Twitch increases bug bounty payouts after source code leak by... wait, is that it?
- Reference: 1634058064
- News link: https://www.theregister.co.uk/2021/10/12/twitch_bug_bounties_tiny_increase/
- Source link:
The paltry sum was announced to people signed up to Twitch's bug bounty platform, provided by "crowdsourced cybersecurity" firm Bugcrowd. An email seen by The Register detailed the increase in "base payouts" to members of the scheme last week.
The missive said Twitch was "expanding our scope to capture additional submissions," adding: "We'll be working hard with our Bugcrowd triage team to ensure that legitimate submissions are marked as in scope."
[1]
Those increases are as follows:
P1: $3,000 -> $5,000
P2: $1,800 -> $2,000
P3: $300 -> $500
P4: $100 -> $300
A Reg reader who received this message remarked: "That's one of the general problems with these bounties – they often don't match the seriousness of the vulnerabilities you find. Personally I find bug bounties a big waste of time and an Orwellian gig economy so will be sitting this one out."
Last week Twitch had its source code and video streamer payout data, among other things, [2]leaked in a 128GB torrent file , prompting much excitement among streamers around who was scoring the largest payout from the site.
[3]
[4]
Of more interest (certainly to El Reg 's readership) was the leak of what looked like Twitch's entire codebase, now available to all of its rivals (and regulators) to pore through at will to discover how the site's ranking and promotion algorithms operate. Given the large sums seemingly being paid out to the top streamers, it might also interest tax authorities around the world.
Twitch blamed the leak on a "server configuration change" that was spotted by a "malicious third party" while insisting that "full credit card numbers" were not exposed – leaving open the possibility that other credit card data was revealed to the world.
[5]
Bug bounties are typically a bit bigger than a few hundred or thousand pounds; a computer science student bagged $50k from Shopify this summer after [6]spotting something very similar to the Twitch leak – an access token granting read/write access to Shopify's source code repos.
[7]Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos
[8]Want to get rich from bug bounties? You're better off exterminating roaches for a living
[9]Things that are not PogChamp: Amazon's Twitch has its source code, streamer payout data leaked
Although bug bounty companies make a big song and dance about the amounts that can be paid out, in reality five-figure payouts are few and far between. Research from a couple of years ago showed that [10]the top 1 per cent on HackerOne made an average of £26,500 per year ($34,225 at the time).
Advocates of bug bounties say the schemes help encourage responsible security research and reporting, giving people a financial incentive to do the right thing. Critics say they're used as infosec window dressing and people who have spoken to The Register in the past have complained that some companies go to great lengths to minimise payouts by inappropriately downgrading high-severity vulns.
Twitch failed to acknowledge a request for comment. We have yet to hear from Bugcrowd. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2021/10/06/twitch_data_leak/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/
[7] https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/
[8] https://www.theregister.com/2019/01/15/bugs_bounty_salary/
[9] https://www.theregister.com/2021/10/06/twitch_data_leak/
[10] https://www.theregister.com/2019/01/15/bugs_bounty_salary/
[11] https://whitepapers.theregister.com/
Re: It's a market; place your bid
*Jumps up & down enthusiasticly on the upvote button*
Damn my inability to upvote the hell out of your post!
*Hands you a pint* Drink up & congratulations for nailing the issue in the very first post. =-)
Re: It's a market; place your bid
Something to remember is that the kids who graduated Uni/College and got into the corporate computer and networking world back when computers started becoming ubiquitous on desktops all over the corporate world are now roughly in their mid 50s.
Note this is managers, users, coders, programmers, systems folks, everyone.
They started commercial computer work with DOS 4.0 and Windows 2.x (or thereabouts), and have become conditioned to the Redmond Way ... In their minds (and the generations following) it's supposed to be shoddy code, it's supposed to not be secure, it's supposed to break at the least convenient time, it will crash at random, updates will make things worse, over time it gets bigger and worse, if you turn it off and back on again it might fix it (maybe; try flicking the switch again) ... these are all enshrined in the corporate attitude.
What would be the point in building clean, elegant program code that just works when the underlying OS doesn't support such a concept?
Those of us who started coding in the 60s or earlier are just left shaking our heads. Can you imagine what the reaction in Corporate America would have been if DEC or Burroughs or Sperry or IBM had made just one release that was as buggy as the code that is run as a matter of course on modern computers? Or worse, the drek in "the cloud"? The company's stock would have tanked, they would never have been trusted again, heads would have rolled ... ugly wouldn't even begin to describe it.
But these days? Navigating through crap, buggy, crash-prone bullshit has become business as usual. Because THAT'S HOW COMPUTERS ARE SUPPOSED TO WORK! Ask any manager. Or coder under 50. (Thankfully there are still a few real programmers out there in each generation.)
So why bother paying money to fix it? The shareholders will just bitch about the expense.
I have no answers. I'm not sure there are any. It's probably too late.
Re: It's a market; place your bid
Nice rant
Worth pointing out that things are several orders of magnitude more complex than back then
Also super cars are better engineered than mass production cars, but a daily runner is a lot more useful...
Odd timing that both Facebook and Twitch went down at the same due to "server configuration changes"?
Not really both are "move fast and break things" companies
In other words meet kpis and hope for best, then when it blows up and new managers come in, test until quarterly bonus is threatened, get sloppy, break it again and jump ship to do same shit elsewhere
How Much Are You Willing To Lose Per Day For a Data Breach?
Divide by ten and that's your bug bounty reward.
And this offer comes
from the richest corporation on Planet Earth.
As someone in an episode of The Simpsons said "I didn't get rich by writing checks".
Re: And this offer comes
"It is easier to get money from poor people" Gunilla Goodmountain.
Re: And this offer comes
"There's a sucker born every minute." —David Hannum
(Probably. Supposedly in reference to PT Barnum's roll in the Cardiff Giant hoax. Or so the story goes. My gut feeling is that the very same phrase was in widespread use long before humans invented writing.)
It's a market; place your bid
If you're offering bug bounties you need to think about them as your bid in an active marketplace. It's true that part of your bid is non-monetary: many researchers and engineers prefer to sell their knowledge to vendors and others who will use it defensively (i.e., to fix the bug). But that non-monetary component has only so much value, which differs from one person to the next -- some may be indifferent and will simply accept the highest monetary bid on offer -- and you cannot rely on it to carry the day over potentially much larger bids offered by criminals (a group that includes state actors, who have the ability to literally print money to pay for knowledge they can weaponise). As with any auction, you have to ask yourself up front how important it is to win.
A genuine P1 bug (security-related or otherwise) is a drop-everything moment for however many engineers are needed to analyse and fix it. The type, scope, and scale of the impact that qualifies a bug as P1 depends on your business, but for a major Internet-facing service it's going to be something that is highly likely to compromise your customers' personal information, your own databases, or take out your service. Such incidents are at best costly to fix and come with reputational damage that may never be overcome. In the limit, they can threaten the very existence of your company. With that in mind, $5000 seems like a paltry bid. I'm pretty sure I'd want to reconsider that if I were in their shoes; it's easy to imagine nefarious actors offering a healthy multiple, and the cost of cleaning up from an exploit of a P1 security bug in your service is surely many times that as well.
This is part of the cost of doing business: you can invest up front in better systems and software, and you will have fewer and less severe bugs to address later. Or you can defer that investment and either suffer the consequences of malicious exploitation or pay others more to find your bugs for you. Those are, unfortunately, the only three choices you have. Deferring investment and then demanding that others do your work for far less than it would have cost you up front is not one of your options.