being, and not enabling hundreds of criminals to hurt millions of people because your net income is potentially better?

Re: The Chrome VRP Panel has decided to award $250k for this report

#208
post #4

How does one start acquiring skills like these?

By reading and keeping up with the published work in browser exploit development, replicating it yourself, and then finding you have a knack for spotting vulnerabilities in C++ code.

Re: The Chrome VRP Panel has decided to award $250k for this report

#209

Are there people who work full time from income on bug bounties?

To add to the sibling comment, there are also many different ways of making a living doing this stuff:

* You can find killer clientside bugs where the bounty will cover a year's worth of compensation (bear in mind you'll get maybe 1.5 of these payouts a year on your own if you're good but replacement-level)

* You can find these kinds of bugs and work with brokers to sell them to grey-market buyers along with enablement/implants --- more development work, a little more market risk.

* You can find smaller, easier bugs (serverside, web bugs) that get nothing resembling these kinds of payouts but are much easier to find, and make good money on volume. This is a much more common way of making a living on bounty payments.

Re: The Chrome VRP Panel has decided to award $250k for this report

#210
post #116

I wonder how much the black market would pay for an exploit like that - anyone know?

Grey market, not black. It's been several months since I've talked to anyone in the space but full-chain reliable quiet Chrome exploit packages were high six figures, with discussions starting about bugs reaching 7 figures imminently, and the people I talked to might have been talking that down (or talking it up).

Again, remember that grey market payouts are tranched, so you could get 3x more than Google would pay, or you could get 0.5x, and for much more work.

Post reply on HN