So I’m the guy who sent the t-shirt out as a thank you
yahoodevelopers.tumblr.com
yahoodevelopers.tumblr.com
Brilliantly handled.
Personally, I think it's ridiculous that this was blown so far out of proportion, all because someone went above and beyond with his own resources trying to thank reporters. But then I don't have both sides of the story and, frankly, I'm not going to go looking for internet anger to figure it out.
Guy tries to do something nice and gets a big slap on the face. I can imagine this reaction from those outside of Yahoo wanting big rewards for their discoveries, sad to hear it was coming from internal as well.
1) A clean, unconditional apology, like: "I screwed up, I'm going to fix it". I had very little hope since people don't often admit this type of things.
2) A defensive apology (that is, not really an apology): "Yeah I kinda screwed up a tiny little bit, but really it wasn't my fault, the predecessors..."
3) A smart-ass offensive strategy: "aha, you don't get it, our t-shirts are really cool, you should be happy that we even offer gifts and recognitions, you ungrateful bastards"
My ideal answer would have been 1) of course. Turns out, he exceeded my expectations (I'm the cynical jerk, here). He was a good guy in the story, explained the situation without fake apologies, or anything. Great answer.
It's striking when you can tell whether an answer is honest/no-nonsense. And not even an overdone apology can beat an honest-to-goodness straight forward answer.
That is PR jiu-jitsu. Make everyone feel good, make yourself look good and don't even use the word "sorry". Of course, it helps that you were "in the right" to begin with, but deftly handled, nevertheless...
Neither of those call for saying, "I'm sorry" or "I apologize" and saying either seems to detract a bit. I could be wrong? It's interesting to think about.
He also wrote thank you notes.
Very old school. My grandmother would be proud.
T-shirt-gaters need to lighten the heck up.
> it helps that you were "in the right" to begin with
Great on Yahoo for putting a reward program in place, but when did everyone become so entitled to getting something for reporting a bug/security concern.
If you stumble on to an issue, and you are a good person, submit the report. If you are looking to make a living off of finding bugs, go directly to the companies that actually have a reward program in place. Don't be mad when you get a thank you gift that wasn't what you expected. Don't get mad at your security report not meeting guidelines.
Sometime around the point where:
- Yahoo!'s competition started offering bounties, and
- "Entitlement" became a rhetorical tool to dismiss discussion of any business practice that might cost money
You are a security "researcher". Maybe that means you work with a group of bona-fide professionals, maybe that means you're still in high school.
Either way, you have the capability to break things. But, breaking things isn't trivial; you don't expect to spend a few minutes "poking around" and come up with something, especially something interesting.
So you have some choices. You can: try to break things which will give you rewards proportional to the time you spent and the severity of what you find; try to break things which will give you almost no official reward at all; or try to break things and then sell the solution to the highest bidder or make use of it yourself. (Let's assume that people aren't generally in the habit of working for free.)
Now then. You're Yahoo, with millions of user accounts and a not-great track record for security. What would you prefer for the hacker to do, and how would you incentivize them to do it?
You can gripe about "the community" or "entitlement" all you want -- until it becomes sufficiently annoying or unproductive -- but that won't change the end result, which is that companies which give substantial rewards for bug bounties are creating a marketplace where they win by getting lots of good talent to examine their systems without paying by the hour or day for it and the company gets first dibs on the details of the bug.
Companies which don't do this, lose.
People lose. As in, real flesh and blood people. Everyone seems to think, "Ah, they'll just sell it to the highest bidder." You know what, screw that belief, and screw those people who think that way. You do that, you become evil. End of story. Should it be the company's job to ensure this doesn't happen as best as possible? Yes. Does the lack of a reward justify the demonstrably evil behavior of selling vulnerabilities? No. Sick and tired of the idea it's ok to sell a vulnerability wherever the money is. When is the computing community going to step up and put an end to morally wrong behavior like this? We need to ostracize those people, not condone and justify such behavior.
Reportedly there is a lot of money in the security vulnerability dark grey market at this particular moment in time, and that seems to be pushing up the perceived monetary value of these vulnerabilities.
