$100M in bounties paid via HackerOne to ethical hackers
bleepingcomputer.com
bleepingcomputer.com
Not by HackerOne per se but the companies using the platform.
A better title would be “$100M in bounties paid to ethical hackers by companies via HackerOne”.
To be fair, the original message on Twitter reads much better than the title of the article:
> HackerOne is proud to announce that hackers have earned $100 Million in bug bounties by hacking for good on our platform.
I was on both sides of this: leading the security team at a company paying bug bounties via HackerOne and also reporting security problems to other companies as a freelancer. To be honest, the experience was always bad in both cases. I wasted several hours triaging bugs reported by “hackers” that often disregarded the conditions of our bug bounty program. People reporting the most trivial things and we would have to pay them anyway just to move on, otherwise they would end up ranting for days.
On the other side, as a bug bounty hunter, the experience is also awful. One of the biggest problems is the fact that you have no way to know if other person has reported the same issue, so you spend hours if not days documenting a vulnerability and creating proof of concepts (PoC) and it is only after your submission that you get a message saying “closed: duplicate issue”. Add to that all the back-and-forth trying to justify more complex issues that are slightly more difficult to prove without damaging the system you are testing.
I am glad so many companies and people are still onboard with this service, but I wouldn’t blame anyone for closing their account after all the bad experiences I had.
Yes. I would say 2/3 of my reports were resolved this way. Sadly I can't fault either HackerOne of the company -- I don't see a viable alternative.
The "fair" thing here is probably to split the bounty among the discoverers, but that's not going to happen either.
The core issue is not the reward division algorithm, it's the inherent lack of visibility. One solution here would be to just open all reports after a while, but this creates problems of its own. One is that it gives ammo to people engaging in dishonest or clueless PR. Another is that some researchers don't actually want visibility, because their employers have murky rules around such engagements, or because they have some far-off disclosure timeline in mind (as a part of a presentation at a conference, or whatnot).
Probably also need stiff penalties for insiders who might conspire to notify others of bugs and split the pay out.
As far as not doing it. At some point critical industries may be have to be regulated to force them to behave responsibly.
Or a mechanism for companies that use email to register the researchers submissions in HackerOne. The details will be sealed and non-public, with researchers having no way to know it exists unless the company provides a link to it as proof of work. HackerOne thus acts as a kind of notary against accusations from researchers that it wasn’t really a duplicate.
And some payouts are 10k, I’ve never even heard of $50 minimums, I thought it’s either $100 or swag.
Out of curiosity, why shouldn't they? Is it because they then end up with a lot of garbage/spam submissions to sort through from people hoping to trick the company into paying out a bounty?
As for the problem of spammy submissions: charge a small nominal fee of $10 or so to submit, with a full refund if it’s a legit issue (even if it’s a duplicate).
Maybe that's a little farfetched, though.
Another scenario is someone does what you suggest after finding a real vulnerability, to waste the teams time while they exploit the real vulnerability.
Not a perfect fix, but I think it helps.
One potential issue: someone on the Mozilla team could pass some of these on to a few friends who then claim some of the money.
It's not a major likelihood, unless the bounties are numerous or especially large.
So long as there is a big of lag before confirmation (which, in practice, there already is), the vendor would know about the issue at least several days in advance of the black-hat even getting a hint and could hopefully patch it in that time.
For especially big holes, just take a bit longer than usual to get back to people until it's fixed.
The problem is that you can just tell all your friends to file the same bug, and now they have to pay everyone?
sounds these "hackers" have an incentive to be stubborn over non issues
The companies that consistently publish their bugs have a good track record of giving appropriate bounties. I don't see a clear incentive for a company that doesn't allow their bugs to be published, to be anything other than stingy. Computer security is a cost center for a business, and the folks managing the bug bounty program have a clear incentive to minimize their costs, while maximizing the bugs found.
I think a potential solution would be increased bug disclosure on platforms like Hackerone. Currently, a company has to agree to disclose the details, and most never do. Openness allows hackers to vote with their feet, and spend more time on the companies that are easier to work with, both in bounties rewarded, and easiness of the reporting process.
Whatever the scale is, companies have no incentive to avoid paying them, because even at the high end of the scale the amounts are immaterial. Remember, we're talking about H1 bounties here, not the Apple and Google platform bounties, which are totally different animals.
The real risk companies that run bounties face is that their programs won't generate any real bugs at all, but will absorb costs from both the platform and all the nonsense bugs they have to triage. New serious bounties are good news, not bad news, for most bounty programs.
