So is this person upset because Microsoft wouldn't patch the bug? Or that they didn't want to pay for the information?
Comments seem to reference Apple pays 25k for this type of info.
Can anyone with background give some context here?
So is this person upset because Microsoft wouldn't patch the bug? Or that they didn't want to pay for the information?
Comments seem to reference Apple pays 25k for this type of info.
Can anyone with background give some context here?
The author's blog is also full of anti-social comments, which would sound awfully melodramatic if I didn't have personal experience with depression. Regardless, it is a public expression that she's going to be a fairly toxic person to work with, which is almost certainly working against her in the job hunt.
https://twitter.com/SandboxEscaper/status/103411618937352192...
https://twitter.com/SandboxEscaper/status/103411292604562227...
EDIT as @dixie_land points out, it appears the author is open to selling indiscriminately.
From her website - http://sandboxescaper.blogspot.com:
> I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas".
- - -
w.r.t. the 0-day release: Well that's some seriously irresponsible stuff right there.
I think she has a tough time (she's transgender and doesn't have support from her peers). It's sad that she hasn't found a way to live a happy life although she clearly has serious skills. I hope she'll be fine.
It's just annoying that a lot of users are now at risk, I hope the patches will be installed ASAP.
Is selling an exploit to a foreign government even 100% legal? (Serious question; that seems like the sort of thing that could get one in trouble.)
Exploit development security research is something that there's a surprisingly small market for... unless you're selling vulns. And buyers are usually either government intelligence services or organized crime (skipping right past "what's the difference hyuk hyuk hyuk").
Doing the work first and selling it later is always inherently risky, be it writing a novel or bug hunting.
It sometimes can be perhaps slightly less lucrative than you might expect, with your average pen tester paid significantly less than your average SWE. And often somewhat different than the kind of specialty skills someone focused on (say) Windows Internals might have. Compare with selling exploits, where a month's worth of highly enjoyable work might turn into mid-five-figures. Or higher.
You're absolutely right. Penetration testing and code auditing are ways to make money. It's possible that there may be some relevant differences in both subject and compensation is all.
Companies, such as companies that sell surveillance software to governments, do hire people to just find exploits, but judging by leaked emails that can be a stressful job as you are expected to regularly deliver new exploits.
> I think she has a tough time (she's transgender and doesn't have support from her peers)
This is from her website, I don't like armchair-psychoanalysis, either:
> I'm also transgender. But my transition so far has been really difficult (social isolation, lack of support.. etc), my voice is still really manly and I don't really pass at all (which probably weirds people out.. so I would rather say it upfront so I don't need to have anxiety about it, I have alot of anxiety issues). I also have not been able to change my name yet, legally its still "Thomas".
from http://sandboxescaper.blogspot.com
Seems I was the only one who clicked on her website. The first question I've had in my mind: "What does this person feel? It's weird to publish 0-days on Twitter with a little bit of rant"
For the downvoters: Would love to know why you downvoted me. Maybe I can clarify some aspects.
Many people I've talked are in favor of full-disclosure and think that coordinated disclosure is long term dangerous as large companies with the resources to actually develop secure software are not sufficiently incentivized to do so under coordinated disclosure.
Edit: I've also noticed on HN that sometimes I will get downvoted really hard for no clear reason and then two weeks later HN will magically transform my downvotes into upvotes. Not really sure why that happens, maybe a wave of bot banning?
Yup, I've seen this more recently but now the cycle is faster. My comments regularly get downvotes but then later in the evening they turned into upvotes.
Also back in Dec 2017, there was a huge wave of people shilling on reddit for ICOs and subreddits would regularly post what "HN users think" and "how to correct them".
I'd like to also point out that there is a very real cabal of HN nicks that is actively doing drive by downvotes on specific topics centring around LGBTQ+, immigration and ICOs.
I started seeing this back in 2014 and it correlated with the rise of r/the_donald. There are even amino groups that specifically coordinates such attacks. For instance, the Damore threads were really interesting. Within the first few hours of posting there were a lot of comments seemed off for HN userbase, defending trump and Damore's manifesto. Counter comments were flagged and downvoted.
We know reddit is under the influence of shills and HN is not exempt.
If this is the case, which I can see how it could be, then this is the bigger story for those outside of Tech circles to understand.
1st link -> http://archive.is/8xh4z
2nd link -> http://archive.is/KGyCf
and
> Will sell to people in the eastern hemisphere too. I just want money so I can travel.
EDIT: Did not realize selling bugs outside of bug bounty programs and related bug programs was a normal thing. Now I know.
As a transgender person, this is all that happens in our lives to be honest. It's very tough to have anything but a 'rough time' when the general public views you weirdly, and your family/friends have completely abandoned you.
>Travel blog of an evil transgirl
First post talks about her transition slightly.
Not impossible and not necessarily excusable. Just... difficult.