But if you think about it, it would feel an awful lot like extortion for a researcher who's found a vulnerability to allude to the grey market value of a vulnerability in a responsible disclosure discussion. This is kind of what the community is doing by consistently bringing that point up in regards to rewards for such responsible disclosures.
At the end of the day, if the researcher is virtuous, then the black/grey market value of the vulnerability is irrelevant, and so acknowledgement of the issue, followed by rapid action to close the vulnerability, and optionally, a token of appreciation is plenty of reward for the disclosure from a moral point of view.
Now, I'm not naive. I believe that people respond to incentives and when you're talking about incentives, then the black/grey market values do come into the calculation. But that's a purely amoral and pragmatic optimization problem, and therefore not a proper object for the moralizing that we've seen regarding these programs.
I don't have any particular issues with pontificating about how a particular company could be more effective if it increased its bug bounty rates[2], but any pseudo-moral outrage is hollow because it's founded on the assumption that moral and immoral disclosure are relatively equivalent options.
[1] That is, it's not always technically illegal, but I think that the market is fairly universally regarded as antisocial if not a major threat of the day.
[2] Though it would be very difficult for a company outsider to actually accurately determine the value of responsible disclosures to a company. There are a whole lot of vulnerabilities in complex software, and really, any particular disclosure is essentially worthless. I would imagine that the real monetary value of a given disclosure is orders of magnitude less valuable to the vulnerable company than it would be to a potential attacker. For the vulnerable company, they still have a vulnerable product after fixing the particular vulnerability, but for the attacker, they have a successful attack vector by having knowledge of the particular open vulnerability. Also, I can't imagine that the value of a particular vulnerability is proportional to the company's revenue/valuation/etc. which is the metric that seems to always be trotted out when talking about how a particular company's reward program is not generous enough, especially with regards to "billion dollar companies"
in the absence of incentives, the danger is that the white-hats will simply not bother with you. and yes, people lose, but you cannot really lay a moral responsibility on people to help a profit-making company out for free just because if they don't other people might get hurt.
The idea that money always overrules morals is a deep and pervasive belief in the business culture of this country. The vuln market is no exception and is a symptom, not a cause.
When is the computing community going to step up and put an end to morally wrong behavior like this?
About the same time any other industry puts an end to the morally wrong behavior they engage in (read: never).
Or, to push the same buttons as above but in another direction: when did everyone become so entitled to getting exclusive access to a bug/security report about them instead of competing for it in the market like anyone else?
No, it is business. Yahoo has no right to expect you to work for free for them.
This action is taking something that you created (important, unique data) and offering it for auction instead of gifting it to the place where it would benefit everyone.
An appropriate non-IT analogy would be noticing a particular simple way how a Bigcorp chainsaw could be made safer, fixing a risk of hurting the user - you could just let them know "hey, do X and all your chainsaws will be safer for all of us" and get nice fuzzies, or offer to sell them (or other chainsaw manufacturers) the discovery - it's your choice, and although one is much more charitable, both choices are acceptable.
Bugcrowd maintains a list of websites that have bounty programs: https://bugcrowd.com/list-of-bug-bounty-programs/
If you want to get paid market rate for the value you provide as a security researcher, then stop doing work on spec and just hoping that someone compensates you for it.
Standard practice to deliberately insult a waitress is to leave a short tip. That's more insulting than leaving nothing.
And in this case both the "a token of our appreciation" and "short tip" practices could been "meant", and were as a matter of fact taken as "meant" by the sender and receiver respectively.
Just in case you want to know where I stand: if I find $100K in cash and there is no way to trace it back to me I'm not returning it. However, that is different to finding a bug and selling it for monetary gain.
YES!
There seem to be two camps here, neither of which can even fathom the other's position.
On your side, we have people who do a purely logical comparison that non-zero is greater than zero, so this is better.
On my side, we have people who inherently separate tasks done for free for fun or just to be nice, from tasks done for money. For these people, getting paid a pittance is a grave insult, while not getting paid at all (when nothing is owed) is just fine.
I don't really know how to explain it any further. I think the people in your camp just need to understand that the other camp exists and contains a lot of people, and that regardless of logic, giving someone a $12.50 gift card is a massive insult, far worse than giving them nothing. You don't have to understand why, but you have to know that this is how it is for a lot of people.
It seems like there are just two distinct modes. When you do something for free, you're basically doing a favor, and you get pleasure from being altruistic. Once you get paid, it's now an exchange of value, not altruism, so you only get pleasure from being paid. If the pay is small, you'll feel upset because your end of the bargain is based entirely on that, while if you're doing it for free, you switch over.
I could be full of it....
When they traded a shirt for the report Yahoo was implying that they no longer owed him anything, it was a fair barter
Basically, no monetary reward is necessarily expected here. But once you give one, it is a faux pas to give one that looks small in comparison to what is considered the "norm." We even have common insults reflecting this fact, where bragging about something I impressive will invite comments like, "Wow, here is a shiny nickel." The impromptu offer of a clearly paltry reward is understood as a slight.
I think the problem mostly lies in conflating "token of gratitude" with "gratitude". The token is a cheap thing, and has some small monetary value. The gratitude itself is a much more valuable thing, for both the giver and the receiver. Reporters are motivated by doing the right thing, and perhaps getting some recognition for their contribution. The recognition has two parts: recognizing cleverness (you caught something others missed), and recognizing honor (doing the "right thing", reporting it to the affected party rather than exploiting it yourself).
You can't put a price on cleverness and honor. And if you try to, and you come up with $12.50, then you're an idiot. The only thing you can do is recognize it, and show gratitude for the help.
What the OP tried to do was show gratitude and recognition with a token, and some recipients confused the token for the gratitude. It doesn't sound to me like the giver was confused! E.g. he wasn't saying "Here, let me pay you for your time, eliminating the need for us to recognize your cleverness and honor for the cost of a T-shirt." Now you might say that the token was poorly chosen: there is a reason people invented trophies, items that are totally worthless other than as tokens of accomplishment. It's because the recipient will NEVER confuse a trophy for the price of the accomplishment behind it.
Personally, I think a cool little useless trophy would have worked better, and certainly no gift certificates! Being named and honored somewhere on the Yahoo website would be great. Giving a small cash prize, like $1000, would be a classy move.
The bottom-line remains: there was nothing fundamentally wrong with the T-shirt-as-trophy, apart from the (apparent) risk of recipients confusing it for T-shirt-as-payment.
As best I can tell, the gift card was offered without comment. And while the intentions were good, the lack of such a message meant that it was taken badly.
I guess the lesson is, if you're offering only a token of appreciation, make sure the recipient knows you know it's only a token.
Sure. But given the lack of a formal bounty program at Yahoo!, it was a poor choice to pick them as a place for "tasks done for money"
Yahoo's reaction put it into the "paid" category, and then paid an insultingly low amount. That was their error. A different reaction, even just different wording when sending the gift card, could have put it into the "free" category.
If something is given, then they are acknowledging that their thanks/recognition is not enough, but that $x monetary value makes up the difference.
Some people take it as an insult that if thanks isn't enough, they can be 'bought' for $x, where $x is $12.50, or whatever. The reasoning is basically that if you are saying the time taken to reproduce and report the issue is important enough to compensate, you should probably compensate commensurate with what they would expect to make for their time/expertise.
I think most people who report these things do so because they want to improve things, not for the money, so most probably fall into the first camp, but I can understand where the second camp is coming from.
Yes. Giving nothing doesn't give any indication of value - maybe the work is very highly valued but it's not Yahoo's policy to compensate. Fair enough.
Giving a cheap gift attaches a very particular value.
There is a body of research on this, e.g. http://ideas.repec.org/p/zur/iewwpx/007.html
"rewards undermine the intrinsic motivation of volunteers." "a large literature in social psychology [emphasizes] that external rewards can undermine the intrinsic motivation for an activity"
The problem is when the worlds of social norms and market norms cross. The book gives the example of Thanksgiving dinner, and what would happen if you offered your mother-in-law a couple hundred dollars to pay for the meal at the end. Another example is sex: paying for sex makes it a very different situation. (Also note the difference between giving someone flowers on a date and giving someone cash.)