(I've managed several, continuing until recently; before I did, I went around talking to people who ran them to get the lay of the land. I'm pretty confident in my answers here.)
The issues I've personally experienced have been with impact, for bugs outside of the very traditional XSS/SQLI/RCE. I've gotten things along the lines of "yes, our _______ is seriously broken, but it's not/barely a security issue," with an explanation that stretches plausibility. Maybe I'm full of crap, maybe they are.
I'm sure those running bounty programs would have all sorts of folks contesting things that aren't actually real bugs. I think the only real good solution is increased visibility on all sides. That way each of our technical arguments can stand on their merits, whoever is full of crap can get called on it, and others looking for bugs can choose where to invest their time (glossing over that solution missing a bunch of thorny implementation details, I'm sure).
I've heard rumors of people selling exploits for this company on the black market for more money now.
They simply don't take no for an answer.
(Tangent) Can anyone recommend a coherent interpretation of that statement?
I know what it means for an individual person to be proud. And I could see an argument for extending that notion to a group of persons if every person in the organization was proud.
But I assume HackerOne has had employees / members come and go over time. And I also assume that some of the past or current members don't share that feeling of pride for this particular milestone.
So the only interpretation I can think of is that the person writing the PR was being sleazily vague. I.e., trying to get the audience to take a sentiment that's only meaningfully applied to individual humans / animals, and getting them to unwittingly apply it to a brand name instead.
Is there a better explanation that eludes me?
From my end, there are a lot of trivial things I have to go through where it's low effort on the researcher end (And I've even had automated searches where the researcher has sent mails to us assuming we'd have the same issue because of some similar HTTP Header or something similar). Thankfully I've gotten faster at keeping these out but it still takes up more time than needed.
From the researcher end, I assume it's frustrating where they put in the effort to craft a well documented mail and I have to inform them that it's a duplicate or known issue that we are currently working on a fix for. It's a hard call and I'll often have to use a judgement call on these. But it's made harder still when I'll suddenly see an issue that has existed for a long time be reported by a single researcher. And then in a matter of two days 3 to 4 other researchers will pop up with the exact same issue leading me to believe that either there's different accounts under the same name, or some kind of researcher group that works together in sharing findings (And maybe bounty).
Basically, I'm not sure how much this is a HackerOne issue vs a general bounty program pain ¯\_(ツ)_/¯
You also have to be aware of policy changes. I've noticed companies remove language that told how much they'd pay out. Some companies have a mandatory pay out of 7-14 days but they are rare; with everyone else, you just have to hope they pay you, and they do, I guess... whenever they feel like it.
They closed one of my reports for being a "denial of service" attack when it was a crash caused by malformed input. I've also heard of others having the same issue.
Sounds like you have a crash that you think might be exploitable- in that case, consider saying "memory corruption triggered by malformed input" to make it more clear that the crash isn't the point.
cool, posting my PoC on pastebin then
I'm honestly envious of their community and all of the tools they've created and tutorials and everything for newcomers. They've done a great job getting anyone who is remotely curious the ability to dabble.
When I was coming up as a sysadmin "rtfm."
Anyway, are people making lucrative careers out of bug bounties? What do these "infosec CEO" twitter people do day to day? Their goal is to hit bounties and sell pentesting/exploits I assume?
There's a strong power law distribution - the top folks make a lot of money (say, > $500k/yr) and then it quickly drops off from there.
Unless you’re talking about private exploit sales, which is totally different.
And I'd hope we are only one of their many clients. We might be an outsider though, my company does very well to address the bugs that are brought to us fairly. We understand the need to encourage the top 100 researchers on the platform an incentive to look over our stack. That's where the value is.
We do get a lot of spammy notifications too which sucks but it's part and parcel with the issue mentioned here. We leverage BugCrowd to help filter the chaff from the precious metals. :)
As of that date, 6 people made over $1M total since it launched (not per year). So maybe 1 or 2 have hit 500k in a year? Some of those names have been doing it for over 6 years.
According to a previous report, only 0.3% have made over $5k in their lifetime on the platform.
https://duo.com/decipher/taking-hype-out-of-bug-bounty-progr...
Any suggestions where to start? I'm several years out of the scene and would love to be reacquainted.
Then there's hackthebox https://www.hackthebox.eu/ I haven't used this yet.
Mostly I just grab stuff off of twitter/reddit, I don't really know who to recommend right now, I kind of just followed a ton of relatively random open source infosec people organically, but none really scream "has guide for diving in or is a great intro person" off the top of my head.. (maybe @troyhunt), https://www.reddit.com/r/netsecstudents/
Hopefully someone else can chime in because I'd like to know more as well.
On the YouTube side for people who are a bit more casual like me, John Hammond and Live Overflow both seem pretty good for beginners.
John has a bunch popping up on my feed where he runs through a CTF or hacking room and steps through his process, like this SQLite timing attack (https://www.youtube.com/watch?v=DYLDG_2Vs3E) which I found interesting since I knew the concept but hadn't seen it in action before.
Live Overflow also explains things pretty clearly and has covered a variety of topics like using Ghidra, hacking an intentionally hackable MMO, or recreating patched XSS flaws.
I think it's really good to pick a niche first and stick to it, reverse engineering code looks fun but I'm not sure how commercial that skill is compared to busting open web apps.
If you want something to poke and prod at there's also Damn Vulnerable Web Application (DVWA) at http://www.dvwa.co.uk/
Hack the Box Try Hack Me Pentester Lab Hacker101 Portswigger Web Security Academy Linux Academy Bugcrowd University Hacksplaining Cybrary Malware Unicorn bugbountyguide.com CTFtime root-me.org MalwareTech Nahamsec The Cyber Mentor
I'm pretty sure a reasonable number are doing quite well for themselves after currency conversions. It would be quite challenging to replace a typical Bay Area security architecture salary with bug bounties, though. Few people are equipped to find and claim $10k+ bounties twice a month, every month.
Infosec twitter people aren't the ones doing bug bounties. A lot of them are blue team cybersecurity, doing network engineering and IT, or do penetration testing for networks which is a different wheelhouse. Some of them might be reporting exploits to Zerodium/ZDI/other exploit brokers, but they keep a low profile and it is very different from "bug bounties".
It's 95th percentile for a lead developer in the UK... and probably everywhere outside some areas in the US.
This was admittedly a few years ago. No idea if that's still accurate.
Not really, no.
Sure, the top 20 hackers on H1 do make a very decent living (you can listen to the story of Dawgy-G on Darknet Diaries ep60 about that). But realistically, if you are that good at it you can get paid much more doing a 'real' infosec job.
Bug bounty hunting platforms like H1 do give you the freedom to work whenever you want, wherever you want on your own terms. Basically gig economy.
Personally I do bounty hunting every now and then because I enjoy the learning experience from it. But looking at the time it takes me to discover a bug and writing a detailed report only to receive a couple hundred USD for it, it really isn't worth my time in a professional sense.
I'd say I make about 25USD/hour from it. Of course this is highly dependent on your skills. And it is also highly dependent on where you live whether 25 USD/hour is actually enough to make a living.
Sometimes you can get lucky and stumble upon a valuable bug and make a couple of grand for only an hour worth of work, but most of research you'll do will yield you knowledge, not money.
It's questionable if these companies are getting massive value for money if most of the bugs are oversights rather than intricate flaws in a bespoke process.
https://hackerone.com/try_to_hack?filter=type:bounty-awarded https://hackerone.com/mlitchfield?filter=type:bounty-awarded
The only other publicly disclosed signals for market price come from third party companies and state actors.
The other signals are not public and hard to quantify, they come from trying to weaponize and monetize exploits yourself. This results in potentially incurring various forms of liability, or reducing that by selling information to a different broker, who will eventually find someone to weaponize or monetize a piece of the exploit. This part is a much more efficient market, but it is not vertically integrated.
The prime bug bounties seem to be trending upwards in value, with the bottom being crowded and with non-serious companies testing the waters.
Does anyone have any ideas to make the value of bug bounties be more dynamic and elastic, trend upwards towards their true value inline with the growth of the sector?
Perhaps it will become more stable when people realise you can sell negative results as well (either implicitly by cooperating, or through an actual market). Anything that can bridge the gap between hackers wanting to get paid for their efforts and companies wanting to pay for results would help.
More volume would also help, in the end it's hard to sustain a whole industry on just tens or hundreds of millions per year.
Good thing I never said that. The market is inefficient. I like that idea of monetizing negative results. More transaction volume generally helps, I think external market signals and their actual value are whats really missing.
Like, how much would someone pay for an exploit should dictate how much a company should pay for letting a crowd try to fix it where only one person/group gets the payment. If there was a way for additional participants to get paid for bothering to look at all that would be helpful too, and different people can focus on how people try to game that instead of worrying about the idea of people gaming it.
An unknown person finding a vulnerability has clear value, but a negative result from an unknown person doesn't mean much.
The good/dangerous bugs require creativity and deep system knowledge to find, which is hard to trust that an unknown person has.
It is sexy and all to sell "we hacked you using emacs through sendmail by the moon phase exploit that happens every 2 months". But really how many people will be able to exploit that? My company is not target of a state sponsored actors. Automated tools, checklist evaluation and decent administrators will be good enough for most of companies. Ordering pentests from time to time is good practice to check if administrators are doing their job as in "trust but verify".
Trust is easy. You either have a proof of concept and can show impact in your report or gtfo basically.
The reality is probably that 80% of the vulnerabilities disclosed on bounty platforms just aren't worth that much. Certainly: companies that lack security expertise but manage bounties tend to radically overpay bounties; I'd of course be curious to see a breakdown of that $100MM by bug class.
Could you share your reasoning on this? Are you saying they're overpaying for a low threat type of vulnerability, have a large number of vulns that should have been caught earlier, or something different? Genuinely curious! Thanks
Yes this is true.
> and you wouldn't have gotten it without the bounty
Of this I am highly skeptical. Most companies that I’ve worked at who don’t have bug bounty programs get the occasional serious report. These reports were submitted to companies before bug bounty programs were even thought up. Bug bounty services just seek to capture value from something that was happening long before they were invented, and I’m highly skeptical of them having a significant impact on generating serious reports that otherwise wouldn’t exist.
The other issue is that everybody has a finite security budget, and dealing with the spam is going to (perhaps significantly) eat into that. In those cases, it’s taking money that could be spent on something with a decent ROI, and redirecting it to essentially just creating busy work for your security team (or spending their budget on paying somebody else to do that busy work).
I think they really only exist because a lot of security professionals don’t really know what they’re doing, and a lot of their employers don’t really know what they’re supposed to be doing.
It's also a refrain I got from almost everyone I asked about running bounty programs.
A fundamental truth I don't think anybody who does appsec assessments professionally can escape: multiple audits of the same target will turn up different bugs. It happens even if the same people do both assessments! I've never talked to a software security professional who pushed back on this; maybe you'll be the first.
I completely agree with this.
> I watched it happen, several times
I don’t doubt you have, but this is anecdata. I wouldn’t want to draw any conclusions from this, especially because it conflicts with a lot of my own anecdata.
Auditing/security testing is something you could infinitely devote incrementally more budget to, and infinitely receive incremental returns from. While I question it provides as much benefit as you’re describing, it can certainly provide a benefit. My issue with it is that, in my experience, it has always had a bad RoI. The resources that you have to devote to dealing with the spam make extracting any value from bounty programs a very expensive exercise. I’ve personally seen people devoting more than one day a week to managing bounty programs that they were lucky to get one good report per year out of. Imagine how much more value they could have gotten from having a security engineer spending a full day per week threat modeling with the product engineers.
Perhaps the ROI is different if your department is over-funded, or if you have a big brand that people want to write self-promotion blogs about. But any time I hear a security professional parroting the importance of bug bounty programs, the cynic in my wonders whether they’re just looking for some low-skill busy work for themselves.
The reason: Bug bounty is fundamentally favoring the companies that sign up. They pay next to nothing for getting a lot of eyes on their site and here and there a valuable find will be made.
Rewards should probably be much higher, like 10x I think to attract better researchers.
Also, the latest invention of private programs, where testers aren't even allowed to talk about it or share finds after is a joke as well - it's all just in favor of the companies. The basically buy the researchers silence, e.g. they can dismiss a find and don't pay and just say oops duplicate.
For someone skilled and interested in infosec there are better ways to make money.
These free-for-all bug bounty programs are a drain on resources that could be better spent elsewhere
The real value hackerone and similar should be providing is filtering out the time wasting reporters and the vendors who slow roll on reports - but they do neither of those
If someone’s ethics is to maximise chaos, then a full disclosure on 4chan is _technically_ the _most_ ethical action for this person.
https://www.hackerone.com/lp/resources/2020-hacker-report
I've looked through it and there's some nice information on how hacker industry emerged and grew into what it is now, talks about money earned by ethical hacking as well.
It's still illegal. Besides, planting a bug and solving it would still involve faking version control records to insert the bug.
You might be able to get away with it once but the bean counters wouldn't let you fool them twice in that regard. Unless you had a guy on the inside etc. but it's turtles all the way down.