The situation I imagine is someone outside of the parking lot showing up to me and telling me there is something wrong with my car, but they will only disclose it to me if I pay them $50. Then I happen to be an expert car mechanic and I know my car pretty well and I know whatever they tell me is irrelevant and definitely not a security concern. I think it is pretty justified to alert other car owners of that same parking lot that ”that guy in the blue shirt telling you you have a problem with your car is just a scammer, don’t pay him”. That’s nothing like complaining about a begger offering to wash your window.
It is useful even for real white hat hackers sharing actual problems.
Low quality reports that include a POC are, on the other hand, neither extortion nor scams. They may be problematic for other reasons (lowering the signal-to-noise ratio), but they don't fall into the same category as the aforementioned "no disclosure without payment" reports and should not be treated the same way in my opinion.
I think the only way to come to this kind of conclusion is if you're hearing about the SPF-record beg-bounty phenomenon for the first time in this article. Because we get these all the time. There can't be any benefit to singling any one of them out.
Further: this isn't a 419 scam. You're not soliciting wooden keyboards from people trying to ransack your bank account. These are just pentesters who are not (perhaps yet?) good at their job. The reports you get from them are dumb, but they're not usually wrong; they're just issues that nobody cares about.
You can write a post about the beg bounty fraud without using cruelty to stimulate the nucleus accumbens of a huge number of people. But it's harder to do it, because the underlying observation ("oh, there's a lot of bogus scanner-fodder bounty posts") is banal. Here, Troy wanted to light us all up. But he didn't want to work to do it. So he recast some hapless bounty dork as a scammer and built a whole post around administering justice to them. Gross.
There are a lot of disadvantaged people overseas and they're increasingly connected. They're fundamentally no less capable than we are. I look forward to their eventual overthrow of infosec.
Thank you for this comment. This article and some of the comments here have made me enormously uncomfortable.
There are serious double standards where if privileged people do it, it's wise/clever/smart. If poor people do essentially the same thing, they are morally depraved abusers for wanting money.
The phrase "fake it til you make it" comes to mind here. For privileged people, that approach is celebrated and encouraged. Here, it's being maligned in a way that strikes me as classism.
I don’t know what “gingerly” means, but you are right in this assumption. I only own small side projects sites, but the article felt like a useful warning to me in case I receive such a message some day.
I am more inclined to agree with you than before your reply, your point of view makes sense. I would still call the article more “helpful” than “gross” though.
Honestly: if he hadn't brought up that he was called out for this and tried to rebut it, I wouldn't have thought to write about it. But he did, and, like I said, his argument is pretty weak.
Moreover, the presumption that an Islamic name means they’re underprivileged or foreign-born is condescending, maybe even racist. My rich South Asian friends in high school had similar names, similar hacking proclivities and very much the same poorly English in their written correspondences.
The institution of bug bounties is structurally reliant on a huge wage gap between countries. “Picking the wrong country to be born in” is not a moral fault. Yes, many of the people engaged in bounty farming at scale are low-skilled relative to the average HN reader, but they are probably not low skilled relative to the average HN reader at the lowest skilled portion of your own career, and when you were being paid for your labor during that portion, you earned a month’s wages for this guy in ~hours of work.
It is also true that they don’t conform to our class norms in communications styles. That’s also something I’d suggest moderating one’s emotional response to out of noblesse oblige.
“I’m responding to this out of abundance of charity, but given literally no identifying information in the email I think there is a high probability I am speaking to a script rather than a human.
What do you want to tell me about what application specifically?”
They responded that they were a human and asked whether there was a bug bounty. I sent them a one word No. They replied “Thanks” and that was the end of it.
I wrote the first email on the thought that it might have been an early career security researcher possibly poorly calibrated on how to reach a security contact, and if I write it in the future, I will probably revise the “human” language as it doesn’t travel as well as I intended it to.
Perhaps:
“It would be more effective in the future to include details about the report or at least about which application you are reporting about to route emails like this effectively.” followed by the query.
Is the "White Hat" doing what Troy says he is doing? It seems so. Many not so technically versed people would maybe even be intimidated or scared by the approach. It is objectively wrong (without further circumstance).
But I think it can be attributed to unprofessional and incompetent behavior rather than malice. Troy is in a position of power and wisdom in this case. He _could_ try and educate/correct the actor by firmly rejecting his request and clearly stating what the issue is without trying to embarrass him, let alone publicly shame him.
---
An analogy that came to mind:
Dogs are this way. If a dog acts from a position of weakness (incompetence) and gets into the face of the other dogs, then that dog is "corrected", typically by one that enjoys some form of respect. If the corrected dog reacts accordingly (stops the misbehavior) the other dogs calm down again. The correcting behavior typically starts with very mild body language and then escalates further.
From then on it's settled. Publicly shaming others is a very human thing to do.
---
Again - torn. It feels both right and wrong. I wouldn't do it this way. Not with a person that I assume to be in a relatively weak position.
Sure. A scammer is probably substantially less well off than a Microsoft executive. Scammers are often not very well-off. That doesn't make their behavior acceptable or impolite to call out.
> He _could_ try and educate/correct the actor by firmly rejecting his request and clearly stating what the issue is without trying to embarrass him, let alone publicly shame him.
