Live data from Hacker News

Launch HN: Federacy (YC S18) – bug bounties for startups

news.ycombinator.com

21–27 of 27 posts

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#21

Earlier quoted context omitted.

Has anyone ever tried requiring an application fee to help with the bombardment issue?

That'd be interesting--a small, maybe even just $1-10, deposit that gets refunded if the bug is legitimate. I don't think punishing dupes is a good idea though, because a researcher has no idea (and should have no idea) whether their bug has been found before, so dupes should probably still result in a refund. However, as a kid who has no credit card, but has found some pretty spicy bugs (and gotten rewarded for them…

We definitely don't want to discourage you from contributing. It also doesn't necessarily have to be money, you could stake reputation you've previously earned.

The dupes problem is super important, in my opinion, because it's currently an unpleasant experience for both sides. Not getting paid out for valid work that has simply been reported before (but not disclosed) can make doing this kind of research as a freelancer unfeasible, while triaging duplicate reports burns time for dev teams.

We've tried to build out in-scope/out-of-scope functionality that makes it super simple to keep your scopes current (could even update automatically via API). We definitely want to build out additional functionality that makes publicly acknowledging known, 'won't fix', and non-impactful issues super easy, perhaps by pulling most of the information from a duplicate report. Do you think that’d be useful?

The other thing we want to really focus on is the disclosure process, and encouraging companies to do it as often and soon as possible.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#22
post #18
post #5

Earlier quoted context omitted.

Your experience is exactly why we're building Federacy. Bug bounties can be an incredibly efficient way to work with outside security researchers to find vulnerabilities, test for best practices, etc., but done poorly, can cause more damage then they help. We want to make them work for startups as well as they do for companies like Dropbox, Shopify, and Google. We have our work cut out for us -- but if we're successf…

Every bug bounty platform has tried to be "selective" in the researchers they allow in when they start. You'll soon discover that selective doesn't scale. The only way you are going to disrupt the current market is by hiring on your own salaried pentesting talent to participate.

[deleted]

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#23
What does it mean to "contract an outsourced CISO" to a researcher who reported through a bug bounty program? What's an "outsourced CISO"?

I think it's unlikely that "CISO" is the word you want to use in your copy.

How are you vetting researchers? I logged in as a researcher, and it looks like it works just like H1 works: there are public bounties, and private ones for which admission is gated by performance on the public bounties.

It is not the case that H1 typically costs six figures; typical costs for a startup on H1, with triage, are low five figures.

We manage bug bounties for several of our clients (we run outsourced security teams for startups). If there's a problem we have with bounties, it's not getting enough submissions from them. Triage can be annoying (I kind of enjoy it), but we do full-scope penetration tests for each of our clients, and it's noteworthy how much more a real pentest finds than a bounty program. There are different incentives, different information available, and different kinds of work result.

(There are things bounties do better, too; bounties are good for finding oddball XSS and CSRF problems, and good at corner-case web hygiene stuff).

How are you attracting talent? I don't really understand the business model. Bounty researchers already have a bunch of platforms they can use if they want to do bounty-type scanning. Why are they using yours?

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#24
post #14

As a "researcher" I don't find your vulnerability levels too informative. I'd suggest you use or adapt the bugcrowd taxonomy: https://bugcrowd.com/vulnerability-rating-taxonomy That is a model that has been shaped from the experience of many programs and has a clear, "yes this is an issue but no you're not getting paid" level which is important for avoiding thousands of time-wasting reports such as non-perfect HTTPS…

I agree with you, they aren't very informative. We're big fans of BugCrowd's work in this area, and intend to adopt their VRT, though we're still considering how to make P1/P2/P3/P4 more clear/descriptive at a glance. We're also still brainstorming and looking for good ideas on how to handle duplicate reports. At this point, we're tackling it by vetting researchers and helping with the ones who ignore 'Known Issues'…

The baseline VRT P5's a bunch of things most startups really want to know about, like exposed admin consoles and broken password reset flows.

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#25
post #23

What does it mean to "contract an outsourced CISO" to a researcher who reported through a bug bounty program? What's an "outsourced CISO"? I think it's unlikely that "CISO" is the word you want to use in your copy. How are you vetting researchers? I logged in as a researcher, and it looks like it works just like H1 works: there are public bounties, and private ones for which admission is gated by performance on the p…

Just a quick preface: we started building Federacy a little over two months ago as part of this batch of YC companies. We’re a team of two FTE. Many or all of our assumptions could well prove to be woefully off-target. But.. we think that if we keep our heads down and build what the startups and researchers on the platform ask for, we can make at least a small difference in how startups can secure themselves.

A huge majority of the startups we’ve talked to don’t have a bug bounty program, haven’t worked with an outside pentester, and honestly, don’t know where to start.

