Earlier quoted context omitted.
No, it's not. CNE is shockingly effective, both for organized crime and for the international IC. The productivity wins are so great there is enormous space for the market prices of tradable vulnerabilities to increase; maybe even multiple orders of magnitude. We're not going to disrupt that process with bug bounties. I really think people just like to think about stories where someone like them finds a bug and gets…
> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun. P.S. a lot of time your writing comes off as having a smug tone that rubs me the wrong way. Actually, I already won a small lottery jackpot doing security stuff. Then a large one doing security stuff. Then a small one again doing other stuff. I could hav…
Leaking the email of any YouTube user for $10k
461–470 of 487 posts
Re: Leaking the email of any YouTube user for $10k
#462Earlier quoted context omitted.
No, it's not. CNE is shockingly effective, both for organized crime and for the international IC. The productivity wins are so great there is enormous space for the market prices of tradable vulnerabilities to increase; maybe even multiple orders of magnitude. We're not going to disrupt that process with bug bounties. I really think people just like to think about stories where someone like them finds a bug and gets…
> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun. Increasing bounties by a small factor will be enough to reduce things on the grey market and to increase the ROI of people choosing to do freelance security research. The time between payoffs is enough that no one is going to get rich from $150k bounties…
Where we differ is the long-term impact of those increasing costs. I don't think market competition is going to meaningfully improve security. Things like swapping out components for memory-safe replacements, hardening runtimes, and deprecating ancient protocols and formats have, though, and will continue to pay off. So I'm optimistic, just for a different reason than you are.
Re: Leaking the email of any YouTube user for $10k
#463Earlier quoted context omitted.
There's an easy way to put your money where your mouth is here. Just offer $11k for this or similar vulnerabilities out of your own pocket, and then resell them. If there really is a large and active market for this at higher dollar values, you'll make a killing! Sure is funny there's nobody doing that despite so many people being so dead certain there's an active market.
If I did, would you know? And if I did, it wouldn’t stop people from doing co-ordinated disclosure either, would it? Same with high end exploits - some folks do co-ord disclosure because it feels good and is great for your CV; others sell gray market and we generally have no idea what’s being traded. (With the exception of say, zerodium or 0xcharlie’s various talks)
Re: Leaking the email of any YouTube user for $10k
#464Earlier quoted context omitted.
I think you've missed my point. I know data brokers exist. Does there exist today a data broker that functions in whole or in significant part buy acquiring vulnerabilities and exploiting them to collect data? He's a more concise way to frame my argument: if you're imagining yourself to be the first person to sell a particular kind of vulnerability to, then your customer is imaginary.
Yeah, I think this is valid. “I’m confident I can find someone who will buy this” vs “I’ll message grugq”, roughly?
Re: Leaking the email of any YouTube user for $10k
#465Earlier quoted context omitted.
Potentially deanonymizing pseudonymous Youtube accounts sounds pretty bad by itself.
> deanonymizing pseudonymous Youtube accounts But its not, its giving their gmail address which is mostlikely something like mrbeast01@gmail.com
Re: Leaking the email of any YouTube user for $10k
#466Earlier quoted context omitted.
> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun. P.S. a lot of time your writing comes off as having a smug tone that rubs me the wrong way. Actually, I already won a small lottery jackpot doing security stuff. Then a large one doing security stuff. Then a small one again doing other stuff. I could hav…
Sorry you feel that way, but I own it. You're welcome not to take me seriously. I know your background. But I think you've made some claims in this thread that are probably wrong.
You're right that I've not been involved in the grey market for awhile. And when I did, I was on the "advising sophisticated buyers" side of it, rather than trying to sell things.
Re: Leaking the email of any YouTube user for $10k
#467Earlier quoted context omitted.
