It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What's worse is the alternative is winding up like Aaron Swartz... (all he did was scrape PDFs for mostly public funded / tax funded papers) Which is even worse, I think I'd be glad to receive $20 for Starbucks instead of being legally chased for showing them they messed up.
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
"all he did was scrape PDFs for mostly public funded / tax funded papers"
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
sdfhbdf · · focus · HN ↗
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
giancarlostoro · · focus · HN ↗
There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued.
elmer2 · · focus · HN ↗
He wasn't a security researcher. He broke into a room and used equipment to steal information. It wasn't just 'tax funded papers'. Companies invested millions of dollars into some of this research.
We shouldn't support theft and he should have gotten some jail time/punishment for it.
"There should really be laws for protecting security researchers who produce 0 harm and divulge / share a vulnerability with a service provider. I'd rather the floor be getting no money AND not going to jail or being sued."
Too many 'security researchers' demand money or threaten to release the vulnerabilities.
I don't know anyone that got into trouble going through a legit bug bounty program.
latexr · · focus · HN ↗
He was intimidated to the point of suicide, and somehow you don’t think that’s punishment enough?