The obvious solution to this is to not seek the bug bounty. The next time a critical security vulnerability is found, sell it to the highest bidder. I’m sure there are black hats out there willing to pay the money that the megacorp refuses to pay out.
I feel for people wanting to be security researchers with a conscience. They used to get thrown in jail or hit with lawsuits. Things progressed to where they could get a tiny fraction of the black market value as a bug bounty, and possibly even make a basic living doing that, but we are probably headed back in the other direction.
Meanwhile, black hats are sitting in a resort pool somewhere spending the half million some authoritarian regime paid them for a simmilar exploit, trying to drink enough all-inclusive booze to avoid thinking of the people getting their fingernails pried off in some goulag after getting exposed via said exploit.
For those that don’t read the article - Paul AGREED to no payment, and later regret it. Why should amd pay? They made it clear their policy doesn’t cover MITM attacks and so there is no bounty available for this vulnerability. Amd had and has no obligation to make the pay out, ESPECIALLY when the researcher agreed to no pay out!
How do you KNOW the CIA wasn’t paying for that bug to be prolonged?
Same question about epistemology: how do you KNOW God is/isn’t real? How do you know this isn’t a simulation with a system administrator who can supplant causation that is capable of being proven scientifically?
You live in a police state. The CIA routinely breaks the law for purposes they deem necessary. It’s a possibility they were exploiting the bug for their purposes. This is the reality we live in. But this gets dismissed by charismatic figures in the news so the average person never truly considers it. Operation Mockingbird was FIFTY years ago, proving the agency is not just lying to the American public but actively breaking the law to do so. Why not this?
The obvious solution to this is to not seek the bug bounty. The next time a critical security vulnerability is found, sell it to the highest bidder. I’m sure there are black hats out there willing to pay the money that the megacorp refuses to pay out.
That is essentially the behavior AMD is incentivizing here.
I feel for people wanting to be security researchers with a conscience. They used to get thrown in jail or hit with lawsuits. Things progressed to where they could get a tiny fraction of the black market value as a bug bounty, and possibly even make a basic living doing that, but we are probably headed back in the other direction.
Meanwhile, black hats are sitting in a resort pool somewhere spending the half million some authoritarian regime paid them for a simmilar exploit, trying to drink enough all-inclusive booze to avoid thinking of the people getting their fingernails pried off in some goulag after getting exposed via said exploit.
Well shiiiiiiiiiit balls.
I was thinking just pay the 10k amd
For those that don’t read the article - Paul AGREED to no payment, and later regret it. Why should amd pay? They made it clear their policy doesn’t cover MITM attacks and so there is no bounty available for this vulnerability. Amd had and has no obligation to make the pay out, ESPECIALLY when the researcher agreed to no pay out!
Damn that might make me read the article
How do you KNOW the CIA wasn’t paying for that bug to be prolonged?
Same question about epistemology: how do you KNOW God is/isn’t real? How do you know this isn’t a simulation with a system administrator who can supplant causation that is capable of being proven scientifically?
You live in a police state. The CIA routinely breaks the law for purposes they deem necessary. It’s a possibility they were exploiting the bug for their purposes. This is the reality we live in. But this gets dismissed by charismatic figures in the news so the average person never truly considers it. Operation Mockingbird was FIFTY years ago, proving the agency is not just lying to the American public but actively breaking the law to do so. Why not this?