Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You let the market decide. Google could purchase the bugs on the same market blackhats do.


Google directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions:

* They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable).

* They don't require you to actually build a reliable exploit chain.

* They pay up front, not in tranches.

* They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.


They pay in plain old money, too. On the market your counterparty will be a criminal who is trying to scam you every step of the way.


Not so much, the grey market is pretty well structured.


Is there anywhere I could read more about this?

Sound very interesting!


The Grugq has done several interesting interviews/articles on the industry.

There's also a couple of Darknet Diaries episodes with similar interviews.


we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.


I would say that maintaining legacy systems as a software engineer is effectively "using bugs to make money" and very much an "economically legitimate activity".

If old systems had no bugs/issues, companies could do without the maintenance burden altogether (which includes even systems not being evolved/extended).


Companies sometimes reward their employees with important bug fixes. When I worked on a big dev team, we'd even decide what were the most important fixes and give people a special 5k bonus or something.

But they weren't security issues necessarily. I never thought about it, fixing a huge performance issue is big. A security fix that gets caught early makes no noise so you just don't know how important it would have been. We also once had a really terrible bug that lead to lots of customers getting effectively attacked.


> Companies sometimes reward their employees with important bug fixes.

Potentially creates a misaligned incentive to intentionally hide bugs in the code you write so that later you can fix it and get the bounty.


> using bugs to make money

Aka security research.

It's one thing to hold something for ransom ("give me $5M or I release the 0day"). It's another to sell a valuable piece of information ("give me $5M if you want the 0day"). As long as you're only offering the bug to the company who would be impacted by its release, there's nothing unethical about asking for payment.

Maybe you think that, ethically, all bugs should be reported, regardless of payment, because it prevents harm. Well a lot of things prevent harm that we don't all take it upon ourselves to do voluntarily. Should everyone do all safety-related work for free? If we don't want to do it for free, should we not do safety work at all?

If the company really wanted it safe, and they can't make it safe themselves, they can pay someone else to make it safe. If they aren't willing to do that, then nobody is obligated to do free work for them, because we don't require anyone else to do safety-critical work for free. Let's not forget, this isn't a scrappy startup struggling for a seed round, this is one of the world's largest corporations with billions of dollars in cash. If they want your labor, make them pay for it.


>Well a lot of things prevent harm that we don't all take it upon ourselves to do voluntarily. Should everyone do all safety-related work for free?

Thanks for putting it like that, it changed my opinion on the subject.

If it's normal to expect people to be compensated for other security work, it implies it should also be normal to compensate security researches.


"Crime" is very flexible term. One country's criminal is another country hero. Maybe the author would sell the vulnerability to an organization making exploits for government use.

"Safety" is also a relative thing, when the world is safer for one party, it is usually worse for another.


Having secure browsers, encryption etc. actually clearly benefits the world. No “but think about the children/terrorists” please.


As our surroundings grow more secure, the justice system variant of swatting becomes a greater portion of the threats to worry about. There will be abuseable bugs and situations in our non static world, there is no way we'll ever have perfect security of anything. So a motivated actor with a grudge should be able to plant something a place you provably beyond reasonable doubt have sole control of, given enough time. How do you propose then that we secure deniability once the justice system is wielded as a weapon against the innocent, when everyone feels that there is no reasonable way defects exist and could have been used? Just look at the British post office scandal, real world justice systems have already operated under the assumption that software doesn't have bugs for decades, which speaks volumes on their inclination to believe that they both exist and are used by a unknown third party with ill intent. Thus the widespread trust in that things are secure is a threat in itself. And unlike airports we don't need the users to have an artificial sense of security for computers, networks, software, and digital services to be viable markets.


Brain dead moral relativism argument. The question is whether eg. a group trying to scam elders out of insurance money or a Columbian cartel to hack local politicians to do blackmail, or South Sudan to hack Darfur or whatever, should be allowed to compete with the companies making products for their own exploits.

99.999% of people will agree that reducing software vulnerabilities is desirable if they're able to understand the question, including the bad actors themselves a lot of the times.

The situations like bad state actors are already not bound by laws, and things like keeping activism legal are better fought for through other ways


> The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier.

Yeah let's see how this plays out, paying people less than their time is worth for RCEs.


> we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime.

"Making money from bugs" is not solely a black-market activity. There are plenty of grey and even white hat activities in this market.


Finding bugs is hardly a crime, selling them even isn't.

Now exploiting them? Yes that's a crime.


> using bugs to make money [is a crime]

No it’s not lol


Well, someone did decide to tell google about this in exchange for a thousand dollars (albeit unclear how much the money was the motivator). Doesn't that mean the market did decide in google's favour?


Someone decided to tell Google about this in exchange for an unknown amount of money, chosen unilaterally by Google at a later date, at which point the market value of the vulnerability is $0.

There's no way money is the motivator.


Money is not the only coin to pay someone in.


Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.


> Blackhat markets will always be able to pay better.

... than Google?

> Selling to Google though you aren't chancing jail time.

Why would you go to jail for selling a vulnerability? It's free speech.


"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.


Has anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.


It would be absurd to jail someone for accurately describing a bug on their blog or whatever.

Not so much for taking money from someone who the buyer should know has no reason to be interested in buying the information. And either you know who your counterparty is, in which case you know that they are using it nefariously, or you don't know who your counterparty is, in which case you know that they are using it nefariously. Any court and any jury should see straight through this.

Similarly if you figure out how to get the ATM down the street to give you free money, and you "accurately describe the bug" to people who pay you, and they use it to steal money from the ATM, expect to be charged for participating in, and in fact being an instrumental enabler of their crime. Because it is beyond all reasonable doubt that you could've believed they could have been interested enough to pay you for any other reason.


Has anyone actually been charged and convicted for disclosing knowledge of a vulnerability in exchange for money with no further collusion to commit a crime?


Jeremy Jethro seems to be an example. His lawyer claimed he had no knowledge of what the exploit would be used for, and that it didn't even work, but he ultimately pled guilty to criminal conspiracy.


Hmm. Are you aware of any publicly identifiable security researchers that openly talk about selling their exploits on the black market?

Since it's all so legal and risk-free, you'd think selling an exploit for a million bucks would be quite the feather in their cap!

It may also be helpful to visualize being interviewed by the FBI and being asked "Did you sell this exploit? To whom? How much did you receive? For what purpose did you think it would be used?". And to remember they already know the answers to these questions, and lying to the FBI is also a crime.


My question stands.


"this vulnerability is being sold for research purposes only and must never be used outside of a tightly controlled research sandbox"


courts are very good at reasoning about things like this and figuring out its bullshit. Zerodium is probably the closest you could get to some reasonable denial about this. Selling an exploit on crime.com for "research puposes only" will get you laughed at on the way to the cell.


Telling someone the steps to rob a bank world probably catch you some charges, I'm assuming.


Are true crime authors going to jail? Or even authors of heist fiction?


No, it wouldn't.


They would be broke quick.


In the past I would have thought this would incentivize finding bugs that might never be found. However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.


> In the past I would have thought this would incentivize finding bugs that might never be found.

Isn't that a good thing?

> However it is now clear that all bugs that can be found will be found. So this makes a ton of sense.

If Google can find all the bugs nowadays, presumably with AI, why still pay a bug bounty? At least by this logic, bug bounties make less sense now.


Because there’s still a sizable group of people who see $1,000 from Google as more than $1,000.

Even a resume item.


Sure they make sense — you need some incentive to drive the price to zero.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: