If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†).
You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty.
You can tell them "I found a vulnerability in sOmEtHiNg! But I'm not telling you what it is!" but Facebook is beset constantly by bogus bounty claims and they will blow you off.
You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything.
Part of being a good "agent" is understanding the market you're working in.
† Especially because to even try to put a valuation on the bug --- which, again, ~nobody wants to buy --- you'd have to actively exploit it to see what's on the target system, which is straightforwardly a felony.
https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl...
wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah
reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they had
I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me.
I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.
Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw).
Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
Really this seems like a shady security company when I describe it like that.
So a hacker group that will blackmail companies?
$7500 for spending anywhere less than a month on something is a pretty decent compensation.
You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users, in this case Facebook’s.
If you think $7500 for finding something like this is not enough, you shouldn’t do it. You wouldn’t clean toilets for $1 a month either right?
Literally the point of unions (and big part of companies).
Forcing companies to pay a lot for found exploits is something completely different though.
An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs.
The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
The rewards for these kinds of things are pretty public, so you can guess how much you will get paid for finding certain security bugs. If the amounts are too low, again, just don't do it.
> The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
"Nobody's forcing them to" and "they'd probably do it for free anyway" aren't what I'd consider valid reasons to keep something on a freelance basis. Perhaps "it's an infrequent odd-job" is a more sensible rationale, if there was one
I think that forcing companies to recognize and deal with vulnerabilities is a good thing, so to the degree this kind of setup would do that it wouldn't be all bad, but trying to extract additional gains beyond that exposure isn't good (e.g., companies would pay more to prevent bad PR from a threat to expose something than just to fix a vulnerability due to the risk it presents them, and the former is 'artificial' in this case so it wouldn't be efficient for a group to try to extract that from someone).
That is, today companies have some existential risk that a cyber security incident causes great harm to them (think: sony hacks, cambridge analytica), the existence of white hats researching these vulnerabilities and disclosing them responsible gives companies an avenue to address this risk, likely at a lower cost premium relative to hiring security teams to try and find them. I think that it's easier for companies to recognize and deal with these risks now than it used to be, and easier for security researchers to get paid for it. These are both good things, but it is quite possible that the risk posed by cyber security threats to companies is generally worth more than they're paying in aggregate (2 million in vuln fees quotes in their latest report, not much at all given the impact), so I think that some structure that would allow researchers to force companies to up the ante would be a good thing, but this is hard since it's a completely one sided market and companies can just accept the risk of an incident occurring rather than pay, even if it's inefficient.
Oh, no, the horror! Almost a trillion dollar company would need to pay a couple of extra grands to a security researcher who discovered an enormous vulnerability.
Sequencing plays a major role here. And while that may seem somewhat arbitrary, it is significant.
(Similar case, that, for some reason tech people have entirely too much trouble understanding: Announce "I'm going to shoot this gun at that target". Person, having heard you, walks and stands in front of the target. Are you still allowed/morally right to shoot?)
I had some young college students report a very clever bug to me a few years ago, and they chose to take a rather aggressive approach when it came to discussing the bounty. We paid them a sum they were very happy with, but also gave them warning that if they took that same approach with the wrong company they could easily find themselves charged with a crime.
"You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything."
Wouldn't that cost Facebook much more than $7,000?
The bug is there whether a bounty hunter finds it or not. The other "leverage" you have, if you don't like $7K bounties for auth bypass on random backend thingies, is just not do hunt for bounties at all. Facebook knows that; their desire to attract bounty hunters is priced in to the bounties they pay.
It's for this reason that people who want to make serious money and who start in bounty hunting break basically two ways:
* Either they get really good at mopping up lots of 4-figure bounties (hitting the occasional blackjack on something that pays into low-mid 5 figures), often with a fair bit of automation, or
* They graduate into consulting, where the weekly rate for this kind of work is substantially higher, you're given a briefing by the target about where to look, and where you get paid whether or not you find a marquee bug.
(A good person to ask about this stuff is 'daeken).
Seems like that captures the "higher bugs per hour" advantage of the consultant while retaining the "you only get paid for directly producing value" advantage of bounties.
The reason companies pay for app pentests and also run bug bounties is that the two modalities find different kinds of bugs. App pentesters generally get a lot of intel about their targets (source is not unusual). You're also getting a team with bios and a final deliverable that records the diligence work done, which is not an outcome you get with a bounty program.
