Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Microsoft Security Privacy The Almighty Buck IT

Ask Slashdot: What Is the Best Way To Thank Users For Reporting Security Issues? 128

An anonymous Slashdot reader writes: I have worked in the IT field long enough to know that many issues can be avoided if users pay attention to pop-ups, security alerts, "from" addresses et al and not just machine gun click their way through things. Unfortunately, most users seem to have the "fuck it" mentality in terms of good security practices. Sometimes I will have users submit a ticket asking if an email is safe to open or if that strange 800 number that popped up in their browser is really Microsoft. When that happens I like to talk to them in person (when possible) to commend them and tell them how much trouble could be avoided if more users followed their example. I'm curious to know if anyone has ever worked somewhere with bug bounty type incentives for corporate users or if you have a unique way of thanking people for not trying to open Urgent_Invoice.exe.
This discussion has been archived. No new comments can be posted.

Ask Slashdot: What Is the Best Way To Thank Users For Reporting Security Issues?

Comments Filter:
  • by Anonymous Coward on Monday January 09, 2017 @06:07PM (#53637507)

    How about just saying, "Thank you!" to them?

    You could also give them money.

    • by Anonymous Coward on Monday January 09, 2017 @06:16PM (#53637569)

      Report them to the FBI for hacking. That has been the standard procedure in the past.

      • Absolutely! Anyone who finds any kind of security issue and then reveals it needs to be pursued and punished so severely that everyone who finds such issues just pretends they didn't see it and moves on. That'll make things REALLY secure!

        • Re: (Score:3, Informative)

          by Anonymous Coward

          Absolutely! Anyone who finds any kind of security issue and then reveals it needs to be pursued and punished so severely that everyone who finds such issues just pretends they didn't see it and moves on. That'll make things REALLY secure!

          You seem to be under the mistaken assumption that solving security problems is actually the end goal here. It's not. The end goal is to avoid personal or company liability, in which case congratulating someone is the WRONG thing to do because then you admit the product has a problem, and thus you are liable.
          Call the FBI is indeed the only correct answer.

          • Surely a sensible manager would realise that the real liability is in getting owned by a genuinely malicious attacker, no?

          • by AmiMoJo ( 196126 )

            You can run a bug bounty programme internally and it won't create liability, because that is industry best practice. In fact these days if I were suing some company over a security breech then the lack of a safe way to report problems and some kind of reward scheme would be evidence of their negligence.

            We went down this route long ago. Humans are imperfect, sometimes they make mistakes when engineering stuff, but there is only liability if reasonable measures were not taken to detect and mitigate the proble

    • Re: (Score:2, Interesting)

      by Anonymous Coward

      Thank them via email and CC their manager.

      Or, perhaps, thank their manager and CC your manager (and the end user).

    • by Grishnakh ( 216268 ) on Monday January 09, 2017 @07:38PM (#53638087)

      This is a stupid answer.

      Here's how you should actually handle people who report security issues:

      1) If you're an IT director and it's a company employee who reported it, you need to inform the upper management that you have a possible hacker in the company, and get his ass fired.

      2) If you work in a company and someone in the general public reported it, you need to notify your legal department so they can file a lawsuit against the person for defamation.

      3) If you're in government and this was reported by someone in the general public of your country, you need to notify law enforcement so they'll be arrested for hacking and thrown in prison.

      Only hackers would care about "security issues", and if that information becomes public, it will just help other hackers, so any such people need to be dealt with, extremely harshly. If you disagree, then you obviously are not in a position of power in the US.

      • by Anonymous Coward

        You forgot:

        4) Start a war with Russia because obviously they did it.

    • You can give them one of these!!!
      https://society6.com/product/w... [society6.com]

      Or if they steal all your info send them one of these:
      https://society6.com/product/b... [society6.com]

    • by plopez ( 54068 )

      how about a "Wall of Fame" website. Post their names, email addresses, physical addresses, social security numbers, and mothers maiden names.

