Earlier quoted context omitted.
You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/
Wow, a digital arms dealer. How is that they have not been destroyed or captured by someone's military?
$36k Google App Engine RCE
71–80 of 164 posts
Re: $36k Google App Engine RCE
#72"When issuing the reward, we'll take into account what you could have achieved with this access" makes me laugh. How scary must that be for the Google team? You know you've messed up so badly and the person who is investigating is doing so blindly with no knowledge or accountability if he breaks something. Yikes. Kudos to everyone for doing the right things. And great bounty- the average yearly income in Uruguay is $…
Are you sure that's accurate? According to this [1] it's about 10 000 USD per capita. [1] https://www.ceicdata.com/en/indicator/uruguay/annual-househo...
Re: $36k Google App Engine RCE
#73"When issuing the reward, we'll take into account what you could have achieved with this access" makes me laugh. How scary must that be for the Google team? You know you've messed up so badly and the person who is investigating is doing so blindly with no knowledge or accountability if he breaks something. Yikes. Kudos to everyone for doing the right things. And great bounty- the average yearly income in Uruguay is $…
Are you sure that's accurate? According to this [1] it's about 10 000 USD per capita. [1] https://www.ceicdata.com/en/indicator/uruguay/annual-househo...
Re: $36k Google App Engine RCE
#74Earlier quoted context omitted.
Sorry, I'm interested in anyone's response to this, since the HN community reaction to any price paid in a bug bounty by a big company always seems to be "people can make more money on the black market". Rather than recapitulating all the previous debates about why that's not true, I'm interested in seeing someone --- doesn't have to be you --- work their way to an educated guess at a black market price for a bug lik…
Why to vendors pay bug bounties, if not to defend against financially motivated attackers? To defend against "digital vandals" who would damage systems but not profit from them? To defend against widespread grassroots attacks if an attack is published publicly?
Re: $36k Google App Engine RCE
#75Earlier quoted context omitted.
I have not and I haven't been looking for one either. I'm not quite sure what you're getting at here. If you're trying to point out that I haven't done my homework on this and that I don't have a sufficiently specific/workable plan how to approach it - that is accurate. I don't have exploits to sell. In my previous comment I already stated the assumption that I made, if you feel it's incorrect, which clearly you do,…
Sorry, I'm interested in anyone's response to this, since the HN community reaction to any price paid in a bug bounty by a big company always seems to be "people can make more money on the black market". Rather than recapitulating all the previous debates about why that's not true, I'm interested in seeing someone --- doesn't have to be you --- work their way to an educated guess at a black market price for a bug lik…
As for the black market price - I don't consider my security background sufficient for my guess to be anywhere near educated enough, so I'm bowing out.
Re: $36k Google App Engine RCE
#76It would be no skin of Google’s back to multiply these bug bounties by 10, and they should.
But that's would be counter to their interests. They want to hire this kid when he graduates. If they paid 10x their current bounty rates they'd have paid over $400,000 to him in the last couple of years of his free time . That's a great way to never be able to hire him.
Re: $36k Google App Engine RCE
#77Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.
> a student from Uruguay who worked with Sugar Labs. Sugar Labs is the organization behind Sugar, the operating system for the [One Laptop per Child] XO-1 which the Uruguayan government has distributed to public primary schools. The XO-1 was Ezequiel’s first computer.
> Ezequiel’s curiosity in computer science was piqued when a technician came to his school to solve a simple bug that was affecting most XO’s. The technician used the command line which, up to that point, Ezequiel thought was useless. Realizing that the command line offered him a lot of power, Ezequiel began his exploration.
Re: $36k Google App Engine RCE
#78Earlier quoted context omitted.
Sorry, I'm interested in anyone's response to this, since the HN community reaction to any price paid in a bug bounty by a big company always seems to be "people can make more money on the black market". Rather than recapitulating all the previous debates about why that's not true, I'm interested in seeing someone --- doesn't have to be you --- work their way to an educated guess at a black market price for a bug lik…
I understand. I did in fact believe that this applies to any highest reward RCE vulnerability, thanks for pointing out that this may not be the case. As for the black market price - I don't consider my security background sufficient for my guess to be anywhere near educated enough, so I'm bowing out.
Re: $36k Google App Engine RCE
#79Earlier quoted context omitted.
You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/
Wow, a digital arms dealer. How is that they have not been destroyed or captured by someone's military?
There are, of course, real brokers who will buy zero-day vulnerabilities for use by national IC's and LEO's. Their names don't get around like Zerodium's --- Zerodium sponsors conferences --- but they're not hard to find.
If you've got the kind of bug that these firms buy --- essentially, clientside RCE in hugely popular platforms --- you can probably do better selling to them than you can by collecting bounties from the vendors directly. It takes some moral flexibility, though, since really what you're doing is profiting from other people's exposure, and, especially with mobile clientside RCE, what you're really really doing is getting dissidents in Western-friendly dictatorships imprisoned. But you can do that.
But none of these firms (that I know) buy one-off vulnerabilities like a GCE RCE. All the vulnerabilities with high market values have half-lives, which is to say that even after they're patched, it will take weeks, months, or sometimes even years to see them eradicated, which gives them the residual value that props up their market price. In contrast to that, a GCE RCE that was actually exploited would be detected pretty quickly, and shut down with finality in a matter of hours.