Bug Bounties Aren't Silver Bullet for Better Security (infosecurity-magazine.com)
Many organizations may find they're better off hiring pen testers and in-house security researchers directly than running bug bounty programs, according to new MIT research. From a report: The New Solutions for Cybersecurity paper features a surprising analysis of bug bounty programs in the chapter, Fixing a Hole: The Labor Market for Bugs. It studied 61 HackerOne bounty programs over 23 months -- including those run for Twitter, Coinbase, Square and other big names -- and one Facebook program over 45 months. It claimed that, contrary to industry hype, organizations running these programs don't benefit from a large pool of white hats probing their products. Instead, an elite few produce the biggest volume and highest quality of bug reports across multiple products, earning the biggest slice of available rewards. It's also claimed that even these elite "top 1%" ethical hackers can't make a decent wage by Western standards.
But their are a bullet in the arsenal against bugs...
They're getting bug reports. Would they have gotten those without the bounties?
Would in-house researchers find the same ones? Especially if only the elite are finding them.
And why would anyone think bug bounties should be a replacement for a job?
Write good code by hiring on merit only.
Keep the inner core of skilled coders working hard on quality productive code.
Once low quality code is part of the company it is hard work to go back and try and find good workers.
Domestic spying is now "Benign Information Gathering"
Sounds like another case of the Pareto principle where a small number of people (the elite few) find the majority of the quality bugs.
.1% or something, but I'm somewhat more skeptical about the claims that not even the elite can make it as bug bounty hunters.
I don't know if these elite few are doing this full time, but I'd imagine that they aren't if they only make ~$35k. Most could easily get six figures doing security consulting work, and I would expect that a lot of them do and only do this as a hobby or for the added notoriety. I looked up the pwn2own contest and the main page reports one guy hauled in over $100,000 in the 2018 contest, so some can clearly make a good living doing nothing else if they don't want to. I don't know if those guys are the
Who said it's supposed to be a full time job? Bounties aren't jobs. They're rewards for ethical disclosure
Loonix sycophants cheerleading for loonix toreball's little hobby OS and other garbage Open Sores abominations riddled with shit security.
All they are is free pentesting for companies who do not want to pay for pentesting or appsec engineers. They're also an "easy" button for shitty developers or developers who aren't educated in how to write secure software.
Basically, the community uses bug bounties to get recognition; but at the same time the companies abuse them. Sad really; as a security engineer, you should not participate in this shit.
Apparently the people in the "security industry" are only "ethical" if you pay through the nose for them to be "ethical".
I'm pretty sure that's not how this "ethics" thing works anywhere else, so it's not surprising it doesn't actually work that way in the imperial textile industry that calls itself "computer security". Funny you lot need MIT to figure that out.
"Inbred Nazi faggot imagines visually online how he'll be tortured for eternity in retard republican hell, news at 11"
What kind of credulous moron believes they are about improving security or (LOL) creating work for unemployed engineers?
"Triggered jew faggot compulsively repeats itself; drinks n1ggerpiss in frustration"
I sure hope my boss doesn't read this article, since yesterday I held a long presentation for the whole board of directors entitled: "Bug Bounties -- the Silver Bullet for Better Security?" where my conclusion was a resounding "YES!"... They applauded. I got multiple pats on the shoulder. Everyone was happy. And now this.
I came here, initially, to see the type of stuff being said by "loonix sycophants" back circa 2005 & there was a ton of bs, lies, & crap said by them - such as "we can't be infected" (or much like it - just like Apple tried & amended to "no PC viruses" (fucking marketing asshole BULLSHITTERS)), & being a programmer & network admin for decades I knew THAT was bullshit TO THE MAX. The REAL deal is "security by obscurity" that Linux enjoys.
They've largely CUT THE CRAP since then though on that note & why? I used this against them here a few times, makes a point:
What PROVES that? ANDROID DOES (more attacked than Windows by FAR, even over time, though both have had the SHIT beaten out of them (which is, in a way, GOOD - you learn by it, just like in life)) & yes, ANDROID is a Linux (stupidly using "DALVIK" (fucking JAVA which is, security shit)). Now, some of the dorks around here will TRY DENY that, but good luck.
NOW, on the FLIPSIDE?