The book describes a research experiment, where participants were paid $5, 50 cents, or nothing to perform a short task of sorting shapes. The people paid $5 sorted 50% more shapes than the people paid less (since they were more motivated), but the people paid nothing did the most of all since they were motivated by helping out the researchers.
This ties in with intrinsic vs extrinsic motivation - if you're getting paid, it's extrinsic motivation, and then you're motivated by whether you're getting your money's worth.
(There's a lot more, but I don't have time to get into it, so check out the book.)
The point is, that if people report bugs for free, it's part of the social norms world, where they are keeping the world safe, making it a better place, etc. If they are getting paid, it's part of the market norms world, and they expect to get paid what the bug is worth. With Yahoo, the lines got crossed: giving a T-shirt is generally part of the social norms world, but giving a $12 gift certificate crosses over into the market norms world, and $12 is insultingly low. This is why it would have been better for Yahoo to give nothing.
Imagine you ask a friend over to help fix your car in exchange for beer. This would clearly not be interpreted as payment, but as a way of saying thanks. Now suppose it turns out they generally like beer but hate the particular kind you purchased, so you feel bad and give them $10 to buy themselves a beer they like. Suddenly, thinking you were doing something nice, you've crossed into market norms.
This, as far as I can tell, is basically what happened.
He tried to leave the $0.25 as a tip. She said, "Oh, no, you must need this," and gave it back to him. Her clear view was that no tip was better than $0.25. I congratulated her, and made up for his idiocy with my tip.
If you don't tip at all, you're either clueless or an asshole. Tipping a quarter is more insulting: you're acknowledging the need to tip, but making it clear you don't think much of the bartender.
I was at a company where someone reported a security problem to the support team. I didn't quite believe it, but they got me on the phone, and within 10 seconds the guy had said the right words to tell me he had found something. So we fixed it.
What then? The company had no formal bounty system in place. I said we should send him something, so I got him an Amazon gift card and sent it to him along with a letter of thanks.
He said thank you back to us.
It all seemed good, but maybe it was just luck of the draw that an Internet mob didn't show up for me the next day.
I think it's great they are making a policy change, and making it retroactive even. My opinion is facing the community and the perceived entitlement people have at getting something for reporting a bug. I applaud those that have policies in place, but the community is shining a bad light on itself with the outrage.
Every act an employee takes and every word they speak while on the job is directly attributable to their employer. No exceptions, no excuses, ever. It doesn't matter if it was against policy, and it doesn't matter how many employees there are. The company must take responsibility. It reflects extremely poorly on the corporate culture of Yahoo and Tumblr that you don't recognize that.
You fail to understand two things. The first is that you have no such "right". You are speaking as a representative of your employer when others perceive you to be. What you or your employer think is irrelevant.
The second is that this isn't about you. Whether you must take responsibility internally is up to your employer. But whether your employer must take responsibility in public is not. It has nothing to do with your "rights". You don't have a say in the matter.
Could you please explain your logic there?
That's how I see things from the outside, I don't have any inside information and it could very well turn out they have most of their staff working on software testing and security.
I found a vulnerability with a large regional service I use a couple of years ago and did the right thing by discreetly reporting it. They thanked me and gave me credit for their service equal to about $50; I felt like they really appreciated my report.
If they had given me swag they give away for free I would have been nonplussed.
That said, yes, big companies really ought to have official bug bounties. But that doesn't mean you have a right to expect them.
Somewhere between the ability to sell vulnerabilities and the implementation of bug bounties.
Why on earth are you undermining Yahoo's official communications in a public forum?
When did everyone stop reflecting on how communication can be improved? Yahoo! wants to better show it's appreciation and gratitude for these security finds. Security researchers don't want their work cheapened.
In the rare instances where my report is ignored, and any attempts to report to a developer (easily found on Twitter) are ignored, I tend to just forget about it. I assume that it gets read, and that eventually it gets fixed. That being said, when you've found a software bug, especially a large bug, the teams treatment of the bug reflects your opinion of the entire company. I noticed that one large website was pushing new registered passwords around in plain text, and I reported this. Six months later, the bug still exists. My opinion of the holding company (which runs a number of popular sites) has dropped significantly.
I think most developers are just happy to be thanked, and are hopeful that their report will be taken seriously and fixed as a priority. Gifts are nice, but a fixed bug and a genuine thanks from a real person at that company are much better.
Twilio, either formally or informally, sent me a t-shirt twice when I found a bug. For me as a programmer, a bug on the 3rd party partner side generally means I spent some amount of my time figuring out that the bug wasn't something I was generating, but rather my vendor. Programmer time has a pretty real value to it, which no one likes wasting.
When I reported the bug and the support person offered to send me a t-shirt, I forgot about the time I spent on the bug and went "Neat! A t-shirt!". Now, when I look at the t-shirt, I couldn't tell you the specifics on the troubleshooting or how it ruined my afternoon 10 months ago. But, I can tell you that it felt like the vendor actually responded to my concerns. Some vendors haven't, and then I do the natural thing and spew vitriol about them across the internet and to my colleagues.
If I didn't like a vendor and they were replaceable, the second that I hit a bug that I felt the need to report, I would just not use that vendor anymore. Anyone who files a bug report has some amount of loyalty to a company that is not worth upsetting.
A third option is to choose neither because the discoverer doesn't think it warrants his or her time to report it. Reporting a security vulnerability requires more than just sending an email. Meanwhile, others who have discovered the same vulnerability may be selling access to it and a company like Yahoo has no idea until severe damage has been done.
However, it is a little much for a for-profit, publicly traded company with $4 billion in annual revenue (mostly made from manipulating how their users spend money) to think that other people should do things for them for free.
I certainly miss the long-ago days when the Internet was an academic community, mainly free of commercial influence. And I love it when people rise above base commercial motives to do something more beautiful. But if we line people up based on their right to complain that the Internet is all crass and money-oriented these days, Yahoo, who led the first wave of Internet commercialization, surely must be near the back.
I'm not sure I understand this. Yahoo! did not have a bounty program that paid out money so if you were submitting a vulnerability you found it would be a little ridiculous to expect any remuneration.
The post I was replying to comes from a "let's all help each other out" perspective, which I like and is the mode I want everybody to be in. But the last people who should be pushing that line are those who are making billions of dollars. Especially so when those people are the ones who led the first wave of commercializing the internet.
It comes across to me as something like, "Hey, let's all work together so I can line my pockets."
Ideally in a restaurant, we'd pay servers real wages. Well the market won't bear that. So we have this tipping system set up. It's by no means ideal, but it works well enough and eventually, tipless restaurants will bowl everyone over with how much better they are and we'll just move in that direction.
Security research needs to be paid. There's too much on the line to just leave this work to unpaid volunteers. But a real security department, for many reasons, is simply unfeasible. Real security has to audit everything. Too much manpower is needed. Bug bounties allow websites to get the security updates they need while compensating researchers somewhat adequately.
It's not entitlement to believe that you should get an appropriate payment for your research. These companies have a responsibility to their customers. They all need to be paying bounties. Even the ones that have security departments should be paying them because people miss things all the time and the consequences of a breach are tremendous. Better pay a little now to avoid a lot of pain later.
Or I can take this bug to an Onion site and auction this bug off to the highest paying blackhat. It would most likely bed used for illegal purposes, but selling bugs isn't illegal if found accidentally.
What I'm saying is this is Capitalism in action.
For better or for worse, cyber criminals started paying black hats for exclusive access to vulnerabilities, and now "good guys" such as the NSA and the FBI are paying grey hats for exclusive access to vulnerabilities. At this point, if you are a security researcher, if you voluntarily disclose a vulnerability you find to a company like Yahoo or Microsoft, even with the fairly generous rewards getting paid out, it's likely they will be taking a monetary hit compared to what an organization like the NSA would be willing to pay.
Fortunately, there are still people who have enough of a conscience that they still care about doing the right thing, as opposed to optimizing for their monetary return (and if you are selling to the government agency like the NSA, you are automatically on the side of the angels, right?). But if you are looking for someone to blame, I'd nominate organizations like the NSA and the cyber-criminals. That's not particularly constructive, though --- the world is the way it is now, and it's unlikely to be something that can be changed back to the "Good Old Days" (which, for the record, was never really all that Good).