> I really think people just like to think about stories where someone like them finds a bug and gets a lottery jackpot as a result. I like that story too! It's fun. Increasing bounties by a small factor will be enough to reduce things on the grey market and to increase the ROI of people choosing to do freelance security research. The time between payoffs is enough that no one is going to get rich from $150k bounties…
From conversations with people who participate in the grey market today and conversations with people involved in large-scale bounties, I think everybody believes that payouts for high-value exploits (and thus bounty payoffs for high-value POCs) are going to climb, probably rapidly, so the thing you want is a thing I expect to happen, and am happy is happening. Where we differ is the long-term impact of those increas…
I think the things you describe all have long-term wins but may worsen the short-term picture. Sure, using better tools is good, but younger code is riskier for its own reasons.
Bounties are a great short to intermediate strategy. There's code that's used today, and this is the way to get some near-term outside effort towards making it better (and these sentinel events can provide guidance on where to spend inside effort as you say).
And, of course, if software engineering growing up means we actually get fewer bugs, bounties become even more worthwhile: any issues found will remove a bigger proportion of total vulnerability.
Re: Leaking the email of any YouTube user for $10k
#468Earlier quoted context omitted.
Sorry you feel that way, but I own it. You're welcome not to take me seriously. I know your background. But I think you've made some claims in this thread that are probably wrong.
You're free to disagree, but you don't need to do it with the snarky variant "I like that story too! It's fun." that's so easily misread on the internet. You're right that I've not been involved in the grey market for awhile. And when I did, I was on the "advising sophisticated buyers" side of it, rather than trying to sell things.
Re: Leaking the email of any YouTube user for $10k
#469Earlier quoted context omitted.
From conversations with people who participate in the grey market today and conversations with people involved in large-scale bounties, I think everybody believes that payouts for high-value exploits (and thus bounty payoffs for high-value POCs) are going to climb, probably rapidly, so the thing you want is a thing I expect to happen, and am happy is happening. Where we differ is the long-term impact of those increas…
> I don't think market competition is going to meaningfully improve security. I think the things you describe all have long-term wins but may worsen the short-term picture. Sure, using better tools is good, but younger code is riskier for its own reasons. Bounties are a great short to intermediate strategy. There's code that's used today, and this is the way to get some near-term outside effort towards making it bett…
I see bounties as an engineering tool more than anything else. For the reason I provided upthread, I don't think it's likely that they're going to alter market dynamics. I don't have a really strong basis to claim this; it's just a conclusion I'm drawing from the incentives at play. I think the most important thing bounties do is mobilize people who would never work with a grey-market broker to do good vuln research work, I think the sums we're transacting in today are clearly enough to accomplish that, and regardless of whether you agree there, we both agree that those sums are set to increase.
Re: Leaking the email of any YouTube user for $10k
#470Earlier quoted context omitted.
> I don't think market competition is going to meaningfully improve security. I think the things you describe all have long-term wins but may worsen the short-term picture. Sure, using better tools is good, but younger code is riskier for its own reasons. Bounties are a great short to intermediate strategy. There's code that's used today, and this is the way to get some near-term outside effort towards making it bett…
I hear that concern a lot, about younger code, but I think that misapprehends the situation. New code will bring new bugs, but only specific kinds of bugs have real market value. I think we're on a trajectory towards those marketable bugs having something like a vintage. I see bounties as an engineering tool more than anything else. For the reason I provided upthread, I don't think it's likely that they're going to a…
I'm reminded of when we really systematically started treating temporary names correctly and thought security was going to be so much better.
I think there's no shortage of bugs and exploitation scenarios. We'll eliminate the easiest to exploit and most common mistakes, but there will be yet more.
> I think the most important thing bounties do is mobilize people who would never work with a grey-market broker to do good vuln research work
I think it makes it easier for those who work with grey market brokers to "go legit", too. Even if bounties can't win on price, this doesn't mean they can't win people over.
Of course, the fact that they can't win on price is a market oddity. Exploitation causes net economic harm; it's a negative-sum proposition. The only reason why software vendors can't outbid the criminals is because the software vendors don't pay the actual losses. I'm hoping this changes some over time.
> we both agree that those sums are set to increase.
I don't/didn't know that's true, but that's welcome news if true.