But you can do things in between. It's not crazy to offer a gig to someone who has delivered a good finding on a bounty project. But you have to do something to incentivize them beyond what the bounty already does, and the most normal way to do that is to not make payment contingent.
Well, okay, but the opportunity cost (ie. the other valuable things they could be doing) is surely something that could have a $ value attached?
The middle manager who cares a lot about staying “on budget” for bounties could care less how long it takes the security team to track down a bug.
Anything mildly "interesting" being sold through such a program would be high treason. How do you know this "Russian website" isn't actually a CIA honeypot? Or maybe it's not a honeypot, but instead of paying you 250K you just die of heart attack in a couple of months? Or they sell your identity back to your govt. as part of some unrelated game.
Bad business.
Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?
No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes...
Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a la Google Project Zero? Maybe what makes that non-blackmail is the promise of revealing it no matter what, but offering to delay up to ninety days?
The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc.
Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on.
Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation of blackmail, no demand for money involved.
Now, not all cases of blackmail fit the classic situation. It is possible for a person to commit blackmail without demanding money, if instead they demand something else of direct value to them – for example, saying to a university president "Offer my child a place or else I'll tell the media that you are cheating on your wife".
But, in the case of Google Project Zero style "Fix this bug in 90 days or I'll publicly reveal it", it isn't clear that the demander is actually demanding anything of any direct personal benefit to themselves. Generally speaking, the direct personal benefit to the security researcher of the bug being fixed is going to be negligible. If I demand you do something which doesn't directly benefit me (or my family or friends) in any tangible way, I don't see how such a demand could legally count as blackmail.
I doubt the delay itself has any direct legal relevance. Going to someone and saying "I'm going to report your crimes to the authorities no matter what, but if you don't pay me I'll do it tomorrow, if you pay me I'll wait until next week instead" is probably still blackmail. (Getting one week's notice is invaluable if you plan to flee the country, for example.)
The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail.
If I just went ahead and reported your crime to the police – no crime of blackmail.
If I just didn't – no blackmail (but could be some other crime, such as misprision)
It's only when I tell you that whether I'm going to do it depends on whether you do something for me that blackmail has been committed.
Now a more relevant example:
I discovered a security vulnerability in FB.
1. Publish the vulnerability publicly (legal)
2. Sell the vulnerability to exploiters (illegal)
3. Accept FB's bug bounty reward (legal)
4. Attempt to negotiate a different amount with FB, falling back to #1 (illegal, blackmail)
5. Attempt to negotiate a different amount with FB, falling back to #2 (illegal, extortion)
6. Attempt to negotiate a different amount with FB, falling back to #3 (legal)
I assert that treating #4 as a crime is to use the police powers of the state to protect FB's wallet.
But I also think a lot of these companies are happy to frame negotiations as extortionate if someone has the audacity to counter their offer, and that's bullshit. But it would also be bullshit to try to drive up the price on a real bounty after the fact by threating to let the bountied person run free with a map to your house, so it's complicated and I can see the precedent in thought there.
But whether it's legal or not, it won't work. Facebook will likely never do business with you again, but they'll watch your Twitter account for the free bugs you're promising to give them.
I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol
And then come in with the much larger payload and a few forum posts about it
They only use Monero for payments and PGP signed messaging on White House
If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of person who commits felonies to briefly lock up short account names on Instagram, and you'll have absolutely no way of arguing in court that you didn't know exactly what they were going to do. But you'll probably sell it, because there is an existing business process that acquires OG Instagram accounts your bug can slot into.
Nobody has a business process for exploiting access to a stupid internal legal dashboard application. Nobody is going to shell out more than $7000, speculatively, for access to this website.
Sure, the economic value of the root password to the NAS for Joe's Carwash is quite low but I suspect even the low level systems at high profile companies is worth tons (I'd guess millions) of dollars to the right (wrong people).
One time, about 15 "bug bounties are a ripoff" threads ago, someone actually made a non-ironic case for a high valuation for logout CSRF bugs. A competing image service could employ it to ruthlessly log users out, degrading service and jacking up their own signups. A logout CSRF. That's the kind of logic we're talking about here.
Nobody buys these kinds of bugs speculatively.
It's a good way to prevent people from snooping on your messages. Why do you think it's a bad idea?
There's an international market of brokers for zero days, but this specific vulnerability is less in demand.
