Live data from Hacker News

Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

blogs.zdnet.com

31–40 of 40 posts

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#31
post #22

Earlier quoted context omitted.

You're missing mine, I'm afraid: I've made no claim about anyone having to do anything. Indeed, if I was in Charlie's shoes, I wouldn't be working on spec. Let me put it another way. There are two markets for exploits: the legitimate one, and the criminal one. Charlie is participating in the legitimate one. He's going to get paid what the sole counterparty wants to pay him. We can argue about what the counterparty sh…

Apple pays zero for vulnerabilities, friend. They get them for free. Charlie Miller is saying he's going to stop doing that. Can you blame him?

No, but that's not his point. (I think) he says there's something wrong with him basing his price on what criminals would pay (regardless of whether he would actually sell it to criminals).

I don't know. If he can't ask whatever he wants for it and Apple can't pay whatever they want for it, there's no simple solution.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#33

Miller says that the bugs have a market value beyond $5000 -- indeed, he claims that an IE8 exploit has a "market value" of over $50k. But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits. The idea of announ…

Conversely, he is basically stating that third parties like himself are working as exploit-oriented QA Engineers for the software they are exploiting. If full-time QA people get paid for it, why shouldn't he?

Please enlighten me... I don't see any mention of selling the exploit to criminals, just mention that they could get a lot more money than is offered. Is there just a subtext I'm missing with those statements?

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#35
post #4

Earlier quoted context omitted.

I don't like vulnerability markets. It seems to me like a flaw is more valuable before it's patched, and more valuable before it's disclosed. Like plutonium, anything done to make it safer makes it less valuable. If you're going to pay top dollar for something like that, you bother me. But I have two problems with where you're going. First, finding a bug in your own time and not telling Apple about it unless they pay…

I have no problem with you, Charlie, or anyone else being paid top dollar for his or her work, particularly in an important field like security research. Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results. But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)." He was saying "the market value of this is $Z., and it's…

One's billing rate is determined by the market value of one's services. For instance, I may be able to charge $300/hr for general security consulting to a software vendor, but I cannot expect $300/hr for flipping burgers at a fast food place. It's contextual; there's not one price assigned to one person. If Charlie finds an exploit that could potentially cause a lot of damage, it's perfectly reasonable to expect the vendor to pay a value proportionate to that exploit's potential liability, damages, etc.

Hourly rates are determined based on market rates, and vary from job to job.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#36
post #2

I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them. You have to remind them that if Apple had 90% of the business computer market that wouldn't be true anymore. Apple's best security is the fact that far fewer people buy their products than they do Microsoft's.

I've always thought it was funny when someone would try to sell me on macs by saying there are less bugs and viruses on them.

Why do you find that funny? You said yourself that it's true.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#37
post #22

Earlier quoted context omitted.

Apple pays zero for vulnerabilities, friend. They get them for free. Charlie Miller is saying he's going to stop doing that. Can you blame him?

No, but that's not his point. (I think) he says there's something wrong with him basing his price on what criminals would pay (regardless of whether he would actually sell it to criminals). I don't know. If he can't ask whatever he wants for it and Apple can't pay whatever they want for it, there's no simple solution.

I think we've latched too much on the pricing specifics. I don't think Miller cares; I think he's just trying to illustrate that there is in fact a market value for this work, and that vendors and customers appear to expect to get the work product for free.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#38
post #24

With all of the talk about morals and ethics, these are the 2 questions I ask myself whenever making a tough decision: 1) Am I making the world a better place or a worse place? 2) Am I providing value to the people I care about? I can't speak for Charlie Miller. But, my answer would be no for both questions. If I were in the same position as him I would feel like a big piece of fucking shit every single morning when…

I think Charlie Miller wakes up thinking, "you're the weak, and I'm the tyranny of evil men, but I'm trying real hard to be the shepherd". Then he goes off getting in all kinds of adventures and shit, like Kane from Kung Fu.

That's just what I think.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#39
post #24

With all of the talk about morals and ethics, these are the 2 questions I ask myself whenever making a tough decision: 1) Am I making the world a better place or a worse place? 2) Am I providing value to the people I care about? I can't speak for Charlie Miller. But, my answer would be no for both questions. If I were in the same position as him I would feel like a big piece of fucking shit every single morning when…

In his case: 3) Can I feed myself? By finding Safari bugs, he does make the world a better place. But he can't live like that, so he has to stop looking for Safari bugs. Since Safari undoubtedly has bugs, this means someone else is going to find them. That someone else could be a criminal, but you can't blame the guy for not wanting to do work that doesn't pay. In the end, Safari's security is Apple's problem, not Ch…

I understand that he has to eat. But making enough money to eat is not that hard.

And it isn't just Apple's problem (or just Microsoft or just Google). It's my problem, too. It's my mom's problem, too.

Think about the case where a user's data is compromised.

With great power comes great responsibility, and whatever other cheesey statement you want to make. I would feel personally responsible if I found an exploit and later that exploit was used to compromise someone's bank account or private correspondence.

My conscience is more important than my stomach. I can find other ways to eat.

Re: Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."

#40
post #39

Earlier quoted context omitted.

In his case: 3) Can I feed myself? By finding Safari bugs, he does make the world a better place. But he can't live like that, so he has to stop looking for Safari bugs. Since Safari undoubtedly has bugs, this means someone else is going to find them. That someone else could be a criminal, but you can't blame the guy for not wanting to do work that doesn't pay. In the end, Safari's security is Apple's problem, not Ch…

I understand that he has to eat. But making enough money to eat is not that hard. And it isn't just Apple's problem (or just Microsoft or just Google). It's my problem, too. It's my mom's problem, too. Think about the case where a user's data is compromised. With great power comes great responsibility, and whatever other cheesey statement you want to make. I would feel personally responsible if I found an exploit and…

I would feel personally responsible if I found an exploit and later that exploit was used to compromise someone's bank account or private correspondence.

Which is why he's not even looking for exploits anymore. He is leaving it to Apple's QA team, since it is really their job.

Post reply on HN