News: 1634058064

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Twitch increases bug bounty payouts after source code leak by... wait, is that it?

(2021/10/12)


Amazon-owned streaming platform Twitch has responded to last week's breach of its source code by increasing bug bounty pay-outs from $3,000 to $5,000, sources have told The Register .

The paltry sum was announced to people signed up to Twitch's bug bounty platform, provided by "crowdsourced cybersecurity" firm Bugcrowd. An email seen by The Register detailed the increase in "base payouts" to members of the scheme last week.

The missive said Twitch was "expanding our scope to capture additional submissions," adding: "We'll be working hard with our Bugcrowd triage team to ensure that legitimate submissions are marked as in scope."

[1]

Those increases are as follows:

P1: $3,000 -> $5,000

P2: $1,800 -> $2,000

P3: $300 -> $500

P4: $100 -> $300

A Reg reader who received this message remarked: "That's one of the general problems with these bounties – they often don't match the seriousness of the vulnerabilities you find. Personally I find bug bounties a big waste of time and an Orwellian gig economy so will be sitting this one out."

Last week Twitch had its source code and video streamer payout data, among other things, [2]leaked in a 128GB torrent file , prompting much excitement among streamers around who was scoring the largest payout from the site.

[3]

[4]

Of more interest (certainly to El Reg 's readership) was the leak of what looked like Twitch's entire codebase, now available to all of its rivals (and regulators) to pore through at will to discover how the site's ranking and promotion algorithms operate. Given the large sums seemingly being paid out to the top streamers, it might also interest tax authorities around the world.

Twitch blamed the leak on a "server configuration change" that was spotted by a "malicious third party" while insisting that "full credit card numbers" were not exposed – leaving open the possibility that other credit card data was revealed to the world.

[5]

Bug bounties are typically a bit bigger than a few hundred or thousand pounds; a computer science student bagged $50k from Shopify this summer after [6]spotting something very similar to the Twitch leak – an access token granting read/write access to Shopify's source code repos.

[7]Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos

[8]Want to get rich from bug bounties? You're better off exterminating roaches for a living

[9]Things that are not PogChamp: Amazon's Twitch has its source code, streamer payout data leaked

Although bug bounty companies make a big song and dance about the amounts that can be paid out, in reality five-figure payouts are few and far between. Research from a couple of years ago showed that [10]the top 1 per cent on HackerOne made an average of £26,500 per year ($34,225 at the time).

Advocates of bug bounties say the schemes help encourage responsible security research and reporting, giving people a financial incentive to do the right thing. Critics say they're used as infosec window dressing and people who have spoken to The Register in the past have complained that some companies go to great lengths to minimise payouts by inappropriately downgrading high-severity vulns.

Twitch failed to acknowledge a request for comment. We have yet to hear from Bugcrowd. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/10/06/twitch_data_leak/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnmJ@Jg0MFVrGqH9@AQAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/

[7] https://www.theregister.com/2021/07/27/shopify_bug_bounty_payout/

[8] https://www.theregister.com/2019/01/15/bugs_bounty_salary/

[9] https://www.theregister.com/2021/10/06/twitch_data_leak/

[10] https://www.theregister.com/2019/01/15/bugs_bounty_salary/

[11] https://whitepapers.theregister.com/



It's a market; place your bid

fredblogggs

If you're offering bug bounties you need to think about them as your bid in an active marketplace. It's true that part of your bid is non-monetary: many researchers and engineers prefer to sell their knowledge to vendors and others who will use it defensively (i.e., to fix the bug). But that non-monetary component has only so much value, which differs from one person to the next -- some may be indifferent and will simply accept the highest monetary bid on offer -- and you cannot rely on it to carry the day over potentially much larger bids offered by criminals (a group that includes state actors, who have the ability to literally print money to pay for knowledge they can weaponise). As with any auction, you have to ask yourself up front how important it is to win.

A genuine P1 bug (security-related or otherwise) is a drop-everything moment for however many engineers are needed to analyse and fix it. The type, scope, and scale of the impact that qualifies a bug as P1 depends on your business, but for a major Internet-facing service it's going to be something that is highly likely to compromise your customers' personal information, your own databases, or take out your service. Such incidents are at best costly to fix and come with reputational damage that may never be overcome. In the limit, they can threaten the very existence of your company. With that in mind, $5000 seems like a paltry bid. I'm pretty sure I'd want to reconsider that if I were in their shoes; it's easy to imagine nefarious actors offering a healthy multiple, and the cost of cleaning up from an exploit of a P1 security bug in your service is surely many times that as well.

