Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How much money is lost by consumers/businesses for every hour the vulnerability is exploited in the wild with no patch?


The value of the report is dependent on the scarcity of the knowledge. If anybody can report it, the bid goes down.


The value of future reports should also be a component though. By paying a low amount you discourage ethical bug bounty hackers from bothering to look for more exploits. If I think I'm only getting $1000 for a Chrome issue versus $100,000 for an Acme Co issue, I'll be spending my time looking for Acme Co issues.

Bug bounties are as much a way of attracting talent to even try to exploit your system as they are about the exploits themselves. If you lowball the bounties the talent goes elsewhere.


How do you figure? The value of the report is, ethics aside, the same as the value of exploiting it. Doesn’t matter if I can conceive of it, it matters if I can exploit it.


Supply and demand has to be considered. The more parties aware of the vulnerability, the more attractive sellers (reporters) have to make their ask to the buyer (defender).


Not following that. The report is the upstream resource the exploit needs. The value of iron ore is definitely not the value of the steel made with it. Or maybe I misunderstood your view?


There is a theta decay component. The zero day is highly valuable until known; once known, its value rapidly declines to zero.


That’s not how things are valued. That’s moreso how the absence of something is valued.


Go without air for a few minutes and you’ll die, and yet they give the stuff away for free.


Stop giving them ideas.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: