The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…
Stealing Facebook access_tokens using CSRF in device login flow
81–89 of 89 posts
Re: Stealing Facebook access_tokens using CSRF in device login flow
#82Re: Stealing Facebook access_tokens using CSRF in device login flow
#83Re: Stealing Facebook access_tokens using CSRF in device login flow
#84Earlier quoted context omitted.
I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…
Why would you calculate hourly rate? I'd rather try to calculate the economic impact that this could have for the company, especially marketing costs to repair bad PR if something like private messages, pictures, info, etc. get breached. Do you think Facebook would spend $5,000 for that? Hell no, marketing budgets are in the magnitude of millions of dollars... I'm in no way supporting to exploit these vulnerabilities…
Would it make sense to award bonuses to every in-house security researcher based on an estimated, hypothetical worst-case cost? It doesn't take much imagination to see how that reasoning applies to other positions. Do accountants get big bonuses for avoiding multi-million-dollar errors? Lawyers for avoiding costly lawsuits? Operations (IT and otherwise) for keeping infrastructure running? Customer service for assuaging disastrous public interactions? Stretched to absurdity, would you pay for a taxi based on how badly you need to get to point B?
I believe saying "preventing these kinds of problems (doing this work) is what we pay you for" is a reasonable conclusion and paying a market rate for that general value makes more sense versus calculating a kind of commission per individual contribution. That does have a certain appeal (and I wouldn't mind seeing a discussion about it) but I haven't gotten the impression that's the perspective of those who think all* bug bounties should be higher.
*: Added caveat as I'd bet every researcher can name companies that pay poorly
Re: Stealing Facebook access_tokens using CSRF in device login flow
#85Earlier quoted context omitted.
I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?
No, there isn't. Even the people who participate in the grey market for exploits (sales that aren't overtly prohibited by law and for which participation would be unlikely to make you an accessory to a felony) are very quiet about it. But, a good starting point might be the analyses people have done on the Hacking Team leak.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#86The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…
Re: Stealing Facebook access_tokens using CSRF in device login flow
#87Earlier quoted context omitted.
I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?
I don't know much about it tbh. tptacek and a few others have spoken extensively about bug bounties on HN. I'll try and dig up a few of their past comments. Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very…
I have heard many instances where it isn't the case (some bugs are often being exploited for months before the company finds out)... and you probably did too... but anyways, as an example, you don't need a lot of time to copy lots of data...
Re: Stealing Facebook access_tokens using CSRF in device login flow
#88Earlier quoted context omitted.
> Is the value of a sledgehammer equal to the value of a car? My previous post was poorly worded; I didn't mean to imply equality. To use your analogy, valuing a serious vulnerability on a platform that has 1.65B users in the $5-10k range is tantamount to selling a 30lb sledge hammer for a dollar.
But what if producing a sledgehammer only cost 50 cents? Then people would sell sledgehammers for a dollar or less.
Obviously exploit pricing is generally efficient and adheres to free market principles. That said, it's hypothetically possible that an exploit against a large tech company could sell for far more if the circumstances are right, considering the price to damage ratio is so skewed in addition to the unique nature of each exploit.
Therefore, large tech companies don't really have much to lose by paying far more than they currently do on bounties.
Granted, eliminating what's largely a hypothetical edge case is not the primary benefit to paying higher; incentivizing far more white hat researchers is.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#89The black market is a false dichotomy. Either you need the money for your work, then negotiate a reasonable price, or you don't, then disclosing it for free might actually helps someone not to be lowballed by BigCo the next time. There really should be a bug marketplace, instead of one side having all the power and paying pennies.
Markets aren't magical. They route resources, they don't create them from thin air. If Facebook is ultimately the only organization that realizes $5000+ in value from a vulnerability, then no matter how you structure the marketplace, it isn't going discover a higher price for that flaw. If you believe otherwise, you're missing a business opportunity. Go create a "bug market" for Facebook and Google serversides. It's…
However I do believe saying you discovered a pretty serious bug by putting it on a market sends a strong message. Your system is vulnerable and you are too cheap to pay up.