Of course the programs aren't going to be a replacement for real product security teams, but they were never meant to be.
When setting bug bounty payouts, the company should be looking at what security researchers are likely to get when selling an exploit to criminals, not the actual extortion dollar amount (assuming that most security researchers are not willing to personally engage in illegal activity themselves, which appears to be the case).
However, when evaluating the value that a bug bounty program brings to the company, they should absolutely consider these typical extortion amounts.
This doesn't strike me as a very accurate assessment of the situation. There are already markets where people can buy and sell exploits: researchers don't have to get their hands dirty to get paid for their exploits.
I'm saying that the market value of actually performing an illegal act of extortion is higher than the market value of a zero-day, either on one of these markets or via bug bounty.
I'm arguing that the price is different because of the risk of getting caught and going to jail, not that there isn't a market for security researchers to sell exploits to criminals without otherwise getting their hands dirty.
That being said, I still think bug bounties are too low, even when risk adjusting.
Taking the certain $10k is the better deal over hunting for a shady buyer on shady sites who might send you some bitcoin if the deal even pans out or if they even pay. That's a lot more work and uncertainty while they act like it's just the choice between which lever to pull. A bird in the hand…
I recently found a compromised server on a university's network. I wasn't going to cold call them to report it because I had no idea how Betty answering the phones would react. Instead, I sent it to an IT contact that I knew personally. I knew that he didn't have anything at all to do with this, but that he would know who to get it to.
If the .edu is one of their 668 member institutions [1], they have designated security contacts at the .edu that they can directly get in touch with -- and, in many cases, can even wake somebody up at 3 a.m., if/when it's warranted!
Even if the .edu isn't a member, though, they'll almost certainly have an easier time getting in touch with someone with a clue that they can pass your report along to.
---
To explain, generally speaking a bug bounty is going to the smaller of:
1. Cost of Discovery since that is the amount someone would be willing to find bugs at otherwise they are losing money on each bounty they get.
2. Cost of Damage (risk-adjusted) since that is the most a company would be willing to pay.
The reason for this is that as long as the Cost of Discovery is lower than the Cost of Damage (up to ROI), it is reasonable to keep paying the Cost of Discovery since you are paying less than the risk-adjusted harm. But, there is also no point paying significantly more than the Cost of Discovery as long as people keep reporting problems as fast as you can fix them since there is no real reason to pay to get more problems than you can fix. So, to first order the bug bounty for a certain type of problem reflects the cost of discovery of that type of problem.
Circling back to the original point, we see problems that can cause millions in damages getting bug bounties on the order of $10K. This means that, to first order, million dollar attacks only cost $10K to execute which results in a crazy high ROI in the 100s. With an ROI in the 100s, it should be no wonder that such attacks have been increasing in frequency given their sheer profitability. The fact that bounties are so low for such critical problems is a major indictment on the prevailing level of security in the industry.
This is probably the biggest issue in terms of incentives to a researcher. You're either finding the bug by accident or out of curiosity, or you stop short of basically losing money you would otherwise earn going a paid audit.
500K once every 20 years or less beats 50K annually handsomely. Never mind the fact that once you lose control of your data you can never be sure you got that control back, that's somebody else's problem.
People are not very good at threat modeling, estimating chances of things happening to them and estimating the damage resulting from an incident. We collectively are not good at ensuring that the companies where these things happen get dealt with properly.
Bitcoin isn't the issue here.
When you have the pressure on the target, you can make the pay in whatever currency you'd like and there will always be one.
The black hat hacker "ecosystem" has also professionalized from doing it for kicks to doing it for the dough.
Better to throw it to a free market and let people find bugs for peanuts.
That's like saying CVS security guards are pitifully small and inadequate. Yeah, you're right, they aren't going to stop a proper robbery... but stealing is illegal and shouldn't be happening either way. Same for hacking.
If, that is, the burglars could automatically try and burgle every commercial establishment and home in existence, succeeding, with zero effort expended, if the security guards in question were insufficiently vigilant.
It's next to impossible to measure 'sec expertise'. This would only go far if the security expert gave a warranty on their service which we know is never going to happen.
Besides which, the thing that would save this companies is mostly obvious and any half-decent security officer will do them. The difference being buy-in from senior management.
https://www.cyber.gov.au/acsc/view-all-content/publications/...
The attackers also only encrypted about 0,02% of the systems, but the university paid because the attackers threatened to make the stolen data public.
[1] https://attheu.utah.edu/facultystaff/university-of-utah-upda...