This is really accurate. I've really had to work on making good decisions and working on some slight anger issues during my transition after pretty much all of my family abandoned me, a lot of my friends started making fun of me publicly or just abandoned me totally. It's a significant reason why I moved across the country to Seattle -- a more open and accepting area of the USA -- to make new friends and get a job that was very open to LGBT persons. It's still tough, but the life change, surrounding myself with people who support me, really helped.
Researchers sell bugs all the time. Whether to a bounty program, a broker, a carder forum, etc, it happens all the time.
Nobody is going to look down on her for admitting to doing what some people do for a living.
Would you prefer she works for MSFT for free or "responsibly" works with Zerodium so that the Feds can get their hooves on the bug first?
It's perhaps possible that some people, in some scenarios, might be willing to compromise on the ethics of their situation in exchange for a significantly higher chance of a much, much higher payout.
EDIT:
To expand slightly, anyone in a position to pay out for bug bounties should consider carefully what they are willing to do to shift incentives towards ethical behavior. The ability to attack your systems is worth money to those who would do so. It should be worth more to you than to them. How much are you, hypothetical person making such choices, willing to spend?
It's perhaps unfair to expect highly skilled people to take a 90%+ discount on the value of their work in order to be more ethical. Ethics are incredibly important! But it can be difficult to argue that successfully in the face of a breathtaking ask.
Right now bug bounties seem mainly to serve as a way for skiddies in the third world with burp to make for-them-bank on trivial XSS vulns and for serious professionals to make a little extra money. And, y'know, to serve the PR purpose of being able to say you have a bug bounty program.
Example job that I posted: https://news.ycombinator.com/item?id=17442484
Somebody like SandboxEscaper would qualify technically, but I have a feeling that running off randomly to foreign countries and hinting at a possible suicide would be disqualifying. The government frowns on that sort of stuff when sorting out trust issues.
Some companies have policies that don’t allow you to sell them while employed there (it’s awkward when your employee sells a bug in software sold by a client/partner/competitor/supplier), but they wouldn’t generally blacklist anyone who had sold bugs in the past.
Not all 0 day vendors are shady either. At an old employer, we were authorized to purchase 0 days with company money to use during penetration tests because they wanted us to emulate state-sponsored attacks. The vendor had a website for their company and customer support as well. Immunity Canvas also has an optional subscription for 0 days you can purchase to use with their framework.
Many security researches voluntarily have decided on a moral level that they care about general security welfare most of all and that following specific standards and timelines of disclosure will maximize that, but even with the same goal reasonable people can disagree there too right up until full disclosure immediately. Some are just paid for that, because like open source an organization might decide that better security overall will ultimately be good for their bottom line (like Google). And some people just want fame or to put food on the table via their unique marketable skills, which is their call too.
Most people that publish play with fire but have learned some boundaries making it somewhat safe.
[1] https://www.eff.org/issues/coders/vulnerability-reporting-fa...
Selling 0days for profit isn't the issue. The more pressing issue, considering she seems to be desperately looking for an employer, is that she has aired her life openly, honestly, and unfiltered through the same channels as her professional work. Sorry, but any serious employer isn't going to hire somebody who is openly unstable, especially not the "suicidal/disappearing for months at a time" unstable.
I'd recommend reading the rest of her twitter posts, plus the content she has published on her website, to get a better idea of her character. While she has a moderate amount of technical ability in her specific niche, it's nowhere near the level that would justify hiring past all of the red flags.
It's unfortunate, but she really needs to re-invent her online presence by decoupling her severe emotional issues from her showcased professional work.
I'm curious why you made such a post without knowing the industry?
Some level of assumption is often required to efficiently converse, so we just have to accept that occasionally the assumptions are a little more off base than we would like.
From her blog last week
http://sandboxescaper.blogspot.com/2018/08/my-greatest-ambit...
As in, this person wants the opposite of everything being stated, and they're frustrated to the point of saying "of course I want everything to be going as badly as it is". I honestly don't read this any other way.
On that note, I think my comment was at 2 before; it's at 0 as of this reply. Heh.
Some people that held a senior position in major companies before transition ended up as cashier or in similar jobs afterwards.
Limits jobs at the big 4/5 as nearly every job that involves security research/RE will inevitably still have the standard leetcode algorithms whiteboard interview, but there's plenty of other stuff out there if you're willing to put together a decent portfolio. The few exceptions to that are being so famous you can make it to recognized teams, but that isn't a realistic goal for most engineers.
If there's a company you really, really want to work for, you can responsibly disclose something to them and at least get an in-person. Skip the phone algorithms test and go right to the whiteboard! Heck yeah.
1) Jump through a surprising number of hoops to set up a Windows 10 Insider channel machine, reproduction on which is required for their security program.
2) Email a write-up and PoCs to their security address.
3) Get back two emails naming a point of contact and dumping a pile of legal agreements they expect me to follow just for reaching out to them.
4) Receive no further contact or indications of progress.