Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…
I've never had this happen but what I've had in the past is people saying "This isn't a vulnerability", then I told them I would go public with it with an Easy POC that anyone could do. Example: http://writecodeeveryday.github.io/projects/badqr/ I literally had to twist their arm to get it patched... since was a something to 'reduce friction' which allowed you to steal someone's Bitcoins. At the time, the POC would h…
Teen Becomes First Hacker to Earn $1M Through Bug Bounties
41–50 of 178 posts
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#42This is 1MM over 3-4 years, right? $330k is good money, but it's also in the ballpark for gifted vulnerability researchers in SFBA.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#43Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#44Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#45I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#46I'm very happy for the kid and like the idea that these programs are available but does this incentivise companies to effectively outsource their bug finding? From a purely fiscal point of view, why hire expensive full time staff to go digging when you can just throw a few sheckles at stuff as it comes up?
Why not both? The bounties are great for finding things your security team might not think about or might consider low-pri, but having a dedicated team is important to make sure you've got the core use cases covered.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#47This is 1MM over 3-4 years, right? $330k is good money, but it's also in the ballpark for gifted vulnerability researchers in SFBA.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#48This is 1MM over 3-4 years, right? $330k is good money, but it's also in the ballpark for gifted vulnerability researchers in SFBA.
330K USD in San Francisco is much, much less than 300K USD in Buenos Aires
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#49Earlier quoted context omitted.
But no one is going to pay $330k to a 17 year old with no experience
Well, they did, right? So that doesn't seem true.
You can almost always make more as a contractor because you're shifting risk from the company onto your LLC. They pay for a la carte results instead of paying for an employee who could hypothetically deliver results.
Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties
#50This is 1MM over 3-4 years, right? $330k is good money, but it's also in the ballpark for gifted vulnerability researchers in SFBA.
330K USD in San Francisco is much, much less than 300K USD in Buenos Aires
Case in point: my friend that worked at Waymo paid $900/mo for a room in a house in Lower Haight...