Most startups don’t have a CISO or dedicated security team, so by “outsourced CISO” we mean: having a designated, vetted, and experienced person/team on-hand who can help with higher-level strategy and architectural decisions; essentially, a small piece of what you provide at Latacora. We think there are very few firms with your level of experience that are working with non-enterprise customers. Do you agree? Do you think there is a better description?

We’re at the very early stages of conceptualizing how we can make the high-level advisory services work. In talking to a bunch of talented security people at large Internet companies etc, we found a lot were interested in working directly with startup CTOs if they could make a significant impact and not have to deal with the tedious aspects of running a consultancy. Our thinking was that if we could build matchmaking on top of the VRP and other tooling we’re building, it could be an efficient way to connect the two and create a lot of value for both sides. What do you think?

I think the value of a bug bounty program probably comes down to the quality of the people doing the work and the willingness of the company to engage actively with the researchers. It’s our job to manage the balance between the researchers on the platform, and the active programs, so that both find value -- and ultimately, yield more secure startups.

We hope the best startups will use our bug bounty program alongside full-scope pentesting and a myriad of other outside resources. I think you see this done well at some companies that have really good security postures. Shopify, Dropbox, etc. have really strong internal teams, work with outside researchers, and still pay out a lot of bug bounties.

We're currently vetting researchers manually -- James and I are reviewing each registration and reaching out individually so we can pair them with startups on the platform. We’ll build out functionality to help over the long run, and are already tossing around ideas to infer trust through vouching, etc. But, we think it’s important to show our work early and get people using the platform to help guide these decisions.

We’re reaching out to researchers directly -- through our friends, the Y Combinator network, and even cold, if we find someone we think would be a good fit for one of our programs. It’s definitely self-selecting, to an extent, as we’re very much an early-stage startup ourselves, and the work they’ll be doing is with mostly early-stage startups.

Appreciate the heads up wrt H1 costs, edited the original post (edit: can't edit the original post, derp, but duly-noted). I think low five figures still puts H1 out of the reach of a lot of companies, and that a well-run bug bounty program can add a lot of value for almost every startup. I think there are probably tens of thousands of startups that really should be engaging outside security researchers, and, of course, that, in itself, creates a pretty big challenge for an already severe talent crisis.

What do you think?

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#26
post #17
post #13

Your bullets all line up with what Synack and Cobalt.io are doing. How do you differentiate from the two of them, who themselves are already competing hard with each other? Both of them strictly curate their test base, allow for strictly-private programs, allow for researchers to work closely with firms for resolution, can launch and operate your whole program, and charge per finding.

To be completely forthright, we don’t know. Have you used Synack or Cobalt? Would love to hear your experience. We haven’t heard much about Cobalt, but there are some sharp people behind Synack. That said, I don’t think there can be too many people trying to help companies secure themselves. I think HackerOne and BugCrowd have We would like every company to have a bug bounty program, and that is what we’re tailoring…

Hi James and William - congrats on founding Federacy.

I'm the CEO and Co-founder of Cobalt.io. I love startups and it takes a lot of courage to get going, so I applaud you for taking the leap and helping innovate in this space.

We started building the Cobalt.io platform back in 2013. We originally started as a bug bounty platform and since then evolved into a Pen Testing as a Service platform [PTaaS] over the last 5 years.

During this evolution I did a lot of thinking around crowdsourcing freelancers for security testing. I'll recommend these two blogs around how the market has evolved over the years and the different cases where bug bounties make sense vs. pen tests and vuln assessments. - https://blog.cobalt.io/deconstructing-and-rewiring-bug-bount... - https://blog.cobalt.io/the-third-wave-of-application-securit...

I believe you are in the bay area. Feel free to ping me at linkedin or twitter and I'll be happy to meetup.

Cheers Jacob

Re: Launch HN: Federacy (YC S18) – bug bounties for startups

#27
post #17

Earlier quoted context omitted.

To be completely forthright, we don’t know. Have you used Synack or Cobalt? Would love to hear your experience. We haven’t heard much about Cobalt, but there are some sharp people behind Synack. That said, I don’t think there can be too many people trying to help companies secure themselves. I think HackerOne and BugCrowd have We would like every company to have a bug bounty program, and that is what we’re tailoring…

Hi James and William - congrats on founding Federacy. I'm the CEO and Co-founder of Cobalt.io. I love startups and it takes a lot of courage to get going, so I applaud you for taking the leap and helping innovate in this space. We started building the Cobalt.io platform back in 2013. We originally started as a bug bounty platform and since then evolved into a Pen Testing as a Service platform [PTaaS] over the last 5…

Hey Jacob, thanks for the kind words, and taking the time to leave a comment. I'd love to meet up, pinging you now!
Post reply on HN