{"id":541,"date":"2015-06-14T00:18:58","date_gmt":"2015-06-14T00:18:58","guid":{"rendered":"http:\/\/words.deviating.net\/?p=541"},"modified":"2015-06-14T01:23:03","modified_gmt":"2015-06-14T01:23:03","slug":"on-bug-bounties-and-the-physical-world","status":"publish","type":"post","link":"https:\/\/words.deviating.net\/?p=541","title":{"rendered":"On Bug Bounties and the Physical World"},"content":{"rendered":"<p style=\"text-align: justify;\">While having a discussion with a close friend recently, the topic of bug bounties came up. \u00a0She asked me what I thought was a reasonable price range. \u00a0I learned from discussion with her as well as discussion with others that the physical security world is massively different from the IT world in this sense.<\/p>\n<p style=\"text-align: justify;\">Often in our lectures and trainings, we draw a parallel between the physical and digital\u00a0realms. \u00a0The same principles apply, the same kinds of errors lead to the same risks and the same lessons learned. \u00a0However &#8212; and there&#8217;s really no getting around this &#8212; the cost to repair\/upgrade\/patch physical systems tends to be much, much higher.<\/p>\n<p style=\"text-align: justify;\">For this reason, manufacturers of locks, access controls, and other physical security technologies are much more loathe to even discuss (let alone disclose) vulnerabilities with the public. \u00a0Likewise, because of the very long\u00a0persistence that physical bugs tend to have (even when they <em>do<\/em> become public), this sort of attack vector can be weaponized\u00a0to much greater effect.<\/p>\n<p style=\"text-align: justify;\">While bug bounties in the software world tend to float around the low four-figures (although occasional high-four-figures and five-figures do happen, and sometimes garner a bit of attention when they do&#8230; and six-figure bug bounties have existed very, very rarely) I took the position that just about anyone whom I know in the physical security world would scoff at numbers in the $1,000 to $5,000 range. \u00a0Well, perhaps not scoff, but most assuredly we would consider them almost comically low.<\/p>\n<p style=\"text-align: justify;\">In the realm of physical security exploits\u00a0and\u00a0the development of tools that leverage such vulns\u00a0(a development process that often entails far more cost and time than the writing of proof-of-concept code for software bugs)\u00a0this kind of research often commands five-figures at a minimum.\u00a0 Such deals also almost always entail\u00a0NDAs and other <strong>very<\/strong> strongly-worded\u00a0agreements to effectively\u00a0<em>never<\/em> publicize said research. \u00a0Put plainly, if a physical security researcher finds a flaw in a high security lock, the market for that work tends to be either governments or private firms with deep and often shadowy connection to government operators. \u00a0A working tool that can be used to attack a physical security system often commands far more in\u00a0the private realm\u00a0than a designer would ever hope to recoup by\u00a0bringing it to market publicly through retail channels. \u00a0Add that to the fact that most designers and vendors in the hardware and physical security space aren&#8217;t courting researchers with fiscal rewards, and this leads to a LOT of hardware bugs (lock flaws, access control system hacks, safe manipulation tools, etc) never being revealed to the public at large.<\/p>\n<p style=\"text-align: justify;\">Let us make no mistake, the government and the law enforcement\u00a0are interested in your data, too. \u00a0Their eyebrows perk up at the notion of software flaws and privilege escalation within networks or\u00a0computers&#8230; but what really gets\u00a0a lot of spooks and police salivating is the chance to\u00a0surreptitiously enter <em>physical <\/em>relams. \u00a0Intelligence gathering, eavesdropping, sneak and peek work, etc&#8230; all of this is based greatly around physical access, and that means possessing\u00a0attack vectors against supposedly high-security lock systems which the public believes to be immune from vulnerabilities.<\/p>\n<p style=\"text-align: justify;\">Unless physical security vendors consider offering genuine bug bounties (something that is far from likely if they aren&#8217;t yet even interested in public disclosure of discovered\u00a0flaws) the only avenues for researchers are going to be:<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">1. public disclosure simply for the sake of the community and for the fun of speaking\u00a0at hacking and security conferences<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\">2. private sale to governments who will undoubtedly use this knowledge for purposes of surveillance and covert entry<\/p>\n<p style=\"text-align: justify;\">So, give a\u00a0cheer for every hacker con which\u00a0accepts a talk with\u00a0a physical security angle. \u00a0The speaker may have turned down considerable funds in exchange for being able to present to you. \u00a0And the topic areas, while sometimes not-the-norm, are far better aired publicly than kept quiet.<\/p>\n<p style=\"text-align: justify;\"><em>NOTE &#8211; This post was not supposed to turn into a &#8220;let&#8217;s pat ourselves on the back here in the phys sec world&#8221; diatribe, so forgive me for that. \u00a0Still, I&#8217;m pleased to be able to report that &#8212; as of the time of this writing &#8212; The CORE Group has never accepted any offer of keeping research private in exchange for money, access, or favors. \u00a0Our works are always either portrayed publicly and\/or disclosed to the original vendor so\u00a0they may\u00a0endeavor\u00a0to correct said problems.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While having a discussion with a close friend recently, the topic of bug bounties came up. \u00a0She asked me what I thought was a reasonable price range. \u00a0I learned from discussion with her as well as discussion with others that the physical security world is massively different from the IT world in this sense. Often [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-541","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/posts\/541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/words.deviating.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=541"}],"version-history":[{"count":10,"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/posts\/541\/revisions"}],"predecessor-version":[{"id":552,"href":"https:\/\/words.deviating.net\/index.php?rest_route=\/wp\/v2\/posts\/541\/revisions\/552"}],"wp:attachment":[{"href":"https:\/\/words.deviating.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/words.deviating.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/words.deviating.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}