    • That's what I do. Then I follow it up with something like, "Great job, you did exactly right."
    • Assuming they've given you a reasonable amount of time to resolve the issue and issue patches and you do. No thanks are necessary, however, regardless of whether you've fixed the defect or not after a reasonable amount of time they will go public.
  • A bit ironic, but I'm sure it would be appreciated!

  • Fix the Bugs (Score:4, Insightful)

    by BikeWreck ( 1153095 ) on Monday January 09, 2017 @06:13PM (#53637547)
    If they go to the trouble to document and report bugs, you need to fix them quickly. This isn't limited to security bugs -- any kind of bug deserves attention. That's more thanks than they get from most vendors. Nothing will make me quit a vendor more quickly than being ignored when I make substantial, documented bug reports.
  • by ZorinLynx ( 31751 ) on Monday January 09, 2017 @06:14PM (#53637551) Homepage

    I've heard many cases of somebody reporting a security issue, then getting fired, sued, or arrested as a result. In the case of kids in school, suspended or expelled.

    They were HONEST here! They found a security problem and rather than exploit it for personal gain, they reported it, and then get in TROUBLE for it??

    It's absurd. It means when people hear of this and find security problems in the future, they'll keep quiet about them because they don't want to get in trouble too.

    • I've heard many cases of somebody reporting a security issue, then getting fired, sued, or arrested as a result. In the case of kids in school, suspended or expelled.

      They were HONEST here! They found a security problem and rather than exploit it for personal gain, they reported it, and then get in TROUBLE for it??

      It's absurd. It means when people hear of this and find security problems in the future, they'll keep quiet about them because they don't want to get in trouble too.

      Damn I was going to say "don't prosecute them" but you beat me to it. The parent needs a mod point or two as it is ridiculous when that happens.

      • I specifically said "persecute" not "prosecute" because the former sorta encompasses the latter, and it's not always "prosecution" per-say. It's sometimes suspension, firing, etc...

        Just clearing that up!

    • Re: (Score:3, Interesting)

      by Grishnakh ( 216268 )

      Reporting "security issues" just makes people in power look bad, so it makes perfect sense that it would be strongly discouraged in such ways (fired, sued, arrested).

      The simple thing to do: do not EVER report any security issues you come across. It's not going to benefit you in any way, and is quite likely to harm you greatly. Just forget you saw anything and don't say anything to anyone. If this means your company is likely to get hacked so badly that they're going to go under, then they were already ci

      • by AmiMoJo ( 196126 )

        Morally it's best to report it anonymously. Then when your ex-boss is in court claiming he knew nothing and it's all your fault, you can point to that anonymous email as evidence that he is lying.

        Just be sure to use Tor and a disposable email address, and obviously not from a work computer, and don't give any details that could reveal your identity.

      • by Agripa ( 139780 )

        The simple thing to do: do not EVER report any security issues you come across. It's not going to benefit you in any way, and is quite likely to harm you greatly.

        And the best thing to do is anonymously announce it to the world. It is the only way it will get fixed and revenge is sweet.

    • That's why I'll only share such findings anonymously. Or at least anonymous enough. Go ahead, sue or attempt prosecution on John Smith who lives at 1 Main St, Anytown USA.

  • If you demonstrate that you take the report seriously. So just showing a good followup of the report, with progress and fixes.
      That means having the resources since without resources nobody'll be happy.

  • by darkain ( 749283 ) on Monday January 09, 2017 @06:15PM (#53637557) Homepage

    I've been reporting security issues in local businesses that I deal with. One is an ISP that stores and emails users passwords in plain text. Another is a bank exposing credit card numbers in plain text. When I report this shit, I expect actual follow through in fixing them. In the former case, the ISP literally gave me a "not our problem" response, while the bank said they'd contact me back and never did (still need to check to see if this issue has at least been resolved though).

    • Another is a bank exposing credit card numbers in plain text.

      Don't worry -- I'll check for you so you don't have to bother with it. Which bank was that again....? ;-)

  • To every congressman in the country, asking them to repel the CFAA or at least heavily reform it, while also making a huge PR stunt about it.

