Yes. I would say 2/3 of my reports were resolved this way. Sadly I can't fault either HackerOne of the company -- I don't see a viable alternative.
Yes. I would say 2/3 of my reports were resolved this way. Sadly I can't fault either HackerOne of the company -- I don't see a viable alternative.
As for the problem of spammy submissions: charge a small nominal fee of $10 or so to submit, with a full refund if it’s a legit issue (even if it’s a duplicate).
Maybe that's a little farfetched, though.
Another scenario is someone does what you suggest after finding a real vulnerability, to waste the teams time while they exploit the real vulnerability.
Not a perfect fix, but I think it helps.
One potential issue: someone on the Mozilla team could pass some of these on to a few friends who then claim some of the money.
It's not a major likelihood, unless the bounties are numerous or especially large.
So long as there is a big of lag before confirmation (which, in practice, there already is), the vendor would know about the issue at least several days in advance of the black-hat even getting a hint and could hopefully patch it in that time.
For especially big holes, just take a bit longer than usual to get back to people until it's fixed.
The problem is that you can just tell all your friends to file the same bug, and now they have to pay everyone?
The "fair" thing here is probably to split the bounty among the discoverers, but that's not going to happen either.
The core issue is not the reward division algorithm, it's the inherent lack of visibility. One solution here would be to just open all reports after a while, but this creates problems of its own. One is that it gives ammo to people engaging in dishonest or clueless PR. Another is that some researchers don't actually want visibility, because their employers have murky rules around such engagements, or because they have some far-off disclosure timeline in mind (as a part of a presentation at a conference, or whatnot).
Probably also need stiff penalties for insiders who might conspire to notify others of bugs and split the pay out.
As far as not doing it. At some point critical industries may be have to be regulated to force them to behave responsibly.
Or a mechanism for companies that use email to register the researchers submissions in HackerOne. The details will be sealed and non-public, with researchers having no way to know it exists unless the company provides a link to it as proof of work. HackerOne thus acts as a kind of notary against accusations from researchers that it wasn’t really a duplicate.
And some payouts are 10k, I’ve never even heard of $50 minimums, I thought it’s either $100 or swag.
Out of curiosity, why shouldn't they? Is it because they then end up with a lot of garbage/spam submissions to sort through from people hoping to trick the company into paying out a bounty?