I've used Linux since 1994, & again in 1999, then in 2010 (where it ALMOST had me) & since June last year up to now (& intend to KEEP using it, does all I need & devtools like FreePascal + it's Lazarus IDE are FINALLY not CRUDE BULLSHIT)
I've also found LINUX IS SIMPLER TO SECURE than Windows (& trust me on that, I know Windows having used it from Windows 3.0, thru all 9x series, all NT series (NT/2000/XP/Server 2003) & programmed on it for DECADES.
Securing Linux is pretty much only 3-4 files to shore up (rest is in your modem OR firewalling router (usually most modems, blow, but not all here)).
APK
P.S.=> Problem imo, nowadays? Companies "want to save $" & are hiring ROOKIE NOOBZ & dispensing w/ guys of age + experience (who yes, COST more but are worth every penny vs. noobs) - oversimplifying things, but as an AC, /. only lets me post SO MUCH (far less than registered users, even when they do AC submits) so, there you are... apk
Like in any way, you would want to have as many bullets as possible at your disposal. However, you fight with the army you have, not the army you would like to have, so you need to fit everything within your budget.Having a dedicated pen tester is cool, but a lot of them just go through a set of tools or tests and then that's it. They dont necessarily know the best ways to exploit a particular system.
But clueless people keep looking for it. Always the same with those that mistake technology for religion that will solve all problems in magic ways.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
jewgger cocksuckers are nazies. Exterminate them.
Hideous hag pinned under rock for eternity - claims burning smell distracted her
I worked in a very popular bug bounty for a short amount of time. It's about as pure a meritocracy as you can get. Young folks from all over the planet were working very hard to find bugs and some of them did very well for themselves. I would say it's clear that the bug bounty gave them the foothold and the financial backing to start a career in security.
Only the dumbest assholes on the planet think you can survive solely on a bug bounty. However, if you run it properly (which is exceedingly difficult) you can get some real value from it while giving an opportunity for folks that are new to the industry a medium in which they can gain valuable experience and possibly launch a career.
Saying X is not a silver bullet for Y is a misleading rhetorical tactic. If X is better than !X for Y, then X is one of the solutions. That it is not a complete solution is irrelevant. If there is a Z that is better than X, then that is a valid argument.
X will not solve Y is typically used by vested interests against X not people who are genuinely interested in solving Y.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Ah, the UNIDENTIFIABLE anonymous expert on SECURITY who knows all - Lookup Google EFast & tell us another one!
* CLUE: Android uses a LINUX core stupid. That's NOT MacOS or Windows, dummy - that makes it a Linux.
APK
P.S.=> You're a joke & all you can DO is show everyone how much you're AFRAID of me by STALKING me by UNIDENTIFIABLE anonymous posts because it's obvious I've TOTALLY FLOORED YOU BEFORE under your registered "luser" (probably a few sockpuppets) accounts here before & have it bookmarked to TOSS BACK IN YOUR FACE - too obvious... apk
"Of course, a blacklist-based approach is really a pretty bad way to secure a system, and does little to protect against many modern threats like Spectre and Meltdown" - by UNIDENTIFIABLE anonymous NO BALLS WORM who STALKS ME on Monday January 21, 2019 @04:36AM (#57994726)
Here's SPECIFIC EXAMPLES of hosts stopping an INTEL cpu based attack (done by javascript MELTDOWN & SPECTRE) https://www.bleepingcomputer.c...
Now MELTDOWN https://spectreattack.com/spec... - Here IS another (spectre) https://meltdownattack.com/mel...
BOTH NEEDED LOCAL CODE DOWNLOADED TO WORK
3 proofs hosts can stop Meltdown/Spectre/Portsmash etc. by blocking the source of download!
APK
P.S.=> Unbelievable - between THIS post & my other one https://tech.slashdot.org/comm... to you PROVES you're stupid... apk
"Of course, a blacklist-based approach is really a pretty bad way to secure a system" - by UNIDENTIFIABLE anonymous NO BALLS WORM who STALKS ME on Monday January 21, 2019
See subject: MANY evidences to the contrary https://tech.slashdot.org/comm... & YOU DENY 'EM??
"Whitelists and heuristics are far superior to your blacklisting for detecting and blocking such threats." - by UNIDENTIFIABLE anonymous NO BALLS WORM who STALKS ME on Monday January 21, 2019
Whitelists & heuristics GENERATE FALSE POSITIVES LIKE MAD - hosts specifics don't & you can EASILY EDIT HOSTS ENTRIES to remove any stupid (can you with a binary's heuristic algorithm? NO).
