Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

1–10 of 246 posts

Re: Zoom zero-day discovery

#3
Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

Re: Zoom zero-day discovery

#4
What percentage of these kind of exploits does hn think are found by these kind of white hat exercises and what percentage are sitting out there in an intelligence service or private entity's 0-day database? I have always been curious.

Re: Zoom zero-day discovery

#5
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.

Re: Zoom zero-day discovery

#6
“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers.

These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerability across the entire app, or better yet, the whole industry via a research paper.

Re: Zoom zero-day discovery

#7

What percentage of these kind of exploits does hn think are found by these kind of white hat exercises and what percentage are sitting out there in an intelligence service or private entity's 0-day database? I have always been curious.

A wild guess is 3:1 (3 working 0-day exploits in existence for every 1 found with exercises like this). My reasoning is because every time there is a very high-priced bounty on an exploit, it seems to get discovered and pay out. So if governments and blackhats have people hunting full time for these exploits, you better bet they are finding them too.

Re: Zoom zero-day discovery

#8
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

“ does not affect the browser version” at least they weren’t able to combine this with a browser security flaw to escape the JS sandbox.

Re: Zoom zero-day discovery

#9
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

A lot of the time we see someone getting like 10k. Also 200k is over 3 years my wage so I have to say no it does not seem low to myself but to others perhaps that is a low number but I value things differently. I hold high morals so I would not ever just sell an exploit to "the bad guys" so realistically I was never going to get the most money for said exploit so it is not all about money.

Re: Zoom zero-day discovery

#10
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

> Is it just me, or does $200k seem far too low for this?

For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.

Post reply on HN