Live data from Hacker News

Shopify has paid over $300k in security exploit bounties

hackerone.com

31–40 of 80 posts

Re: Shopify has paid over $300k in security exploit bounties

#31
post #18

This wasn't unexpected outside of the extend of the bounties. What you have to realize is how important Security is to Shopify. We are a trust based business to an extreme extend. We host the livelihoods of hundreds of thousands of other businesses. If we are down or compromised all of them can't make money ( as some of you saw during Black Friday, to the tune of $300k+ a minute at times ). One of the best ways for u…

So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…

> you could've engaged a reasonable team for several man-months

Doubt that.

1) The daily rate for this kind of work is high.

2) It's hard to find people who can execute. (read: security as in pen testing, not security as in filling a PCI compliance checklist).

3) Multiply 1 and 2 by the number of people you want in the team.

Re: Shopify has paid over $300k in security exploit bounties

#32

I'm surprised it's so little. 300k is very little compared to the financial burden that a security breach would bring. Talk to Target and Yahoo about cost. If anything they might start looking into way of increasing it.

It's very delicate to talk about financial burden, given the following references: "Two months after damaging data breach, Target stock has its best day in 5 years" http://blogs.marketwatch.com/behindthestorefront/2014/02/26/... "Sad reality: It's cheaper to get hacked than build strong IT defenses" http://www.theregister.co.uk/2016/09/23/if_your_company_has_... "The Cost of Cyberattacks Is Less than You Might Think"…

So, the best way to monetize a breach is to play with the company's stock while you disclose the breach. Interesting.

Re: Shopify has paid over $300k in security exploit bounties

#34
post #16

Earlier quoted context omitted.

How?

Up-to-date browser in Virtualbox with uMatrix for manual whitelisting? To go more tinfoil, a "trash" laptop on its own subnet.

Better keep your real laptop at a safe distance unless you want VM escape --> Bluetooth propagation --> pwned.

Re: Shopify has paid over $300k in security exploit bounties

#35

Earlier quoted context omitted.

So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…

> you could've engaged a reasonable team for several man-months Doubt that. 1) The daily rate for this kind of work is high. 2) It's hard to find people who can execute. (read: security as in pen testing, not security as in filling a PCI compliance checklist). 3) Multiply 1 and 2 by the number of people you want in the team.

Sorry, but got to disagree with you there. I'm a security tester and have been in the industry for 15+ years either as a buyer or provider of services, for small and large companies, I've been involved in procurement of multi hundred $k tests and involved in the delivery similar sized engagements.

You absolutely can get good security testing consultants for $2k/day for example, and probably less depending on the region and exact speciality.

for $368k at a $2k/day rate that would be 184 person-days or several person months (as stated).

It's well known there are teams who specialize in specific technologies, and with a sophisticated customer, not too tricky to interview and make sure you get the right people.

Re: Shopify has paid over $300k in security exploit bounties

#36

Earlier quoted context omitted.

> you could've engaged a reasonable team for several man-months Doubt that. 1) The daily rate for this kind of work is high. 2) It's hard to find people who can execute. (read: security as in pen testing, not security as in filling a PCI compliance checklist). 3) Multiply 1 and 2 by the number of people you want in the team.

Sorry, but got to disagree with you there. I'm a security tester and have been in the industry for 15+ years either as a buyer or provider of services, for small and large companies, I've been involved in procurement of multi hundred $k tests and involved in the delivery similar sized engagements. You absolutely can get good security testing consultants for $2k/day for example, and probably less depending on the regi…

Sorry. Should have clarified. They could get pen testers and it would cost as much as they paid so far.

Managing a pen test or a bounty program are very different things. I don't think that they planned to spend $300k in exploits when they first rolled out the bounties.

A company serious about security should have both anyway: Security audits + bounty programs. They fundamentally cover different things, with some overlap.

Re: Shopify has paid over $300k in security exploit bounties

#37
post #34

Earlier quoted context omitted.

Up-to-date browser in Virtualbox with uMatrix for manual whitelisting? To go more tinfoil, a "trash" laptop on its own subnet.

Better keep your real laptop at a safe distance unless you want VM escape --> Bluetooth propagation --> pwned.

Well, web Bluetooth is a thing now, so no need to escape VM in that scenario

Re: Shopify has paid over $300k in security exploit bounties

#38
post #18

This wasn't unexpected outside of the extend of the bounties. What you have to realize is how important Security is to Shopify. We are a trust based business to an extreme extend. We host the livelihoods of hundreds of thousands of other businesses. If we are down or compromised all of them can't make money ( as some of you saw during Black Friday, to the tune of $300k+ a minute at times ). One of the best ways for u…

So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…

Of course we use both. One provides depth, the other breadth.

Re: Shopify has paid over $300k in security exploit bounties

#39

Earlier quoted context omitted.

Sorry, but got to disagree with you there. I'm a security tester and have been in the industry for 15+ years either as a buyer or provider of services, for small and large companies, I've been involved in procurement of multi hundred $k tests and involved in the delivery similar sized engagements. You absolutely can get good security testing consultants for $2k/day for example, and probably less depending on the regi…

Sorry. Should have clarified. They could get pen testers and it would cost as much as they paid so far. Managing a pen test or a bounty program are very different things. I don't think that they planned to spend $300k in exploits when they first rolled out the bounties. A company serious about security should have both anyway: Security audits + bounty programs. They fundamentally cover different things, with some ove…

Ahh indeed, that was kind of my initial question for the top-commentor. I'm interested in whether Shopify explored getting security consultants in to review this area before going for a bug bounty on it, or went straight to the bug bounty.

My personal feeling is that the order of play should be

Internal Security Review --> External Security Review --> Bug Bounty

as you can use the first two stages to catch all the basic stuff and some of the advanced stuff then leave the bug bounty to pay out for things the first two elements missed, but that you still want to know about.

So I'm interested in data that suggests that companies are either going for that route, or have decided to cut out the external consultant review and go straight to bug bounty. In this case I'd guess part of that would be whether Shopify did indeed expect a $300k+ bug bounty programme or whether that was a surprise to them.

Re: Shopify has paid over $300k in security exploit bounties

#40
post #18

This wasn't unexpected outside of the extend of the bounties. What you have to realize is how important Security is to Shopify. We are a trust based business to an extreme extend. We host the livelihoods of hundreds of thousands of other businesses. If we are down or compromised all of them can't make money ( as some of you saw during Black Friday, to the tune of $300k+ a minute at times ). One of the best ways for u…

So I'd be interested to know your thoughts on bug bounties as against "traditional" security reviews. Have these areas of your application been through external reviews before being opened up to bug bounty or did you decide to start there? I was thinking that for the amount you've paid out in bounties you could've engaged a reasonable team for several man-months, so was interested in what led you more down the bug bo…

You seem to assume we set out to pay this amount to begin with. Indeed for this amount we could have went other ways, but hindsight is 20/20.

No one expected to get so many valid sumbmissions in such a short time. We set the payout amounts this high as a way to attract talent at the beginning of the program, which worked quite well to bootstrap it.

Post reply on HN