Live data from Hacker News

Launch HN: Federacy (YC S18) – bug bounties for startups

news.ycombinator.com

11–20 of 27 posts

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#11

"Would you consider contracting an outsourced CISO or a pentest with a security researcher that has reported vulnerabilities to you through your bug bounty program?" Budget permitting, this seems like a no brainer. I mean, they already have some familiarity with our app. The only thing I would be worried about is people gaming the system: finding some low hanging fruit or running their toolkits on a bunch of apps, th…

Yeah, that definitely makes sense, and I agree.

At the core, Federacy is a marketplace, and the surest way for us to constrain the transactions will be to make it difficult for startups to extract a lot of value. We’ll have to work hard on the tools (reputation, vetting, etc), for startups to trust and work with really talented researchers.

Not quite as important, I think, but also interesting is what tooling we can build to let researchers focus on the work they enjoy, and that adds the most value for startups. If we can make the reporting process more intuitive, they can focus more on research -- and less on writing traditional pentest reports.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#12
post #8
post #5

Earlier quoted context omitted.

Your experience is exactly why we're building Federacy. Bug bounties can be an incredibly efficient way to work with outside security researchers to find vulnerabilities, test for best practices, etc., but done poorly, can cause more damage then they help. We want to make them work for startups as well as they do for companies like Dropbox, Shopify, and Google. We have our work cut out for us -- but if we're successf…

My 2 cents: I used to work on the appsec team at Twitter and can attest that we could not get Mopub to ever resolve any of your security vulnerabilities. Noise is certainly a problem on bug bounty platforms but our team handled all of that - by the time vulnerabilities reached you they were already valid, triaged, important issues to resolve. > We're always overburdened with work on revenue-producing features This is…

Hah, yeah, this stuff is hard and acquisitions make it even harder.

I think you started a month after I left. We built a lot at MoPub in a short period of time and when we were acquired I had a mile-long backlog. The Twitter security team was great though and built a war-room during integration. We worked some intense hours leading up to the IPO and over the Holidays, and I’m proud of the work we all did. We migrated a sprawling stack that supported what was then the largest mobile ad exchange and billions of sub-second auctions over just a few weeks. Most of the MoPub team transitioned to other projects and teams quickly though and I left not that long after.

Totally agree that it starts at the top. If the C-level doesn’t care, there just won’t be the resources it takes to build good, secure software. We intend to focus on supporting companies who do care, and we think this focus will also impact how companies using Federacy interact with researchers. We want outside researchers to be viewed as allies, not as a burden.

Have any thoughts on how we can best accomplish this?

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#13
Your bullets all line up with what Synack and Cobalt.io are doing. How do you differentiate from the two of them, who themselves are already competing hard with each other? Both of them strictly curate their test base, allow for strictly-private programs, allow for researchers to work closely with firms for resolution, can launch and operate your whole program, and charge per finding.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#14
As a "researcher" I don't find your vulnerability levels too informative. I'd suggest you use or adapt the bugcrowd taxonomy: https://bugcrowd.com/vulnerability-rating-taxonomy

That is a model that has been shaped from the experience of many programs and has a clear, "yes this is an issue but no you're not getting paid" level which is important for avoiding thousands of time-wasting reports such as non-perfect HTTPS headers, etc.

I'd be interested in hearing how you plan to deal with duplcate reports. This is an area that hackerone does better than bugcrowd. Hackerone is more interested in disclosure and getting reports to a point where they can be disclosed. If a bug is marked duplicate you are given access to the original report which prevents falsely marking duplicates to avoid bounties.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#15

Earlier quoted context omitted.

Has anyone ever tried requiring an application fee to help with the bombardment issue?

That'd be interesting--a small, maybe even just $1-10, deposit that gets refunded if the bug is legitimate. I don't think punishing dupes is a good idea though, because a researcher has no idea (and should have no idea) whether their bug has been found before, so dupes should probably still result in a refund. However, as a kid who has no credit card, but has found some pretty spicy bugs (and gotten rewarded for them…

Honestly, I think a 99 cent fee could help to remove a lot of the noise.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#16
post #14

As a "researcher" I don't find your vulnerability levels too informative. I'd suggest you use or adapt the bugcrowd taxonomy: https://bugcrowd.com/vulnerability-rating-taxonomy That is a model that has been shaped from the experience of many programs and has a clear, "yes this is an issue but no you're not getting paid" level which is important for avoiding thousands of time-wasting reports such as non-perfect HTTPS…

I agree with you, they aren't very informative. We're big fans of BugCrowd's work in this area, and intend to adopt their VRT, though we're still considering how to make P1/P2/P3/P4 more clear/descriptive at a glance.