He did try this -- firm rejection, explanation of the issue, and invitation to behave ethically: https://twitter.com/troyhunt/status/1456944080936599557
The response was exactly the sort of response you'd expect when calling out someone committing petty crimes.
I suspect if the response had been a sincere apology this blog post might read differently. Or at least not include the bit about this person.
He's a "Microsoft Regional Directory" and a "Microsoft Most Valuable Professional", but those things are very confusingly named. He's not an employee of Microsoft.
If someone doesn’t tell me what’s wrong, then asks me to pay them before they’ll let me know, all my scam meters go straight into the red.
> Attempting to scare people with an alleged vulnerability then withholding information about it until a financial commitment is made all whilst claiming to be a "white hat" is dishonest, deceptive, and fraudulent.
"Withholding information" in this context really means the absence of extra work—of having reached a milestone where something of substance is known, and a problem arises that involves needing to make a decision about whether to pursue it to its ends or not.
Writing up a disclosure is something that takes work. Cleaning up a messy POC so that it can actually be understood by someone else (or just capturing one in a fixed form instead of something transient/ephemeral to begin with) is something that takes work. Being responsive to the other party's questions is something that takes work. Clearing time to make yourself available—even if the other party doesn't have any questions—is something that takes work.
When you are claiming that someone has "already" done "the work" when they notify you a problem exists, you forfeit the argument the moment you ask "What is it?"
People should curtail these "bounty" programs. There is a generalist expectation about how bounties work that is not all all rooted in empiricism. I get why: the idea that you could put a `security.txt` on your website and start getting people to send you good bugs without compensation on faith that you'd come up with a fair valuation and pay accordingly... well, it's a beautiful idea! The fact that it can't possibly work that way, and that acquiring a feed of valid sev:lo-sev:med bugs involves, for savvy companies who have been doing this for 20+ years, outlays of $15,000-$20,000 is, I think, problematic for that idea. If this is news to you, that's fine! But don't run a bounty program; you're not ready, and it is absolutely not a tech company norm that you have to run one of these things.
You're responsible for staffing security@ no matter what you do; you can't curtail it. But you shouldn't advertise to people that you're interested in unsolicited reports unless you're willing to wade through a of DMARC spam. That's the tradeoff for getting, every once in a blue moon, a free report of a real vulnerability.
This isn't a good Samaritan who wants a little quid-pro-quo. This is a classic extortion technique. The more we shame and expose these actors, the better. I think Troy did a great job posting about this topic in the manner that he did.
This Mohammed guy is just a slightly different version of it. He knows exactly what he's doing, which is peddling snake oil hoping to lure in the scared and the less knowledgeable. Morality is certainly a factor and I will continue to criticize these actors on that basis.
More generally, I think publicly shaming individuals is a nasty thing to do.
The second potential problem (I do not know if it applies to this particular person) is that the beggar may be on the lookout for an uninformed and manipulatable person who can be comprehensively scammed.
If you don't think this should be on HN you can choose not to vote for it or avoid future links to troyhunt.com.
I am well aware of that and I imagine you know that. Please don't be pedantic.
Troy's content is typically high quality and engaging (i.e., I won't be avoiding it). This is not and I felt that on it's own was worth a comment (and is even more interesting than the post itself).
You are clearly aware of the pointlessness of complaints couched in this manner, yet you chose to do so anyway. Are you also aware that the guidelines for HN specifically deprecate this sort of thing? Moderating a public forum is a difficult task, Dang does a great job, and, while I do not think you intended it, it can come across as somewhat disrespectful to express disapproval of the content of an article by suggesting that his moderation didn't match one's particular point of view.
I don't think this metaphor completely fits. A more apt metaphor might be someone telling you your tire pressure is too low when you know your tire pressure is perfectly appropriate for the given types of tires you have and climate you're at.
It's pretty annoying when my boss (or my boss's boss) ends up reading one of these emails and freaks out because they don't understand the severity of the problem. Usually when I see these emails they often are blasted to every email that can be found on the contact page, including things like sales channels. Explaining the context of security vulnerabilities that are irrelevant given our configuration is not a particularly fun or easy things to do to non-technical executives terrified of data breaches.
That's a losing argument because it's a strawman anyway. Nobody's really offering to wash a car, outside of a bad analogy.
In want of a rebuttal, I offer the following:
It's not the sole responsibility of random software people receiving these dubious-at-best reports to address the problems caused by late-stage capitalism that put people in desperate situations to where they would need to resort to such behavior. There are probably a lot more political solutions to prevent people from being desperate. There's probably a side-discussion to have about what is the best tactic to help the most people in a given situation, and how software people can do their part, but it's ultimately a bigger problem than any of us.
Further, even if we waved a magic wand and fixed the very real human suffering that goes into the analogous case, that might get rid of the $1 window washers (because it's a thankless thing people do out of desperation), but it's less likely to eliminate what Troy is calling beg bounties. The reason is that the incentives for the latter are different than extreme poverty and homelessness; there's an element of fame-seeking and point-collecting on top of it. The platforms are gamified, you see.
In that regards, I would argue that it is more honorable to publicly shame the beg bounty crowd than someone who's asking to wash your car for $1. However, that just establishes the inequality, not the delta. I don't think I could convince anyone that it's totally honorable, just more honorable.