Frankly he could have just sold the vulnerability to the highest bidder
Frankly he could have just sold the vulnerability to the highest bidder
> Cox does not offer a bounty program or provide compensation in exchange for security vulnerability submissions.
https://www.cox.com/aboutus/policies/cox-security-responsibl...
One big reason to put this out there: Otherwise you get so many drive-by disclosures. Throw ZAP at the domain, copy all of the low and informational topics into a mail at security@domain and ask for a hundred bucks. Just sifting through that nonsense eventually takes up significant time. If you can just answer that with a link to this statement it becomes easier.
It makes me a bit sad that this might scare off some motivated, well natured newbs poking at our API, but the spam drowned them out.
Why? Ethics aside, is everything money?
Edit: As I noted elsewhere, necessities are something else.
Ethics aside, why not? That's why we have ethics.
For me, doing the right thing is beyond all these things, and I don't care about money beyond buying the necessities I need.
Money often starts out as necessity or one of it's close cousins. If I were 1) 8k miles away from my target, 2) in a region with more internet access than employment prospects and 3) needed to eat, I can see a path to profitable disclosure.
> For me, doing the right thing is beyond all these things,
This can be a luxury. After a year or 3 of kids in and out of hunger, what's right can get reframed.
> and I don't care about money beyond buying the necessities I need.
Getting beyond that is the thing.
That...is ethics, no?
Ethics is our answer for those that can't.
However of course in reality, empathy only gets you so far. Should you feel empathy for a CSA consumer because their feelings are important too? Do you empathise with their feelings?
> but I suppose these perfectly selfless people might exist
I don't suppose you read what I typed. Empathy is not the setting of self aside, but the experience of feeling what someone else would in a given scenario. It is deeply selfish.
I would also say it is a prerequisite for an organized system of ethics.
Professional value that doesn't translate into money, do you mean? How do you categorise that?
So this security researcher can keep doing his research without worrying about paying bills. The company gets cheap security audit, the researcher gets money, everybody wins
This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.
We're not talking about a grandma losing her wallet with 50 bucks in it and not giving money to the guy that found it and gave her back.
Yes, Cox has that choice. But, what you're describing is the definition of extortion. The fact that it's easy for people to get away with it does not make it ethical.
The comment I responded to was this:
>it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those.
That comment includes the threat ("instead of easily and anonymously selling those").
So, yes. That is the definition of extortion.
The following two sentences read the same to me:
"To remove my incentive to harm you, you should pay me".
"To remove my incentive to share information with others who may harm you, you should pay me".
And, the threat is pretty clear IMO.
Ransomware victims have sometimes found it practical to pay the ransom. They're still victims of extortion.
The idea that the company owes them anything for their unsolicited work is misguided. And, if they present the bugs for money under the implicit threat of selling the information to people who would harm the company, then it's extortion.
Do you think it's reasonable to say the the ethics of what you call "extortion" should depend with how big the company is? I'm obviously not advocating for making a small company pay more than they can manage
That framing is strange to me. If they want to offer a bug bounty, then they can. But, it's their choice. Maybe they'd instead rather engage a security firm of their own selection.
But, whatever the case, to say "they should pay the money because they can afford to" isn't right to me. I don't believe the definition of extortion changes based on how big the target is or whether it can afford to pay.
In fact, the line of thinking in some of the comments here is so far off from what seems obviously ethical to me that I've had to re-read a few times to ensure that I'm not missing something.
2. If said person doesn't present the bug to the company, but just goes straight to selling it to the highest bidder it's not extortion. If the company does not provide the right incentives (via e.g. bug bounties), isn't it their own fault if they get pwnd? They clearly don't value security.
Not to mention them getting "pwnd" creates a lot of collateral damage in the form of innocent customers.