  • Fix the problem, promptly.

  • Hack directly to their screen and display, "Thanks for reporting the security issue. -Anonymous Coward"

  • send them a 500 dollar gift card
  • Want to know when somebody finds a XSS vuln in your timesheet app? Give 'em a starbucks gift card. Or a $20 pre-paid gift debit card they can use anywhere.

    Sure, employees will try to game the system at first, and you'll find loopholes in your "rules" of the game. But the end result is net positive:

    1) Your employees are *paid* and *happy* to notify the company of vulnerabilities, and
    2) You. Fucking. Fix. Vulnerabilities.

    Seriously, it's a net win for both the company and the employees. Just do it.
  • Lawsuit. At least that seems to be industry best practice...

  • We'd just toss them in jail...
  • by MobyDisk ( 75490 ) on Monday January 09, 2017 @06:51PM (#53637781) Homepage

    The best way to reward users is to give them an award that is publicly visible, to encourage others to do the same.

    Anecdote: I worked at an organization that, like many others, had a public "share drive." Sometimes I would browse the folders with pictures of coworkers at after-hours events. One time, I decided to see what was on the drive, and I found an Excel spreadsheet with a list of names, last 4 digits of social security numbers, and credit cards. Excel keeps the author's name in the file, so I contacted the author. They replied with "Oh, that file is a temporary file and it gets deleted every 30 days, so don't worry about it." I forwarded the email to the company's head of security, expecting no reply. A month later I was invited to a conference room for something random, and much too my surprise, I was presented with an award in front of 20 or so people in my department. My boss told me it was handed down to him by the head of corporate security, along with an explanation of what I had done. I was in genuinely proud. Because of that event, I was more engaged with the company, and I have taken that security mindset with me. I can only hope that other employees took it to heart as well.

    I know the summary is about users reporting internal security concerns. However on a broader note, we need an industry standard fo reporting security issues. Every other day there's some story about an organization that ignored a report, or sued the researcher, or something. We need a standards body to:
    1. Create a standard form for submitting vulnerabilities (especially to 3rd-parties.)
    2. A standard way to deliver that form.
    3. A standard amount of time to wait for a response before disclosing it.
    4. A standard form to disclose it publicly, and a list of appropriate organizations to receive it.
    5. An industry-accepted expectation that, if you follow these industry standard steps, then you should be safe from lawsuits.

  • Best way to report security issues and problems? Are you daft?

    1. They don't want to be bothered
    2. They want to "look good" as cheaply as possibly
    3. No liability

    Is it worth the expansion? Here on Slashdot? I must be daft, but I'll say a bit more:

    As regards #1 and many years of attempting to report problems, I can assure you that they [various organizations who, in theory, might be responsible for protecting your security as customers and users] are NOT grateful. These days the trend has become pigeonholing i

  • Comment removed based on user account deletion
  • Send them a threatening letter from your legal team, along with a DMCA takedown notice.
    • I guess that it's better than being labeled a "cyber terrorist" and rotting in Gitmo for the next 25 years.

  • Unfortunately, most users seem to have the "fuck it" mentality in terms of good security practices.

    My workplace has many security "features". I am a long time IT worker above level III.
    From cold boot to being productive takes longer than 10 minutes due to the security feature of being able to use the 2FA token exactly once, then having to wait for the next one (90 seconds on average). This is really a "nice" feature when your infrastructure is completely down and you have C level execs screaming to get i

  • by Anonymous Coward

    Your attitude clearly demonstrates you care about the end users in your network. As a former corporate peon, this is refreshing.

  • Let them keep their job.

  • by tylersoze ( 789256 ) on Monday January 09, 2017 @08:34PM (#53638453)

    By prosecuting them to the fullest extent of the law?

  • by Anonymous Coward

    Teach them to never, ever do it again.

