It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
Every HN post regarding security exploits inevitably results in some comment saying the bounty is too low. I find it helpful to read previous comments by tptacek regarding bug bounties and market values:
This is correct. I've made well over six figures over the last couple of years through bug bounty programs. I wouldn't spend months finding one bug. It's usually days or a week or two max.
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
$5K seems like an absolute steal compared to paying contracted security experts to find such bugs. I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
> $5K seems like an absolute steal compared to paying contracted security experts to find such bugs.
Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.
> I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).
It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.
Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.
We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.
sdfhbdf · · focus · HN ↗
It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.
On <a href="https://www.microsoft.com/en-us/msrc/bounty" rel="nofollow">https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.
What does HN think? Why would it be only $5000?
omoikane · · focus · HN ↗
<a href="https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=tptacek%20bounty%20market&sort=byDate&type=comment" rel="nofollow">https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This one probably has the best summary:
<a href="https://news.ycombinator.com/item?id=43025038">https://news.ycombinator.com/item?id=43025038
elmer2 · · focus · HN ↗
$5,000 is actually pretty normal for a critical. I think the most I received for one bug was around $10,000, but this is the exception.
AI has also ruined the market. I'm a security consultant (where I make most of my money) and stopped bug bounty once AI slop reports made it impossible to actually get anything triaged in a timely manner.
Something else many don't know is that with all of the major platforms, customers can see the bugs before they are even triaged by the platform team. Many companies are now taking advantage of the long triage times and fixing the bugs before the researcher can get paid. It's then marked as a duplicate and the researcher gets nothing.
rnxrx · · focus · HN ↗
Aurornis · · focus · HN ↗
Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.
> I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).
It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.
Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.
We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.