Zerodium offers $100k for a RCE in Pidgin, who received $25k donation this year
twitter.com
twitter.com
None of this is to say that $25k is adequate compensation for critical FOSS development work.
(This is fraud, don't actually do this! But it comes up every time someone does bug fixing metrics)
Edit: If it's not a bug bounty to fix it, but a vuln bounty to sell it, then it's highly-unethical but not necessarily illegal.
Fixing some bugs and adding some features is a nice-to-have that most people and companies aren't willing to pony-up much for.
Comparatively a single hellfire missile costs $150k - plus $32 million for the drone to fire it from.
Also, I don't really see any possible way out of this cyberarms market. There are too many degrees of freedom to really secure anything completely and I'm continually surprised that our governments allow the sale of these munitions to non-allied foreign governments. If someone puts up a $2m dollar bounty for Tesla do we just accept this even if it means physical harm?
I would take the 0-day payday thanks.
I don't necessarily disagree with you, but I do think it's dissonant enough to be interesting.
Chrome funding is probably in the XXM$/year, while Zerodium offers 500k$ for a vulnerability, that's an approximate 20-100 funding / vulnerability ratio.
Pidgin is at 25k$/year, for 100k$ for a vulnerability, so a ratio of 1:4.
I think the only reasonable conclusion is that community-driven opensource projects are 100 time safer than private company-funded opensource projects /s
Like, I understand why that's the case, but it still sucks.
OSS projects aren't people with curable diseases. Most of them are labors of love, run by people in their spare time. Those people have needs that are mostly not met by working on open source projects. Epsilon open source projects are well-enough funded that nobody in the project feels starved for resources.
Bug bounty programs are only useful for these projects if the details of the bug are shared with the project. Zerodium's model relies on keeping developers unaware of the bugs for as long as possible [1].
Nobody developing OSS is grateful for programs like Zerodium.
[1]: https://security.stackexchange.com/questions/199480/what-doe...
> Zerodium customers are government organizations (mainly from Europe and North America) in need of advanced zero-day exploits and cybersecurity capabilities.
Based off Zerodium’s origin and reputation, it seems an exploit is sought which enables a governmental actor to examine information that it otherwise could not. I am assuming they do not have a legal basis for doing so or courts would have granted/ordered such access.
It's also possible that they have a lawful basis and warrant, but realise executing a physical warrant won't get access to what's required - with e2e encrypted chats going over Pidgin, on an encrypted laptop, you need to be very confident that when you swoop, the laptop is on and decrypted. You get one "go" at that, otherwise you have a suspect, little or no evidence, and an attorney requesting their immediate release on bail absent any actual evidence, which would let them flee and clean up any other evidence that may be out there, either with them or others.
This is to say that FOSS needs more funding and contributors; rest of the industry can do whatever they want, and we wouldn’t care.
Are there some activist or terrorist monitored by a 3 letter agency that is computer literate enough to use Linux + pidgin to try and keep away from prying eyes (or just plain ethical reasons)? Or would the exploit end up being targeted at some foreign government that has standardized on Pidgin?
(I'm sure plenty of people do actually do that; just lamenting the fact rather than expressing skepticism at the plausibility.)
Fortunately I recovered it before any of the virus-riddled crapware he downloaded noticed it was there, haha
I suspect that this use also causes those that are not doing Tails to use Pidgin on Windows to communicate with those that are. After all, Pidgin is in Tails. It must be secure.