Was that clear at all before, or was the "reward" just coming from generic Yahoo? It seems like he was essentially creating a de facto company policy, without company approval.
They're surely paying a lot for their security team. And they know (or should have known) their competitors are offering substantial bug bounties. And they knew (or should have known) that one of their own people was spending significant time and money rewarding people reporting bugs.
The managerial fuck-up I see is not putting those things together and saying, "Hey, we should have a real bug bounty program if we don't want to look like cheap jerks." Apparently they were trying to rectify that, which is great. But if I were a manager there, the question I'd be asking is, "Why did we take so long to recognize and respond to this problem?"
Remember everyone: if there's no bounty program in place, reporting bugs means that your expected value for those bugs is $0. If you get more than that, that's awesome, but don't expect it, or act like it's deserved; it's not. Enjoy your Yahoo swag and go on with life.
Yahoo didn't agree to give you money, didn't hire you to test, and didn't even say "hey, can you take a look at this?". It's completely irrational to then say that a gift that they provided you is an insult. In fact, I'll go further: it reflects very poorly on your own character, and not theirs.
It's too bad that, in his role, he was or appeared to be acting on behalf of yahoo. The impermeability of corporate behavior meant nobody on the outside really knew the difference before now.
I really don't get the response above.
I work with so many people who have no hustle. No compulsion to go above and beyond the constraints of the situation.
This position openly advocates that employees should only be workerbee drones who stay within the rules of their corporate overlords
and/or
Only succeed, never make mistakes.
Both are fatally toxic attitudes. Fuck Matthew Shapiro.
so while i can't speak for him, what i can say is that i've known him for many years, worked closely with him on very large, global issues, and have found him to be a very standup, forthright guy who strives to make the world a better place.
It's just as well I'm not a security researcher.
Edit: Wow a lot of drive-by-downvotes. I'm not serious guys, but I hope I have made some people think about the moral issues involved. It's not as clear as people are making it out to be in other comments on this post.
Edit: why would anyone downvote this? Other than the owner of the useless comment anyway... For the record, comments on HN should have substance, it's in the guidelines when you signed up.
It's my policy to downvote any comment that complains about downvoting. However, it would be better in this case to not even respond to GP's inane scribbling. Trust the downvoters to get around to it eventually.
It saddens me to see so many who feel this way.
Even sitting on it is immoral, but in a lesser way. Users would then only lose in the case someone more malicious finds the same problem.
Refuting or discussing the argument would be interesting; painting the suggestion as objectively wrong using emotive terms doesn't really move us forwards.
Still, I think that the moral action (wherby "moral" I mean being disinterested and caring about outcomes for users) is fairly obvious in this specific case (Yahoo, has a good rep for taking security-issues seriously) - send them the patch that you have, regardless of compensation.
Usually, behavior that would be shitty if done offline is just as shitty online. There is a fine line between freelance security research for bug bounties, which is basically crowdsourcing security testing, and rank extortion.
That's why in my jurisdiction you can get fined up to 2000 Euros for that (a realistic amount is a low double-digit amount -- if nothing further happens, of course).
Imagine if you were outside shoveling a decent amount of snow then your neighbor asked you to help shovel his property. If you haven't shoveled snow before, it can be a somewhat laborious task. After you were finished your neighbor said "Thanks for helping me out" and then gave you 50 cents.
It would have been better if they just said "thanks."
Did the neighbor promise to give something in return before you began? Because if you start something with no promise of anything in return, then you shouldn't expect more than a thank you. To perform such a favor, then to expect something in return that was not offered reflects badly on you.
Or maybe your analogy doesn't work in this case.
I used the example of neighbors because they are (in some neighbors) neighborly, and do altruistic things for each other. When there is a big snowfall in my neighborhood, all my neighbors come out and help each other shovel. There is mostly apartments here, so very few people own a snow blower and everyone needs to dig their cars out. I live alone and whenever someone sees me shoveling by myself, someone always comes over and helps me shovel without expectation of anything in return and its always a different person from last time.
When I make baked goods, I usually stop by the people who live in my building's apartments to see if they would like some of what I made.
I once needed help carrying something up the stairs, so I just knocked on a neighbor's door and he came out to help me. This it the neighbor who doesn't have to pay for internet because I let him use my WiFi.
