Earlier quoted context omitted.
Hosting a file on a url anyone can access from anywhere is the whole point…
Public S3 buckets are not a good choice for that because of the "anyone could bankrupt you" reason above. That is generally NOT the use case for S3, and it's the reason why private is the default and there are alerts for public buckets. For public access, within AWS, you'd want to put CloudFront in front of the bucket and only allow external users to access CloudFront. However, there's a better option... Outside of A…
Beg Bounties (2021)
141–150 of 174 posts
Re: Beg Bounties (2021)
#142I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
This is extortion, and a crime.
Re: Beg Bounties (2021)
#143Earlier quoted context omitted.
It seems that in many places intent to commit another crime is a key.
But trespassing is (presumably in those jurisdictions) a crime.
Something like that, I'm not a lawyer.
Re: Beg Bounties (2021)
#144I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".
> I don't think security researchers should work for free I agree. The OP comes across a bit gatekeepy to me. Not everyone has made a big name for themselves yet. How are you supposed to find customers in the first place? Gotta start somewhere. Quality of the findings is orthogonal to asking for compensation. There will always be people asking for money without providing value. But I don’t think we should throw the b…
The piece is gatekeeping in the same way the spam filters we all use are gatekeeping. There's always stuff we want to keep on the far side of our filters. Beg bounties are among them for many.
Re: Beg Bounties (2021)
#145I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
There are a few reasons. 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. 2. The second reason is the approach that the beg bounty uses: that of fearmongering. If the beg-bountier disclosed the vuln and asked for the bounty that would be ok,…
Re: Beg Bounties (2021)
#146A bit off topic: I am genuinely surprised that he gets to blog (regular and micro via Twitter/X) with such a savage style. In many mega corps, even tech, they would eventually curtail this type of blogging. Steve Yegge is a pretty famous example where even Google was trying to curtail his blogging topics and style.
Re: Beg Bounties (2021)
#147Earlier quoted context omitted.
Bad behaviour should not be tolerated just because it comes from the third world
You don't have the option of tolerating or not tolerating it. You're seeing one of these people, but there are a thousand more behind them, and they don't care what you tolerate or don't; it's a numbers game to them.
I get what you're saying about it being unavoidable, but there's no need to concede without a fight.
Re: Beg Bounties (2021)
#148Earlier quoted context omitted.
We've had a handful of these that we've paid out for small issues over the years. Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers. Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" cre…
How many of the legit bounties have been withheld until you paid?
This is part of the reason paying out small bounties is valuable and important. You want to build a reputation in the community for honoring your responsible disclosure policy.
Re: Beg Bounties (2021)
#149I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…
There are a few reasons. 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. 2. The second reason is the approach that the beg bounty uses: that of fearmongering. If the beg-bountier disclosed the vuln and asked for the bounty that would be ok,…
My suggested approach is to not engage.
Re: Beg Bounties (2021)
#150Earlier quoted context omitted.
And? You're not accomplishing anything by pushing back on them.
I simply said “thank you for the report but I’m not paying”. The “researcher” responded by spamming the rest of the board and the property manager for the community with hundreds of messages filled with expletives. I didn’t write a blog or do anything to “trigger” anyone. Heck the only reason I replied is because they kept emailing the other non tech people in an attempt to extort money out of them. I don’t find thei…