Really this seems like a shady security company when I describe it like that.
Really this seems like a shady security company when I describe it like that.
So a hacker group that will blackmail companies?
$7500 for spending anywhere less than a month on something is a pretty decent compensation.
You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users, in this case Facebook’s.
If you think $7500 for finding something like this is not enough, you shouldn’t do it. You wouldn’t clean toilets for $1 a month either right?
Literally the point of unions (and big part of companies).
Forcing companies to pay a lot for found exploits is something completely different though.
An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs.
The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
The rewards for these kinds of things are pretty public, so you can guess how much you will get paid for finding certain security bugs. If the amounts are too low, again, just don't do it.
Oh, no, the horror! Almost a trillion dollar company would need to pay a couple of extra grands to a security researcher who discovered an enormous vulnerability.
> The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
"Nobody's forcing them to" and "they'd probably do it for free anyway" aren't what I'd consider valid reasons to keep something on a freelance basis. Perhaps "it's an infrequent odd-job" is a more sensible rationale, if there was one
I think that forcing companies to recognize and deal with vulnerabilities is a good thing, so to the degree this kind of setup would do that it wouldn't be all bad, but trying to extract additional gains beyond that exposure isn't good (e.g., companies would pay more to prevent bad PR from a threat to expose something than just to fix a vulnerability due to the risk it presents them, and the former is 'artificial' in this case so it wouldn't be efficient for a group to try to extract that from someone).
That is, today companies have some existential risk that a cyber security incident causes great harm to them (think: sony hacks, cambridge analytica), the existence of white hats researching these vulnerabilities and disclosing them responsible gives companies an avenue to address this risk, likely at a lower cost premium relative to hiring security teams to try and find them. I think that it's easier for companies to recognize and deal with these risks now than it used to be, and easier for security researchers to get paid for it. These are both good things, but it is quite possible that the risk posed by cyber security threats to companies is generally worth more than they're paying in aggregate (2 million in vuln fees quotes in their latest report, not much at all given the impact), so I think that some structure that would allow researchers to force companies to up the ante would be a good thing, but this is hard since it's a completely one sided market and companies can just accept the risk of an incident occurring rather than pay, even if it's inefficient.
Sequencing plays a major role here. And while that may seem somewhat arbitrary, it is significant.
(Similar case, that, for some reason tech people have entirely too much trouble understanding: Announce "I'm going to shoot this gun at that target". Person, having heard you, walks and stands in front of the target. Are you still allowed/morally right to shoot?)