The Register Home Page

back to article Bug bounties: The good, the bad, and the frankly ridiculous ways to do it

Thirty years ago, Netscape kicked off the first commercial bug bounty program. Since then, companies large and small have bought into the idea, with mixed results. Bug bounties seem simple: a flaw finder spots a vulnerability, responsibly discloses it, and then gets a reward for their labor. But over the past decades, they've …

  1. Wiretrip Bronze badge

    Is there not a single thing that 'AI' isn't enshittifying?

    1. john.jones.name
      Mushroom

      No AI is at present a LLM

      it repeats

      it repeats

      it REPEATS

      look up black mirror

      Humans repeat... the difference is that we apply it in novel sequences

      skibidi

      finding flaws is frankly a human understanding how a human has used....

    2. DS999 Silver badge

      They just need to require better reports

      Make them provide a few screenshots and/or log files that demonstrate the bug being exploited, not just a text writeup "if you do these steps then you get root" or whatever. For a real report that isn't much of a hurdle, but if AI is hallucinating bugs it would also have to fabricate screenshots and log files. Not sure about log files but AI is demonstrably terrible at image generation that includes text. The text is often garbled or meaningless, even for easy stuff like "generate a map of the US including the names of each state".

      If people submit stuff that includes obviously AI generated slop just blacklist them from doing bug reports.

  2. Blazde Silver badge

    'AI moderation'

    I'm never going to use a bounty platform that's known to use AI moderation (at least where it operates like a brick wall you can't easily appeal your way past - looking at you Google). It's frustrating enough when unscrupulous or ignorant humans reject a vulnerability report you've spent hours working on, but at least you can blame an individual in that case. A senseless 'computer says no' response is a process failure and proof you're wasting your time dealing with the entire company. More AI slop is not the answer to AI slop. It's a b.s. solution and they know it is.

  3. tyrfing

    "no, I don't look for criticals at all, they're too hard and take too long. I go for automation to get more efficient low- and medium-severity bugs.' The mediums are the sweet spot, because they pay more.."

    Just like with taxes. Taxing the billionaires might get you lots on an individual basis, but you get less overall because there just aren't that many of them.

    And taxing them more is really hard.

    1. jake Silver badge

      The flaw in your logic is that a country is supposed to tax billionaires AS WELL AS the ordinary people, in a proportional manor.

      Right now here in the US, the billionaires aren't being proportionally taxed. In fact, most of the fuckers are freeloading.

      "Quand le peuple n'aura plus rien à manger, il mangera le riche." —Jean-Jacques Rousseau

  4. Paul Herber Silver badge

    'finance, fame, and fixing it'

    finance, fame, and totally f*ing it up

    I think that's what you meant.

  5. MashedPotato

    Beg Bounty

    We are plagued by these extortionists who weekly assert that they have found a critical vulnerability, which is nothing more than an SPF compliant issue, or disabled DMARC or perhaps reflected cross site scripting. None of which is important in our systems, all of which generates noise. Inevitably the initial email asks for money "in line with industry good practice. And then the threat that in order to protect personal data if we don't pay up the extortionist will have to go to the information commissioner to ensure full public disclosure.

    The only people worse are the extortionist ratings companies that provide no value to anyone, yet tick an audit box and squeeze fees from unsuspecting clients. "oh you have RDP, we don't think RDP is good practice therefore we rate you D+, you need to remove it". I think we know best whether FTP, RDP, or whatever other specious protocol they decide they don't like is suitable for our environment, our risks and our business needs.

    A plague on all their houses.

    1. Blazde Silver badge

      Re: Beg Bounty

      a critical vulnerability, which is nothing more than .. reflected cross site scripting

      The gift that keeps on giving, because 'serious' security professionals think they don't matter. I urge you to, uh, reflect on this stance.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like