  • A coupon for an espresso and a blowjob in Switzerland.(and the flight perhaps)

    http://www.eater.com/2016/6/24... [eater.com]

  • ... was to send out an email to firm@..... that actually did hit all members of the firm, including the partners, to brag on a person who asked me if, "the UPS link," was OK or not.That way, I got a chance to:

    Make a coworker (fuck the "user" mentality) feel good
    Make a coworker look good to peers and management
    Lecture the entire work universe about security (again, and again, and again)
    Head off the, "Well, no one ever told me ..." crap

    I was a broken record, and sometimes a per

  • by dweller_below ( 136040 ) on Monday January 09, 2017 @10:51PM (#53639271)
    When I worked IT Security for a University, we took extra effort to thank anybody who reported a security issue. Here are some examples:
    • * We had an alert clerk notice that "something was off" when 3 people tried to sweet talk their way into a storage area. She flirted with them, while her co-worker called campus security. The cops had the penetration team spread and handcuffed before they could present their "Get Out Of Jail" documentation. Even then, they kept them handcuffed, until the cops called and verified the documentation. It was the first time that the penetration team had EVER had to use their documentation. I personally called and thanked everybody. I also arranged for the clerk to get a 2 pound box of the local Blue Bird Chocolates: http://bluebirdcandy.com/ [bluebirdcandy.com]
    • * When we started our "Internet Skeptic" awareness campaign: https://it.usu.edu/computer-se... [usu.edu] we would send a coupon for a free Aggie Ice Cream Cone: http://aggieicecream.usu.edu/ [usu.edu] to the first person to report a new phish.
    • * Later, we found that prompt, public thanks worked as well as ice cream. We would promptly analyse every report, and then send out 2 sets of emails. The first would be the thank-you to the reporter. It included: Personalized thanks; A description of the scam; A report of how many others at USU were warned, thanks to their alertness. The second set of email would go out to everybody who had received a copy of the phishing scam. It included: A notification that the prior message was a fraud; Instructions for how to recover, if they had fallen for the fraud; A report of how many others also received the phish; A public acknowledgement of the alert reporter.
    • * This spring, we had a "Phishing Tournament" with various awards for reporting fraudulent emails. The grand prize was a tackle box full of goodies.

    The small amount we spend on thanks was more than repaid by the savings created by a community of alert, careful internet skeptics.

  • by Anonymous Coward

    What we do is send a letter to their commander commending them (the commander) and the person who identified the problem. Commanders love getting their egos stroked, and love handing out letters in big meetings. Like full formal ceremony bullshit, major blah blah blahs, private walks up to the front, gets presented the letter just the same as a medal, shake hands, pose for a photo, salute. It's fucking hilarious, but they eat this shit up.

  • Currently the way to thank users who report security issues is: "Fuck off!"
  • What's wrong with the way it is now?
  • 1) Send email thanking for the report, and solicit them to visit a site for getting more info.
    2) When they browse the site grab at once user's IP address.
    3) Exploit the vulnerability they reported by hacking into their system.
    4) Delete everything you can.
  • Your software is perfect
  • If your company does not aid you with an official reward system, create your own within the limits of your ability.

    I was working in risk management and security assessment a while ago. Basically our job was to find security problems and decide whether we can carry the risk if we find one or whether a service has to go. As you can imagine, that does give you a bit of a wiggle room concerning the severeness of a problem. And we soon made it a public secret that reporting a problem you find in your own system

  • What Is the Best Way To Thank Users For Reporting Security Issues?

    • If a dev needs a "Thank You" after do his job, he/she are doing it wrong...
      • It's not a question of need, it's a question of letting a community know that someone did the right thing so "they" do the right thing..
  • At my company, IT sends out an email or phone paging message when there's something people really need to know about. The person who originally found or reported it is given a mention for helping the company out. It makes them feel VERY special and well-pet.

    It's sad but just a mention of a person's name to a large group of people for having done something that was smiled upon is enough to make most feel like a god/goddess. Human nature, I guess. It works. More people report suspicious things because th

Don't tell me how hard you work. Tell me how much you get done. -- James J. Ling

Working...