There's somewhat of an "rule" if someone is in need of something, they just need to ask, and everything works because the give and take is pretty even, nobody takes and takes and takes without giving.
The point is, the person shoveling snow did it to be nice, and to help a neighbor out. Once the person being helped offered a reward in return, they are now putting a monetary value on the help they received and the value was insultingly low, saying "this is how much I value you." If they just said "Thank you very much" then it just remains as an altruistic gift to the community.
I used the neighbor example to make altruism more evident, to not think of it from a purely business prospective.
Yahoo have 2 choices to not offend people:
1) Bug finding is simply an altruistic act from the community.
2) Pair fair compensation.
Just because someone gives you pocket change for helping them out doesn't mean they put that particular monetary value on your help, it could be just what they had on hand. As in, "here's a little more than just my thanks". You're the one getting needlessly offended. You could always turn down the offer, which you shouldn't because it could be considered offensive to refuse. Out of all the options you have in that case, you choose to be offended. That makes you a bad neighbor.
I fail to see how one can expect any form of compensation whatsoever from Yahoo when none was offered in the first place. Just because some places offer bounties doesn't automatically mean everyone does. If you expect compensation when none was offered, then it's your problem with being offended when not getting anything.
Was it poor form to expect grandiose payouts from a company without a bona fide bug bounty program? I think so.
Is it even sadder that, up until publicly shamed, Yahoo had no bug bounty program whatsoever? Definitely.
This is so wrong, it's not even funny. Bug bounty programs are awesome -- I've participated in many of them -- but they're a tiny, tiny, TINY minority. Of the top 500 websites, how many have bug bounties? 10? That's not an industry standard; it's a nicety.
That's changing, but seriously, there's absolutely nothing wrong with not having a bug bounty program right now.
However, would it be fair to say that a majority of Yahoo's competitors have bounty programs? Google, Microsoft, etc.
"This includes, of course, a check for the researchers at High-Tech Bridge who didn’t like my t-shirt."
Which, frankly, was a pretty cool gesture of thanks from the person writing. In a way I'd like them to keep the T-Shirts regardless of adding the monetary bounty.
Putting together a bug bounty program for a company like Yahoo is a lot of hard work with tons of tiny gotchas. It can take forever, and it's never ready when it needs to be. Looking forward to it.
I think what this guy was doing was awesome; he clearly understands the value of the work researchers were doing, and he did what was in his power to thank them. Compared to getting no reaction, or a terse email, this is probably in the top 20% of responses to random vulnerability disclosures.
It's not about the money, it's about sending a message. And instead of chaos and people wearing masks, we've got vulnerabilities, and the idea the Yahoo actually values its users.
Lets see, the average monthly income in the states is about $4k. A decent cheap wine bottle is about $10.
Now compare that to Yahoo's income and that $12 store credit they gave him.
A more accurate scenario would be if the neighbours sent him the wine cork.
neighbor family : nice bottle wine :: hundreds of thousands of customers : t-shirt
Hmmm. Your value function appears not to monotonically increase.do something for someone who never offered to give you anything but you expected a thousand dollars anyway : they gave me something because they thought it was nice
According to the Google reward program (http://www.google.com/about/appsecurity/reward-program/), a vulnerability of this type seems to be worth somewhere in the $5,000-$10,000 range.
Granted, the security researcher lamenting the lack of Yahoo's appropriate bug bounty program has no right to be righteously indignant about a gift certificate, but it seems clear now that Yahoo knew there was a problem with their bug bounty program and were in the process of fixing it anyway. I have no idea how much money such a vulnerability would be worth on the black market, but I suspect it is more than $12.50.
If I am ever in a position fortunate enough to have to make this sort of decision, I can say that I will be keenly interested in keeping these security researchers on my side. That appears to be exactly what Yahoo is doing now, so kudos to them!
Also if a nice bottle of wine costs $100 from a neighbor making a median of 100K a year scale it up to a company with the profits of Yahoo and do the math on a tshirt.
What's it worth to Yahoo if someone finds an exploit that can expose all users? A friendly smile and handshake? Or another snarky reply on the internet.