APK
P.S.=> Between this post, & this one where YOU BLEW IT on spectre/meltdown being STOPPABLE by hosts https://tech.slashdot.org/comm... & ANDROID does use a LINUX core (certainly not MacOS or Windows) https://tech.slashdot.org/comm... ??? You have PROVEN yourself STUPID, lol... apk
There are no silver bullets for anything.
there most certainly is a "silver bullet" that will solve every problem
the "silver bullet" is keeping the customer happy.
they keep sending checks, you keep paying employees, the company succeeds
but you do seem to be having fun pretending you know something
"You basically have to already be able to run your own evil code on a machine in order to PortSmash it." from https://www.theregister.co.uk/...
* RoTfLmAO @ U, you WEEZIL stupid UNIDENTIFIABLE anonymous STALKER of me... lol!
(it's NOT the only way you can be attacked by Spectre/Meltdown/Portsmash etc. BUT it IS the way it's used against folks - far more effective DELIVERY & SURFACE AREA OF ATTACK IS DONE BY ONLINE METHODS vs. local file based off say, a DvD of an OS (or bushwhacking other code on distro disks)).
APK
P.S.=> See subject & as an ADDENDUM to your STUPID statement here
"Of course, a blacklist-based approach is really a pretty bad way to secure a system, and does little to protect against many modern threats like Spectre and Meltdown" - by UNIDENTIFIABLE anonymous NO BALLS WORM who STALKS ME on Monday January 21, 2019 @04:36AM (#57994726)
Vs. my OTHER Spectre/Meltdown PROOFS hosts CAN STOP THEM https://tech.slashdot.org/comm... ... apk
"Whitelists and heuristics are far superior to your blacklisting for detecting and blocking such threats." - by UNIDENTIFIABLE anonymous NO BALLS WORM who STALKS ME on Monday January 21, 2019 @04:36AM (#57994726)
See subject: Everyone KNOWS whitelists = maintenance nightmares (makes users bitch) & heuristics = known for false positives!
* DAMN YOU ARE REALLY STUPID!
APK
P.S.=> Between these posts blowing you away too per "yours truly" on every so-called 'point' (bullshit) of yours:
Vs. Portsmash hosts work https://tech.slashdot.org/comm...
Vs. Meltdown/Spectre hosts work https://tech.slashdot.org/comm...
ANDROID uses a Linux CORE (sure not MacOS or Windows) o it IS a Linux (stupidly using JAVA ("dalvik") - a security nightmare) https://tech.slashdot.org/comm... & "ALL THOSE EYES" bs SPEWED GARBAGE this ARTICLE PROVES that way off too!
Google EFast IS an example of CLONED "OpenSORES" being ABUSED TOO, stupid... apk
"Many organizations may find they're better off hiring pen testers and in-house security researchers directly than running bug bounty programs"
There is no reason you can't do both. Hell the ones you hire can even be eligible for the bounties as bonuses. It's a built in incentive program.
"Instead, an elite few produce the biggest volume and highest quality of bug reports across multiple products, earning the biggest slice of available rewards. It's also claimed that even these elite "top 1%" ethical hackers can't make a decent wage by Western standards."
Obviously the bounties are too low and/or the bugs aren't being acknowledged properly and paid out.
"classic Windows hosts trick to block the Coinhive or Crypto-Loot domains" - https://www.bleepingcomputer.com/news/security/a-new-player-joins-coinhive-on-the-browser-cryptojacking-scene/ - BLEEPING COMPUTER
ZD NET http://www.zdnet.com/article/how-to-use-a-hosts-file-to-improve-your-internet-experience/ "Hosts files really shine by letting you block ads, spyware sites, malware sites, & tracking sites"
SANS ("A related approach to the DNS issue is to create a hosts file on each system that sends requests for spyware to some place else" hosts by myself & RAMU right @ START of "malware explosion" mid 2005 on) https://isc.sans.edu/forums/di...
Aryeh Goretsky/ESET/NOD32: hosts = good security https://it.slashdot.org/comments.pl?sid=7442373&.cid=49747129/
Oliver Day (SYMANTEC/SECURITYFOCUS) http://www.securityfocus.com/columnists/491/
Spybot S&D uses hosts.
APK
P.S.=> Malwarebytes' hpHosts hosts & RECOMMENDS my program forum.hosts-file.net/viewtopic.php?f=5&t=4290
See subject: It was MY PLEASURE publicly DESTROYING you (who STALKS me by UNIDENTIFIABLE anonymous posts) as usual!
* RoTfLmAo!
APK
P.S.=> Oh, I know you'll come along & "downmodbomb" my points ANNIHILATING you PUBLICLY but then I'll just do my usual & RUN YOU DRY of your ABUSED "downmodpoints" (since you have a registered 'luser' account on /. & use AC to harass me + then downmod me later when I crush you, lol) as I can post UNLIMITEDLY unlike MOST AC posters - go for it, I'll just BURN YOUR ASS as always, lol... apk
"successfully able to carry out a SplitSpectre attack against Intel Haswell/Skylake/AMD Ryzen processors via... Firefox's JavaScript engine" FROM https://it.slashdot.org/story/...
Done by Javascript HOSTS = mitigation that STOPS sources of attack BLOCKING them from user access via online methods & that's that!
* YOU LOSE, loser.
APK
P.S.=> Oh, I am REALLY enjoying KNOCKING THE PISS out of YOU you little SCUMBAG that STALKS me on /. by UNIDENTIFIABLE anonymous posts (then downmod bombing me using your doubtless 1 of MANY sockpuppet accounts you keep here to 'farm karma' to CHEAT the easily cheated "downmoderation system" of /. - fine by me - I'll just REPOST again, NULLIFYING your EFFETE ineffectual "wannabe weapon of WEEZILS" (like you) just to see you DANCE & SQUIRM, bitch)... apk
A lot of hackers stopped submitting to bug bounties, because of companies like Facebook never paying their bounties.
There was always an excuse as why they didn't have to pay. Eventually after submitting multiple bounties and not being paid, they just stop submitting.
Most probably stop looking for bugs, others start selling them on the black markets so they can at least get paid for their work.
Bug Bounties only work for as long as the companies keep their word.
Facebook is NOTORIOUS about not paying for them and have screwed countless individuals out of their bounties.
They will only pay official companies, but their default policy is to try to find any way possible to not pay if it is an independent researcher.
I still have multiple emails where Facebook Developers told me a bug in their system needed to be fixed in EVERY router in the entire world to prevent CSRF protection instead of filtering CSRF in their system. Then they implemented CSRF filters in their system, but I never got paid for that bounty or any bounty I have EVER submitted to Facebook, which are numerous.
It is VERY well documented online and in blogs, almost as much as Google Adsense stealing from publisher (which has been proven and getting exponentially worse.)
How can you expect bug bounty programs to work after the hackers and developers wise up to not being paid and instead completely screwed over?!
Its a constant to discover bugs and fix them. Then you have software improvements which could add even more bugs. Windows is a perfect example of software that has no end to bugs, you will never reach a maturity where they would end.
I'm not even CLOSE to being done MAULING him - the stupid little cocksucker lies about me, libels me, downmod bombs me constantly.
* No, no senor - I'm FAR from FINISHED fucking that little STUPID cocksucker the FUCK up... PAYBACK is a BITCH!
APK
P.S.=> Especially to disgusting "ne'er-do-well" DO-NOTHING BITCHES that STALK me by UNIDENTIFIABLE anonymous (& sooner or later, he'll FUCKUP like c6gunner did using his "registered 'luser'" account IMPERSONATING me & OBVIOUSLY FORGETTING TO SUBMIT BY AC to harass me instead https://linux.slashdot.org/com... (just because I challenged him FAIRLY to show he's done better work than mine AFTER putting down my work others like/use/praise in my hosts engine ALTERING their praises no less) - once he does that & he will inevitably? Oh, I am going to RIDE HIS ASS RIGHT OFF /. - won't be a first either, I've done it before PUBLICLY HUMILIATING "not men" like those doing that (punks & WEEZILS - wastes of LIFE)... apk
> Coders are useless without good specifications, good practices and good languages.
Good practices make a world of difference. Peer review, for example, is huge.
Good specifications, or requirements, are critical. Just as good developers learn how to write particular functions, they learn methods of finding out exactly what the requirements are. So "the requirements weren't clear" isn't an excuse for a a software engineer to have done poorly, it's what they did poorly. There are good ways of getting the requirements defined, and it is the programmers job to learn those methods and use them.