We're also still brainstorming and looking for good ideas on how to handle duplicate reports. At this point, we're tackling it by vetting researchers and helping with the ones who ignore 'Known Issues' and out of scope limitations. Like HackerOne, we're very interested in encouraging companies to disclose their vulnerabilities, because these disclosures are important to their users, the people who may build on top of any service they offer, and the researchers who are being given public credit.

In regard to a company marking a bug a duplicate to avoid bounties, those are definitely not the type of companies we want to work with. I'm not sure that technical solutions to mitigate that sort of behavior is necessary when we can curate those who have access to the platform. We’re going to keep a high quality of researchers and companies -- and it goes both ways.

Our Vulnerability Disclosure Policy Template, which is based primarily on Chris Evan's work @ Dropbox, and is inspired by a bunch of other well-written programs too, puts full control of payments/recognition into the hands of the company. I think our best recourse on this issue is to simply not include bad actors.

Do you have any ideas for other ways we can limit dupes? Or how to really effectively communicate what is out of scope or a known issue?

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#17
post #13

Your bullets all line up with what Synack and Cobalt.io are doing. How do you differentiate from the two of them, who themselves are already competing hard with each other? Both of them strictly curate their test base, allow for strictly-private programs, allow for researchers to work closely with firms for resolution, can launch and operate your whole program, and charge per finding.

To be completely forthright, we don’t know. Have you used Synack or Cobalt? Would love to hear your experience. We haven’t heard much about Cobalt, but there are some sharp people behind Synack.

That said, I don’t think there can be too many people trying to help companies secure themselves.

I think HackerOne and BugCrowd have We would like every company to have a bug bounty program, and that is what we’re tailoring our product to. (We’d certainly rather pay an outside researcher if they find a vulnerability than risk our customer’s data). Synack et al, I’m guessing, run tens to hundreds of thousand per month and accordingly, their software is focused on supporting a small number of large/enterprise customers. We think something important happens when you have tens of thousands of startups/companies using the same marketplace for bug bounties and pentests.

I think we probably all share the same general mission -- but our approach is a bit different: to build software that will be tailored to startups, and to have a lot more of them.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#18
post #5

We've used HackerOne at a startup I work at (10-20 employees). We had to turn it off because we were getting bombarded every couple days with the same issues, that were just run by crackers/hackers running basic pen test scripts. They all seemed to have the same toolkit, and would just run the same tests and report the same bugs. Most of which were either invalid, or just not a priority and, so, a waste of our time t…

Your experience is exactly why we're building Federacy. Bug bounties can be an incredibly efficient way to work with outside security researchers to find vulnerabilities, test for best practices, etc., but done poorly, can cause more damage then they help. We want to make them work for startups as well as they do for companies like Dropbox, Shopify, and Google. We have our work cut out for us -- but if we're successf…

Every bug bounty platform has tried to be "selective" in the researchers they allow in when they start. You'll soon discover that selective doesn't scale.

The only way you are going to disrupt the current market is by hiring on your own salaried pentesting talent to participate.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#19

Earlier quoted context omitted.

Has anyone ever tried requiring an application fee to help with the bombardment issue?

That'd be interesting--a small, maybe even just $1-10, deposit that gets refunded if the bug is legitimate. I don't think punishing dupes is a good idea though, because a researcher has no idea (and should have no idea) whether their bug has been found before, so dupes should probably still result in a refund. However, as a kid who has no credit card, but has found some pretty spicy bugs (and gotten rewarded for them…

You could try a prepaid card. The overhead was $5 when I used them. They were good for keeping my real card numbers out of circulation, too.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#20
post #18
post #5

Earlier quoted context omitted.

Your experience is exactly why we're building Federacy. Bug bounties can be an incredibly efficient way to work with outside security researchers to find vulnerabilities, test for best practices, etc., but done poorly, can cause more damage then they help. We want to make them work for startups as well as they do for companies like Dropbox, Shopify, and Google. We have our work cut out for us -- but if we're successf…

Every bug bounty platform has tried to be "selective" in the researchers they allow in when they start. You'll soon discover that selective doesn't scale. The only way you are going to disrupt the current market is by hiring on your own salaried pentesting talent to participate.

What do you think caused being selective not to scale at other platforms? What do you think we can do to keep the quality of our researchers extremely high?

What we’ve heard in talking about this to a bunch of talented researchers is that they’ve been frustrated with payout rates (too low for amount of work), tone of the interactions between researcher and company, number of opportunities/companies where they can add value (given their skillset - many have said they do the work in large part to learn).

I think there is probably a lot we can do to create/keep balance in the marketplace to address a lot of these if we take things slow.

Would love to hear more of your thoughts on the strategy of building out our team with salaried pentesting talent. Why do you think that is critical to adding a lot of value for startups?

Post reply on HN