Live data from Hacker News

Teen Becomes First Hacker to Earn $1M Through Bug Bounties

digit.fyi

71–80 of 178 posts

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#71
post #41

Earlier quoted context omitted.

With Amazon AWS I had fun exchange a couple of years back. They don't have a bug bounty (still I think), but their response was that they will fix it but not publicly recognize it because "the cloud is always secure"? Go figure.

This is hyperbolic nonsense. Having worked at AWS, I've never encountered a business that is more serious about their security position.

It's not, I still have the email exchange from a couple years back - I thought of posting it somewhere because it was so odd, but I dont have a blog and I am not interested in publicity.

Amazon still doesn't offer a bug bounty program to my knowledge. Also, it's the only cloud provider my active security researcher friends tell me that attempts to regulate them by some weird pen test authorization requirements which are very foreign to industry standards of other cloud providers.

I'm just on the side lines watching, but there is a difference of how transparent AWS vs. GCP vs. Azure are when it comes to security. GCP > Azure > AWS

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#72

Earlier quoted context omitted.

What's a way to learn security work? Genuinely curious.

One of the best introductions to the field is going through overthewire’s bandit vulnerability games. https://overthewire.org/wargames/bandit/ They have 30+ levels where you ssh into a server and attempt to find some type of vulnerability. They start out very easy and get tough quick. It’s very eye opening to see the types of exploits that exist. They also have a set of challenges aimed at serverside web security. ht…

> One of the best introductions to the field is going through overthewire’s bandit vulnerability games.

Never knew about these. I'm visually impaired, so a text-based system like this appeals. Thanks!

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#74
post #33

Pro tip if you are a startup and want free security advice. Just sign up for all the bounty sites and for every single bounty just tell the submitter that it is a duplicate bug and pay them nothing, then hot patch it immediately and when they get suspicious tell them that their bug report had absolutely nothing to do with the timing of your patch. I know there are companies that do this because I have had it happen t…

I mean you're shooting yourself in the foot HARD if you do this because then people start actually hacking you instead of reporting it.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#76
post #68

Earlier quoted context omitted.

People don't even conceive the difference, in Buenos Aires you can rent a great house in a great neighborhood for 800 USD per month, in San Fran you get a shared room where other 3 people live for that much -IF even that-. In SF you spend at least 5 dollars going anywhere and going back using public transport, in Buenos aires $2 is more than enough to go the the opposite side of the city and back.

I know it is that way, but I don't understand it. It always seems to me like it just indicates that the exchange rate is wrong: clearly I can buy more stuff if I convert my money to pesos and spend them there, so the peso is just worth less than the amount we get per euro. Could someone recommend some a website or blog post that explains this? (Or is it a simple enough explanation to fit in an HN comment without goin…

So why haven't you done that, one of the times in the past you've thought this?

All the reasons you haven't are why everyone else doesn't either, so that's why it's the proper exchange rate.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#77
post #34

This is 1MM over 3-4 years, right? $330k is good money, but it's also in the ballpark for gifted vulnerability researchers in SFBA.

SFBA income tax, state and federal, would leave about 55% of that, then, so, as usual, California is expensive.

Income taxes are more like 30% of that. It’s expensive, but not that expensive. Unless you’re counting rent in that, but even then I think half is pushing it.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#78

Earlier quoted context omitted.

To be on the other side of this, we do received unsolicited but welcomed bug and security reports. Some are legit and we pay bounties even if we don't have an official policy and we are an early startup. Others are just automated reports that people copy and paste. These ones are uninteresting, but these people still think they deserve money. Often more aggressively than the legitimate ones.

Can you elaborate on the automated reports a bit more? What makes them uninteresting?

Examples of "vulnerability" reports I've received:

- Dump of CVEs for "Web App X" or "Server X", even though literally zero of them apply to the version that I'm currently running.

- Dumps of port scans with warnings like "Running SSH on port 22 is not recommended" and "Server accepts HTTP. Always use HTTPS".

I assume there are tools that generate these reports because the reports use decent English but the accompanying emails are written in very broken English.

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#79
post #68

Earlier quoted context omitted.

People don't even conceive the difference, in Buenos Aires you can rent a great house in a great neighborhood for 800 USD per month, in San Fran you get a shared room where other 3 people live for that much -IF even that-. In SF you spend at least 5 dollars going anywhere and going back using public transport, in Buenos aires $2 is more than enough to go the the opposite side of the city and back.

I know it is that way, but I don't understand it. It always seems to me like it just indicates that the exchange rate is wrong: clearly I can buy more stuff if I convert my money to pesos and spend them there, so the peso is just worth less than the amount we get per euro. Could someone recommend some a website or blog post that explains this? (Or is it a simple enough explanation to fit in an HN comment without goin…

What makes you attribute that to exchange rate when you can do the same thing with different parts of the US? $800 for a nice house in a nice part of town isn't that far off from prices where I live (Cleveland).

Re: Teen Becomes First Hacker to Earn $1M Through Bug Bounties

#80
post #71

Earlier quoted context omitted.

This is hyperbolic nonsense. Having worked at AWS, I've never encountered a business that is more serious about their security position.

It's not, I still have the email exchange from a couple years back - I thought of posting it somewhere because it was so odd, but I dont have a blog and I am not interested in publicity. Amazon still doesn't offer a bug bounty program to my knowledge. Also, it's the only cloud provider my active security researcher friends tell me that attempts to regulate them by some weird pen test authorization requirements which…

> pen test authorization requirements

Yes, we don't want people to publicize when we fuck up so we'd rather just NDA them to death when they tell us about bugs.

Edit: If you don't accept, we just use the hacking laws in the US to silence you.

Post reply on HN