I doubt that the information found at Facebook legal team could be used by nation-states (but perhaps I am not thinking creatively enough). I can imagine it being used as leverage by a nefarious nation-state, or informational by anti-trust dept. but it would be thrown out of court (therefore only viable for parallel construction). In the case of leverage the nefarious nation-state would feel the wrath of Facebook and/or US government. A country where Facebook has near zero adoption and already on bad terms with USA while within power vacuum, perhaps. Russia has Vkontakte, North Korea and China don't use Facebook either.
Regarding PGP, you don't have to use your real name. You can use an alias. You can sign each other's keys at a crypto party.
It would be much harder to mix identity with your clearnet pgp, if that’s what you were thinking, as the machines would air airgapped or the other ones simply off if you are using the same computer to boot the live os
Any other configuration is just lazy
Same goes here.
It is not about the vulnerability, it is about the content.
It's not even cut-and-dried for the RCEs that firms like this do buy. Bounty programs at giant tech companies are generally aware of the market prices for RCEs and are not overtly trying to screw you over. The flip side is that the price you get from a broker is (1) negotiated and (2) tranched, so the "number" you get is a best-case, not guaranteed, and can collapse if the bug is burned before the IC agencies the broker sells it to finish using it to hurt people. The bounty number, on the other hand, is a sure thing.
But ~nobody is buying auth bypass vulnerabilities. Maybe if you can mint OG Twitter accounts and aren't worried about going to prison.
Wouldn't demanding money be blackmailing?
A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't.
I definitely felt blackmailed. I am not a lawyer but it felt illegal. Maybe someone can chime in to say if it is?
Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilities.
From my perspective, people weird ideas (in both directions!) about how much this stuff costs.
† It's a little tricky to say because the blog post is cagey about what the vulnerability actually is, but I'm thinking about all of the password-reset-flow bugs I've ever seen that fit the rest of the pattern of the post and I'm pretty sure this is low-hanging fruit for a serious app pentest.
That being said, if they pay that company 35k, for example, and they haven't found this, wouldn't that fact make this discovery worth more than 35k?
Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.
So in this threads context, "hey I found a vulnerability in your infrastructure, you could pay me for it" does not actually constitute blackmail unless they actually follow it with "I'm selling to the highest bidder which may not be you".
https://en.m.wikipedia.org/wiki/Pharmaceutical_Benefits_Sche...
The blackmail version is actually "Refuse, and we'll produce a generic version locally and perhaps even export it to any country that wants it."
Note that a mixed economy (combined public/private funding, like the french and australian systems) are probably for the most part the most economically efficient. A big problem in australia is over-provision of services, especially ending up getting more pathology tests than strictly necessary.
This makes the company with said vulnerability pay the true price for it - may be even just purchase it on the black market and outbid the "bad guys". Or pay someone to fix it asap before it's sold.
Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situation?
“I’m going to do x if you don’t y.”
He’s under no obligation to disclose. But the second part is coercion.
x itself might also constitute a crime.
- I'm going to refuse your offer if you don't propose something better.
- I'm going to work on it if you don't want to
- I'm going to eat the cake if don't like it
I'm not sure if this rule would cover all coercion/blackmail, but a rule like the following is probably a good guideline: If the first part negatively impacts the "victim" while the second part positively impacts the other person, it's might be getting close to coercion territory.
Let's take your cake example: The person with the cake isn't really negatively impacted. If they don't like the cake, they aren't materially harmed by someone else eating it. Although even there, context matters: Let's say you're a baker, and you sell cakes, even ones that you don't like yourself (maybe you hate buttercream icing). Taking your cake and eating it when you might otherwise have sold the cake and made money would be a problem.
It is coercion. But not all coercion is criminal.
(Also sucks that you can release it anyway. But you do want to source these vulnerabilities from the world at large.)
Yet another reason why open source and collaboration may be better than capitalism and competition. Many hands make light work, with enough eyes all bugs are shallow, and all that.
(To be fair, open source lacks security by obscurity so a project becomes secure after many years and developers join it.)
I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps.
If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 people on earth? Which makes for more like 0.0014%?
So let's say 1% of 1 million/year are up to this, I suspect it's rather more, but I can't be bothered to do the curve on past graduation rates, and figure out what the world wide figure is... you've easily got a couple of million people world wide.
When I think it's going to get really interesting is in another 10 years or so when there start to be significant numbers of bored retired former developers. At any rate the market rate probably isn't that bad.
With your numbers (assuming linear growth) after those 40 years, about one third of the total US workforce would now be CS graduates.
The real money is probably something more boring than setting up exploits--such as setting up a security consulting practice that charges a ton of money. It's a lot easier because then you would have less pressure to discover completely novel exploits.