I'd say "good languages" are overrated by many. "It's a poor craftsman that blames his tools." One language has benefits and drawbacks compared to another, and being able to choose the language (and style of language) that best fits a given task is useful. If the code is crap, though, it's not because the language sucks, it's because the programmer did a poor job. It is true that trying to write code to query set-based data in Python instead of SQL is likely to result in crappy code.
> Test driven design beats most other forms.
Test driven development is at least a consciously-chosen process. That's certainly better than no methodology, just writing whatever code and throwing it on production with no thought to process.
Silver bullets work only against werewolves, bugs have to be squashed.
That's very questionable, actually. It's how the security s'kiddies do things now, but they haven't been making much headway actually structurally improving security very much at all. You need to understand what the adversary is doing, but copying him verbatim isn't getting you the leg up to actually secure much of anything. See also: Bruce Schneier's bit of math about the hypothetical software with a million exploitable security bugs and the lone "black hat" vs. the team of a hundred "white hats". Spoiler: The lone guy still has a good chance of winning.
DEA-agents likewise need to understand how drug lords work, how deals are made, how to make fake purchases that'll stick in court, that sort of thing. Securing means you need to understand the adversary, not be the adversary. That's the idot's game. As they say: Never argue with an idiot. He'll drag you down to his level then beat you with experience. That's exactly what the "white hats" have been doing, with more stupidity besides.
Undo errant mod.
No shit: you get better results for paying people to work rather than asking them to work for free and only pay them if they find something. Nobody is going to make a lot of money finding bugs in my crappy website or application. Bug bounties only make sense for huge, juicy targets like Google, Apple, Microsoft, etc., and critical infrastructure like OpenSSL, Apache httpd, ntp, bind, etc.
Look everyone it is that retarded bitch Alexander Peter Kowalski's even more retarded friend. That one that talks just like him, always posts as AC, and manages to say dumber shit than he does.
Look it is the retarded bitch APK pretending there is support for himself. If you aren't Alexander Peter Kowalski then you are an even bigger retard than he is since he isn't even trying his usual bitch tactics to defend himself of repeating himself, calling people names, or deflecting from valid criticism.
Retarded bitch Alexander Peter Kowalski you really need to stop talking to congratulating yourself. You think you won but really just showed everyone how much of a spastic retard you are. I see you are still gay wanting to ride some dude's ass but at least you aren't wanting to have violent butt sex with him.
Report co-author and CEO of Luta Security, Katie Moussouris, doubled down on the findings, claiming that independent researchers are “better off pen testing or living the good life of in-house research staff.”
Katie started the bug bounty program at Microsoft and now owns a company doing pen testing. Guess what the report recommends? I wonder what it would recommend if she were still heading up a bug bounty program? Maybe I'm overly cynical, but it appears the authors are trying to structure bug bounty programs to be more like they are, security consultants. If you're going to propose such a large change, why look at only one data set? Even the Hacker One CEO said their data set isn't representative of the whole.
It's clear from the news article, which has a very clickbait-y title, that there are ways to improve bug bounty programs. As others have pointed out in comments here, it's still a useful tool. There's a blog post linked in the news article gives a good overview. That should've been the Slashdot submission.
When you grow a pair of balls & use your real name? Then you can talk. Until then you're nothing but a "ne'er-do-well" do-nothing worm STALKING me by UNIDENTIFIABLE anonymous (some "accomplishment" on your part (not)).
* You fear me - this much is obvious!
APK
P.S.=> I say that because you HIDE from me the way you do which only proves I've dusted you before beneath 1 of your doubtless MANY 'sockpuppets' accounts on /., lol... apk
See subject: & use your real name? Talk. You're a "ne'er-do-well" do-nothing worm STALKING me by UNIDENTIFIABLE anonymous (some "accomplishment" on your part (not)).
* You fear me - this much is obvious!
APK
P.S.=> I say that because you HIDE from me the way you do which only proves I've dusted you before beneath 1 of your doubtless MANY 'sockpuppets' accounts on /., lol... apk
See subject: You're hiding behind UNIDENTIFIABLE anonymous troll posts STALKING me like the psycho weakling you prove you are.
APK
P.S.=> You're disgusting... apk
Looks like the retarded bitch Alexander Peter Kowalski is mad that more of his bullshit has been exposed. Maybe you should go stalk arth1, Ol Olsoc, JustAnotherOldDude, Zontar the Mindless, or Khyber instead. Maybe Zontar can send you another non threatening post card that you can report to the police.