Macbook Hacker Charlie Miller: "I have a new campaign. It's called No More Free Bugs."
blogs.zdnet.com
blogs.zdnet.com
But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits.
The idea of announcing NO MORE FREE BUGS really amounts to saying to the world "I'm either going to sell my work to criminals, or am going to participate in an ongoing blackmail scheme to make myself rich."
Nice. Good luck with that, Charlie.
But I have two problems with where you're going.
First, finding a bug in your own time and not telling Apple about it unless they pay you isn't blackmail. Charlie Miller bills $300/hour. His work product is worth money. Apple has no right to confiscate it. If the dilemma was, "pay up or it's going to the Russian Mafia", it'd be blackmail. But if you think Charlie Miller is selling vulnerabilities to the Russian Mafia, you're a jackass.
Second, the reason you don't see me at CanSecWest --- well, one of them, another being that Nils and Charlie and Dino would crush me --- is that I spent all day reversing protocols, writing fuzzers, and finding flaws. For cash. Vendors pay us, and so do large companies that buy from those vendors. It's my day job; it's a job; money changes hands. How is Charlie's proposal different?
I think it is different. But it's way more subtle than you're making out to be. It's also a common industry practice, so making him the face of it isn't a great play.
(You can see where we stand on this: http://www.matasano.com/log/mtso/ethics/).
Indeed, I think it's a great idea for Apple and the other vendors to reimburse 3rd parties for high quality results.
But he wasn't saying "I put X hours into this, and therefore it's worth $X*(billing rate)."
He was saying "the market value of this is $Z., and it's more for things that have a greater impact."
I don't know Charlie Miller from a hole in the ground, and so I have no idea if he's going to be selling his work to the Russian Mafia. If you say he's a great guy, I'm sure you're right.
Nevertheless, if he thinks that security exploits have a market value beyond a reasonable billing rate, he's implicitly using the threat of the Bad Guys to raise the value of his work.
That's a very fine line to be walking.
If the Bad Guys can get the exploit from someone else, then Apple equally could pay someone other than Alice to disclose it to them. Your premise assumes the work is fungible.
If the entire set of people (including Alice) who are capable of finding these vulnerabilities conspired to withhold their work and push the White Hat market clearing price up to the level that the Bad Guys will pay, then the answer to your question would be yes.
If it's a market without price fixing, then Alice withholding her work doesn't materially affect the actual price of the exploit to Apple, and in that case the answer to your question is no.
Let me put it another way.
There are two markets for exploits: the legitimate one, and the criminal one.
Charlie is participating in the legitimate one. He's going to get paid what the sole counterparty wants to pay him. We can argue about what the counterparty should pay him, but that's up to Apple (in this case), and there are a lot of different things that might enter into their calculation.
An argument that uses the value of the exploit in the criminal market in an attempt to set a value in the legitimate one only makes sense in one of two cases: (a) you're going to take your work and sell it over there, or (b) you claim that someone else either has already discovered or will soon discover the same exploit independently, and will choose to sell it on the criminal market, and therefore the value of your work should reflect the danger of that happening.
In the first case, you're engaging in blackmail.
In the second case, it's just not a very good argument -- because the chance that each element in the chain of reasoning about the value (it's about to be or has already been discovered by someone else, it's going to end up on the black market, it's a substantial risk for a 0-day, etc.) is not true represents a probability that reduces the overall value of your exploit in the legitimate market. Plus, there's the additional reductions in exploit value that come from the vendor not actually caring that much about fixing problems until they're in the wild, or having already found the issue and decided that the particular problem isn't worth fixing for a variety of non-technical reasons, or any one of a dozen other external factors.
Working on spec and then demanding that the vendors match the exploit values that the criminal market is paying is just a Bad Idea, morally and practically.
I don't know. If he can't ask whatever he wants for it and Apple can't pay whatever they want for it, there's no simple solution.
weis2007.econinfosec.org/papers/29.pdf
Based on the limited data in the paper, it seems that it's the government rather than the vendors that is actually setting the price in the legitimate market, at least for high quality exploits.
I think the X*(billing rate) calculation ignores the risk that the researcher took. It's a little like saying that a startup should be worth exactly the amount of money that has been invested in it.
Hourly rates are determined based on market rates, and vary from job to job.
Please enlighten me... I don't see any mention of selling the exploit to criminals, just mention that they could get a lot more money than is offered. Is there just a subtext I'm missing with those statements?
> Q: Google Chrome was the one target left standing. Surprised?
> A: There are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. The’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.
I know many people are mad that the linux/mac version isn't available but if you think about it, the reason is the sandbox. Google loves quality and won't release something if its not of high quality. Sandboxing on windows I'm positive is different on a unix based system. And security is key.
This is, of course, silly. We haven't hit "peak oil" for Windows infections. A new Windows worm still pays off wildly better than a Mac worm; writing Mac malware is economically irrational.
Why do you find that funny? You said yourself that it's true.
Leopard also has some sort of sandbox feature, but apparently it's not used for Safari.
http://www.matasano.com/log/981/a-roundup-of-leopard-securit...
I was mainly interested in if there had been any HN discussion on it. Thanks.
//olme
1) Am I making the world a better place or a worse place?
2) Am I providing value to the people I care about?
I can't speak for Charlie Miller. But, my answer would be no for both questions. If I were in the same position as him I would feel like a big piece of fucking shit every single morning when I looked at myself in the mirror.3) Can I feed myself?
By finding Safari bugs, he does make the world a better place. But he can't live like that, so he has to stop looking for Safari bugs.
Since Safari undoubtedly has bugs, this means someone else is going to find them. That someone else could be a criminal, but you can't blame the guy for not wanting to do work that doesn't pay. In the end, Safari's security is Apple's problem, not Charlie Miller's.
And it isn't just Apple's problem (or just Microsoft or just Google). It's my problem, too. It's my mom's problem, too.
Think about the case where a user's data is compromised.
With great power comes great responsibility, and whatever other cheesey statement you want to make. I would feel personally responsible if I found an exploit and later that exploit was used to compromise someone's bank account or private correspondence.
My conscience is more important than my stomach. I can find other ways to eat.
Which is why he's not even looking for exploits anymore. He is leaving it to Apple's QA team, since it is really their job.
That's just what I think.