Hacker News new | past | comments | ask | show | jobs | submit login
More Than 150 Vulnerabilities Discovered in US Marine Corp Websites (sensorstechforum.com)
39 points by koin0r on Oct 5, 2018 | hide | past | favorite | 10 comments



>Over the 20 days of the hacking challenge, hackers reported nearly 150 unique valid vulnerabilities to the U.S. Marine Corps Cyberspace Command (MARFORCYBER) team and were awarded over $150,000 for their findings, HackerOne wrote.

This is why we keep having breaches. 20 days for $1k a piece? (yeah, yeah... i know they could have worked 2 minutes of the 20 days...)

But for real why are companies' bounties so low? Those breaches could have cost millions.


I would guess that a breach is a write off or covered by insurance where as a bounty probably comes out of someone's budget.


The payouts aren't evenly distributed. A lot of the "hackers" are students and dropouts doing this to have something great on their resume.

This guy got $9,000 in 20 days apparently.

https://twitter.com/ratherbeonline


For security work $1000 / day is pretty low.


As the parent points out; it's not bad for an intern's salary.


I'm not surprised about the number of vulnerabilities, but I am happily surprised that the Marines chose to do a bug bounty hacakathon! Very cool.


I hope we see more of this. It only allows us to strengthen what's publicly accessible which might open up doorways to who knows what as a result.


I recently discovered that the Marines have a recommended reading list:

https://www.marines.mil/News/Messages/Messages-Display/Artic...


Most armed forces have reading lists.


Contract goes to the lowest bidder.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: