Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

81–90 of 174 posts

Re: Beg Bounties (2021)

#81
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

We've had a handful of these that we've paid out for small issues over the years. Things that are _technically_ security issues, but not something that affect us or are exploitable in a meaningful way. $50 a few times a year is stupid cheap to build a reputation of actually paying out security researchers. Among the junk, we've had a few legit bounties submitted. That alone is worth the noise these "beg bounties" cre…

I run a bug bounty program and I don't mind report for small issues. It's true that most report from "beg bounty" hunters are noise, but we've acted on some reports a few time. One time, in particular, a researcher broke something which alerted us to a serious issue, while not understanding themselves what they had found, we still paid a fair bounty on the finding since we would not have found the issue without the action of the researcher.

It also helps that we have very clear rules and defined scope: we've put out of scope the usual suspects and researchers rarely argue when we point out they should have read the rules better before submitting.

Regarding bounties, my yardstick rule is that if a report made us reconsider our practices and change something on our side, then it's worth a bounty, even small. If not, then no bounty far ya, simple as that.

Also, I don't remember getting a disclosure report where they would ask for money before disclosing the vulnerability, I don't think it's that common. Still, this would go straight to the spam folder.

Re: Beg Bounties (2021)

#82
post #30
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[flagged]

Terrorists? Too far don't you think?

Re: Beg Bounties (2021)

#83

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

I’m not sure the BronxWench cares strongly about what people on the Internet think of her. It seems far more likely that they didn’t understand the email from Troy or dismissed it as spam or a scam. They took notice because a bunch of their regulars started getting emails from HIBP. Some of these did understand, and brought the issue to the attention of the admins admins in a way they understood.

It seems far more likely that they didn’t understand the email from Troy or dismissed it as spam or a scam.

That's what happens when there are too many who "cry wolf"; and bug-bounty programs just incentivise that behaviour.

Re: Beg Bounties (2021)

#84

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

My incentives as an employee are similar. Far better to hide a problem than admit and fix it.

That is a sign that you work at a deeply unhealthy company. Even at a moderately healthy company it's usual to have "Don't shoot the messenger" policies in place to avoid blaming developers for doing their job.

Re: Beg Bounties (2021)

#85
post #70
post #61

Earlier quoted context omitted.

Bad behaviour should not be tolerated just because it comes from the third world

Not tolerated but it should be understood . Lots of developers would do morally dubious things for a 'life-changing' amount of money. If you live in a very poor country that isn't a large sum compared to a Western salary.

Understood to be more efficiently dealt with, yes.

Re: Beg Bounties (2021)

#86
post #24
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

Meaningful or not, some companies and organizations don't understand the difference between a CVSS score of 2.0 and 10.0. Being in the cybersecurity industry myself, there is a wide gap of knowledge in the risk of vulnerabilities. Following a some-what standard way of reporting vulnerabilities is well documented. Begging for a bounty is not standard. I also think that is perfectly fine to document the process in publ…

> Occasionally it works for people in developing countries is, in my opinion, a terrible argument for allowing such behavior.

I think the point GP was raising isn't that it's ok, but that it's part of a wider problem and isn't just happening because people are stupid. It makes sense for them because of how the world economy is currently set up. Saying "hey will you just stop please" won't change that fact. Exactly the same thing is true for spam.

Re: Beg Bounties (2021)

#87
Surely "false positives" for security vulnerabilities are better than no emails at all...

    "If you put an email on a website, you will get spam"
- A fundamental law of the internet

Re: Beg Bounties (2021)

#88
A bit off topic: I am genuinely surprised that he gets to blog (regular and micro via Twitter/X) with such a savage style. In many mega corps, even tech, they would eventually curtail this type of blogging. Steve Yegge is a pretty famous example where even Google was trying to curtail his blogging topics and style.

Re: Beg Bounties (2021)

#89

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

I think the principle of charity dictates that we should at least give them an opportunity to do the right thing. Not that this makes it any less frustrating when people take advantage.

Re: Beg Bounties (2021)

#90

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

No criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.
Post reply on HN