Of course the programs aren't going to be a replacement for real product security teams, but they were never meant to be.
Of course the programs aren't going to be a replacement for real product security teams, but they were never meant to be.
To explain, generally speaking a bug bounty is going to the smaller of:
1. Cost of Discovery since that is the amount someone would be willing to find bugs at otherwise they are losing money on each bounty they get.
2. Cost of Damage (risk-adjusted) since that is the most a company would be willing to pay.
The reason for this is that as long as the Cost of Discovery is lower than the Cost of Damage (up to ROI), it is reasonable to keep paying the Cost of Discovery since you are paying less than the risk-adjusted harm. But, there is also no point paying significantly more than the Cost of Discovery as long as people keep reporting problems as fast as you can fix them since there is no real reason to pay to get more problems than you can fix. So, to first order the bug bounty for a certain type of problem reflects the cost of discovery of that type of problem.
Circling back to the original point, we see problems that can cause millions in damages getting bug bounties on the order of $10K. This means that, to first order, million dollar attacks only cost $10K to execute which results in a crazy high ROI in the 100s. With an ROI in the 100s, it should be no wonder that such attacks have been increasing in frequency given their sheer profitability. The fact that bounties are so low for such critical problems is a major indictment on the prevailing level of security in the industry.
This is probably the biggest issue in terms of incentives to a researcher. You're either finding the bug by accident or out of curiosity, or you stop short of basically losing money you would otherwise earn going a paid audit.
When setting bug bounty payouts, the company should be looking at what security researchers are likely to get when selling an exploit to criminals, not the actual extortion dollar amount (assuming that most security researchers are not willing to personally engage in illegal activity themselves, which appears to be the case).
However, when evaluating the value that a bug bounty program brings to the company, they should absolutely consider these typical extortion amounts.
This doesn't strike me as a very accurate assessment of the situation. There are already markets where people can buy and sell exploits: researchers don't have to get their hands dirty to get paid for their exploits.
I'm saying that the market value of actually performing an illegal act of extortion is higher than the market value of a zero-day, either on one of these markets or via bug bounty.
I'm arguing that the price is different because of the risk of getting caught and going to jail, not that there isn't a market for security researchers to sell exploits to criminals without otherwise getting their hands dirty.
That being said, I still think bug bounties are too low, even when risk adjusting.
Taking the certain $10k is the better deal over hunting for a shady buyer on shady sites who might send you some bitcoin if the deal even pans out or if they even pay. That's a lot more work and uncertainty while they act like it's just the choice between which lever to pull. A bird in the hand…
I recently found a compromised server on a university's network. I wasn't going to cold call them to report it because I had no idea how Betty answering the phones would react. Instead, I sent it to an IT contact that I knew personally. I knew that he didn't have anything at all to do with this, but that he would know who to get it to.
If the .edu is one of their 668 member institutions [1], they have designated security contacts at the .edu that they can directly get in touch with -- and, in many cases, can even wake somebody up at 3 a.m., if/when it's warranted!
Even if the .edu isn't a member, though, they'll almost certainly have an easier time getting in touch with someone with a clue that they can pass your report along to.
---