It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What's worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded / tax funded papers) Which is even worse, I think I'd be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
"all he did was scrape PDFs for mostly public funded / tax funded papers"
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
I have not done a deep dive so I could be wrong, weren't these papers published (or soon to be)? Wasn't the one and only group with negative effects the Journals that could extract a fee? Especially with researchers usually happy to send a copy? This wasn't someone stealing trade secrets they weren't even secret.
It was a protest against the monetization of academic knowledge.
You can call that "theft" as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.
Just because there is a law doesn't mean that that law is just and correct. Saying we "shouldn't support theft" is an over-simplification of the situation.
sdfhbdf · · focus · HN ↗
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
giancarlostoro · · focus · HN ↗
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
elmer2 · · focus · HN ↗
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
thereader12 · · focus · HN ↗
mosseater · · focus · HN ↗
You can call that "theft" as much as you want. There are lots of people like Aaron out there that think this sort of information should be freely available.
Just because there is a law doesn't mean that that law is just and correct. Saying we "shouldn't support theft" is an over-simplification of the situation.
latexr · · focus · HN ↗
He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?