Researchers find critical vulnerabilities in Yahoo site, offered $12.50 per bug
geekwire.com
geekwire.com
I mean, I appreciate the effort and the time, but just because you run a large web service or any web service doesn't mean that I should pay you for vulns. You should receive my gratitude, anything more than that is being extra nice.
Now, is there value in posting that there is some bounty for these things? Will it result in better, more frequent disclosure and give me the ability to close holes before someone nefarious comes along? Absolutely. Until I do that, people shouldn't speculatively be doing research and then retroactively bitching about how little they got paid.
If you do work like that, please let me know, I've got some projects you can work on that I might decide to pay you for.
What should happen is that Yahoo should have bounties in the first instance. They don't have to, but not having them leads to a bad outcome for everyone except black-hats.
It's that if you do give a bounty, don't make it an insultingly low value at your corporate store.
If cash is part of the equation, pay the going rate. If it's not, then acknowledge that someone did you a favor. Anything in between could be perceived as an insult/cheap.
You knock on his door and let him know, he says "wow thanks for the heads up, I'll buy you a beer sometime"
You think to yourself, "A beer?? I just saved his car from being stolen-- that's worth a lot more than a beer"
A week later you walk outside and see he did it again. Instead of knocking on his door, you walk into the alley and tell a local criminal about it in exchange for 500 dollars.
This is essentially what you're advocating.
Rather, it's a bank, and through your advanced knowledge of structural engineering, and at least several days of work, you find a weak point in the wall that would allow for easy, noiseless drilling, allowing their vault to be emptied in ten minutes.
I agree completely that Yahoo doesn't owe them a penny, and it would be reprehensible to find a "different market," as the grandparent alludes to. But it's not quite the same.
You have constructed an analogy so inapt that it threatens to suck all other dumb, unenlightening analogies on HN over its event horizon until it forms a sort of inapt hole from which dumb analogies could never escape.
Which would be a good thing, so good job!
The analogy is a bit off, as 'a beer' is relatively good compensation for the disclosure of the car-key vulnerability, compared to the potential black-market value, and the potential loss to the owner.
With this example, it's more like you told your neighbor about his forgotten keys, and they gave you a nickle and a pat on the head.
By contrast, assuming the vulnerability in Yahoo's system took just one work week, their offer was $0.31/hr. That's 384 times worse than your neighbor giving you a beer for finding his key.
This is why your neighbor gets his key back for a beer and people are recommending black marketing Yahoo's vulnerabilities.
It doesn't even have to be monetary - for example, GitHub maintains a list[1] of people who have responsibly disclosed vulnerabilities, and they often send them a shirt or something similar.
[1] https://help.github.com/articles/responsible-disclosure-of-s...
Maybe. But nobody asked these guys to do a thing. Ergo, no foul.
No, it's really not. Which is why it is so insulting.
It would have been much better to just say "thanks" and give nothing.
Yahoo gave them $25 in store credit at Yahoo.
I'd rather have gotten a nice letter, because that kind of "compensation" is as much trying to attract business to Yahoo products as it is trying to reward me.
In all likelihood, they'd have earned at least 10 times as much spending the same number of hours at Burger King, and probably over 100 times as much selling the flaws.
Grossly underpaying is much more insulting, because it says directly what they value your work at, than not paying, which may simply be a policy of not handing out rewards for that kind of behavior.
My point is Yahoo's message to the people would have been taken better as /just/ a letter, than a letter and a far undervalued "reward".
The funds are considerably more impersonal than simply giving a gift and demonstrate in a concrete way the low value it was given by Yahoo - not even worth a personal email to ask about tshirt size/style.
"Each of the discovered vulnerabilities allowed any @yahoo.com email account to be compromised simply by sending a specially crafted link to a logged-in Yahoo user and making him/her clicking on it."[1]
[1] https://www.htbridge.com/news/what_s_your_email_security_wor...