This is part of the cost of doing business: you can invest up front in better systems and software, and you will have fewer and less severe bugs to address later. Or you can defer that investment and either suffer the consequences of malicious exploitation or pay others more to find your bugs for you. Those are, unfortunately, the only three choices you have. Deferring investment and then demanding that others do your work for far less than it would have cost you up front is not one of your options.

Re: It's a market; place your bid

ShadowSystems

*Jumps up & down enthusiasticly on the upvote button*

Damn my inability to upvote the hell out of your post!

*Hands you a pint* Drink up & congratulations for nailing the issue in the very first post. =-)

Re: It's a market; place your bid

jake

Something to remember is that the kids who graduated Uni/College and got into the corporate computer and networking world back when computers started becoming ubiquitous on desktops all over the corporate world are now roughly in their mid 50s.

Note this is managers, users, coders, programmers, systems folks, everyone.

They started commercial computer work with DOS 4.0 and Windows 2.x (or thereabouts), and have become conditioned to the Redmond Way ... In their minds (and the generations following) it's supposed to be shoddy code, it's supposed to not be secure, it's supposed to break at the least convenient time, it will crash at random, updates will make things worse, over time it gets bigger and worse, if you turn it off and back on again it might fix it (maybe; try flicking the switch again) ... these are all enshrined in the corporate attitude.

What would be the point in building clean, elegant program code that just works when the underlying OS doesn't support such a concept?

Those of us who started coding in the 60s or earlier are just left shaking our heads. Can you imagine what the reaction in Corporate America would have been if DEC or Burroughs or Sperry or IBM had made just one release that was as buggy as the code that is run as a matter of course on modern computers? Or worse, the drek in "the cloud"? The company's stock would have tanked, they would never have been trusted again, heads would have rolled ... ugly wouldn't even begin to describe it.

But these days? Navigating through crap, buggy, crash-prone bullshit has become business as usual. Because THAT'S HOW COMPUTERS ARE SUPPOSED TO WORK! Ask any manager. Or coder under 50. (Thankfully there are still a few real programmers out there in each generation.)

So why bother paying money to fix it? The shareholders will just bitch about the expense.

I have no answers. I'm not sure there are any. It's probably too late.

Re: It's a market; place your bid

Anonymous Coward

Nice rant

Worth pointing out that things are several orders of magnitude more complex than back then

Also super cars are better engineered than mass production cars, but a daily runner is a lot more useful...

low_resolution_foxxes

Odd timing that both Facebook and Twitch went down at the same due to "server configuration changes"?

chuBb.

Not really both are "move fast and break things" companies

In other words meet kpis and hope for best, then when it blows up and new managers come in, test until quarterly bonus is threatened, get sloppy, break it again and jump ship to do same shit elsewhere

How Much Are You Willing To Lose Per Day For a Data Breach?

NoneSuch

Divide by ten and that's your bug bounty reward.

And this offer comes

Anonymous Coward

from the richest corporation on Planet Earth.

As someone in an episode of The Simpsons said "I didn't get rich by writing checks".

Re: And this offer comes

Joe W

"It is easier to get money from poor people" Gunilla Goodmountain.

Re: And this offer comes

jake

"There's a sucker born every minute." —David Hannum

(Probably. Supposedly in reference to PT Barnum's roll in the Cardiff Giant hoax. Or so the story goes. My gut feeling is that the very same phrase was in widespread use long before humans invented writing.)

...And no philosophy, sadly, has all the answers. No matter how assured
we may be about certain aspects of our belief, there are always painful
inconsistencies, exceptions, and contradictions. This is true in religion as
it is in politics, and is self-evident to all except fanatics and the naive.
As for the fanatics, whose number is legion in our own time, we might be
advised to leave them to heaven. They will not, unfortunately, do us the
same courtesy. They attack us and each other, and whatever their
protestations to peaceful intent, the bloody record of history makes clear
that they are easily disposed to resort to the sword. My own belief in
God, then, is just that -- a matter of belief, not knowledge. My respect
for Jesus Christ arises from the fact that He seems to have been the
most virtuous inhabitant of Planet Earth. But even well-educated Christians
are frustrated in their thirst for certainty about the beloved figure
of Jesus because of the undeniable ambiguity of the scriptural record.
Such ambiguity is not apparent to children or fanatics, but every
recognized Bible scholar is perfectly aware of it. Some Christians, alas,
resort to formal lying to obscure such reality.
-- Steve Allen, comedian, from an essay in the book "The Courage of
Conviction", edited by Philip Berman