YouTube2Text

Debugging Bug Bounties in Cyberspace: From Vulnerability Discovery to Algorithmic Harms Redress — Transcript

by Columbia SIPA · 20,677 words · 3,358 segments · language en · Watch on YouTube

Full transcript

  1. 0:10hi everyone my name is jason healy i run
  2. 0:13the cyber programs at columbia
  3. 0:15university school of international
  4. 0:17public affairs and i've just been so
  5. 0:19excited for this event
  6. 0:21with some fabulous colleagues
  7. 0:23to talk about
  8. 0:26these issues so this is a range as part
  9. 0:29of the nijilo road and digital futures
  10. 0:31forum it's been organized with the
  11. 0:33support of the saltzman institute in
  12. 0:34warren peace studies my thanks to vir
  13. 0:36patan vikram singh for for helping put
  14. 0:38this together
  15. 0:40um i'm not going to keep any time
  16. 0:42because i want to hear what the
  17. 0:42panelists have to say so we're going to
  18. 0:44turn right uh to matt gertzen he's a
  19. 0:47researcher i just published a great
  20. 0:48report um with data in society and let's
  21. 0:51turn it over to matt
  22. 0:54thank you jason it's a pleasure to be
  23. 0:56here uh thank you for inviting me to
  24. 0:59moderate this event
  25. 1:00i have had the great privilege to watch
  26. 1:04uh both of the reports that we're going
  27. 1:05to be discussing today kind of in their
  28. 1:08development phase over the past couple
  29. 1:10years um and uh it's just it's such a
  30. 1:14great uh thrill to see them out in the
  31. 1:17world and uh and as a backdrop for this
  32. 1:20discussion on the subject of
  33. 1:22bug bounty programs and their uh history
  34. 1:25and their contemporary application today
  35. 1:28so we're going to have a
  36. 1:30pretty standard format where i'm going
  37. 1:32to give a little bit of context for the
  38. 1:34event
  39. 1:35and then
  40. 1:36our panelists will each present a little
  41. 1:39bit about the papers that they've that
  42. 1:42they've just published
  43. 1:43um i think that'll probably take us
  44. 1:45about uh 30 40 minutes something like
  45. 1:47that and then we'll move into a
  46. 1:50you know semi-structured uh conversation
  47. 1:52where i'll ask some ask questions i'll
  48. 1:55also keep a track on the the q a section
  49. 1:58for any questions from the audience and
  50. 1:59intersperse those as appropriate
  51. 2:02and uh we'll
  52. 2:03also allow the panelists to you know
  53. 2:06jump in and address questions that
  54. 2:08come in from the audience
  55. 2:10if they if they see anything that
  56. 2:12particularly grabs their interest
  57. 2:14um
  58. 2:15that's about it i think um so i'll
  59. 2:17briefly introduce
  60. 2:19each of the people here so first we have
  61. 2:21ryan ellis who is an associate professor
  62. 2:23of communications studies at
  63. 2:24northeastern university and an affiliate
  64. 2:26of data and society research institute
  65. 2:29ryan's research and teaching focuses on
  66. 2:31topics related to communication law and
  67. 2:33policy infrastructure politics and cyber
  68. 2:36security he's the author of letters
  69. 2:38power lines and other dangerous things
  70. 2:40the politics of infrastructure security
  71. 2:42and the editor with vivek mohan of
  72. 2:44rewired cyber security governance
  73. 2:47and then we have yuan stevens who is a
  74. 2:49legal and policy expert focused on
  75. 2:51information security data protections
  76. 2:53and human rights she works towards a
  77. 2:55world where powerful actors and the
  78. 2:57systems they build are held accountable
  79. 2:59to the public especially when it comes
  80. 3:00to vulnerable and marginalized people
  81. 3:02she brings years of international
  82. 3:04experience to her work as a researcher
  83. 3:06having examined the impacts of
  84. 3:07technology on vulnerable populations in
  85. 3:09canada the us and germany uan is a
  86. 3:11research affiliate of data and society
  87. 3:13research institute and a collaborator at
  88. 3:15the center for media technology and
  89. 3:17democracy at mcgill university she
  90. 3:19previously worked at harvard
  91. 3:20university's berkman client center for
  92. 3:21internet society during her studies and
  93. 3:23joint degree in civil and common law at
  94. 3:26mcgill university
  95. 3:27camille francois is a lecturer at the
  96. 3:29columbia school of international public
  97. 3:31affairs and the co-lead of the
  98. 3:33algorithmic justice lease community
  99. 3:35reporting of algorithmic systems harm's
  100. 3:38crash project her work spends several
  101. 3:41aspects of cyber security from
  102. 3:43developing industry-leading programs
  103. 3:45focused on protecting vulnerable users
  104. 3:47to detecting information operations
  105. 3:49currently the global director for trust
  106. 3:51and safety at nyan tech
  107. 3:54she was previously chief innovation
  108. 3:55officer in grafica where she built and
  109. 3:57led a team dedicated to exposing and
  110. 3:59mitigating information operations across
  111. 4:01platforms and prior to that a principal
  112. 4:03researcher at google camille has advised
  113. 4:06his governments and parliamentary
  114. 4:07committees on both sides of the atlantic
  115. 4:09and investigated russian interference in
  116. 4:11the 2016 u.s presidential election
  117. 4:14on behalf of the u.s senate select
  118. 4:16intelligence committee
  119. 4:17and finally we have josh kenway who's a
  120. 4:19policy analyst at paypal working on
  121. 4:21corporate governance for technology and
  122. 4:24cyber security and until mid-2021
  123. 4:27he was a research fellow with the
  124. 4:28algorithmic justice league where he was
  125. 4:30part of the community reporting
  126. 4:32again the crash project i just described
  127. 4:35prior to joining paypal josh was an
  128. 4:36associate of the cyber threat alliance a
  129. 4:39non-profit organization that enables the
  130. 4:41sharing of information on cyber threats
  131. 4:43among cyber security companies
  132. 4:44governments and civil society
  133. 4:46organizations so we have a very
  134. 4:48impressive cast of characters here with
  135. 4:51a vast breadth of knowledge
  136. 4:54and i'm very excited for this um
  137. 4:56so i think we can move over to the next
  138. 4:59slide really quickly um if that's all
  139. 5:01right
  140. 5:02and
  141. 5:03i am
  142. 5:04the co-author alongside uh my frequent
  143. 5:08collaborator and former advisor
  144. 5:10gabriella coleman of the recent data
  145. 5:12society report wearing many hats
  146. 5:15and that
  147. 5:17report kind of looks at the
  148. 5:19early history of hackers
  149. 5:22professionalizing throughout the 1990s
  150. 5:24and it really forms a perfect kind of
  151. 5:27precursor pre-history to a lot of the
  152. 5:29topics we're going to discuss today
  153. 5:31so i'm going to give a very brief
  154. 5:33introduction to the material we cover in
  155. 5:35that report which was also released i
  156. 5:37think about three weeks ago by downtown
  157. 5:38society
  158. 5:40um
  159. 5:41and basically in in our report we look
  160. 5:43at
  161. 5:44um the emergence of two very important
  162. 5:47phenomena by which
  163. 5:48hackers um you know people who break
  164. 5:51into
  165. 5:52uh secure
  166. 5:54computer systems
  167. 5:56um
  168. 5:57sought to kind of change the the public
  169. 5:59public conversation
  170. 6:01and the process by which security issues
  171. 6:03were thought about and addressed
  172. 6:06so one of the issues we really take on
  173. 6:08seriously in that report is the
  174. 6:11practice of what was called full
  175. 6:13disclosure and it still exists in some
  176. 6:14forms today
  177. 6:16and full disclosure basically involved
  178. 6:18hackers finding vulnerabilities and
  179. 6:20security systems
  180. 6:22and
  181. 6:23publishing them
  182. 6:24publicly to the world
  183. 6:26making them known
  184. 6:27and in doing so
  185. 6:29you know putting pressure on
  186. 6:31vendors like microsoft was one of their
  187. 6:34big targets and also
  188. 6:36you know institutions of all sorts to
  189. 6:38take those issues very seriously
  190. 6:41address them patch them do whatever they
  191. 6:43could to
  192. 6:45ensure that other hackers
  193. 6:47perhaps of more malicious intent could
  194. 6:49not exploit them
  195. 6:51to harm
  196. 6:52and um
  197. 6:54this
  198. 6:55practice was you know very common among
  199. 6:57a variety of mailing lists
  200. 6:59one of the ones we talk about in the
  201. 7:00report most
  202. 7:02intensively is called bug track
  203. 7:06and
  204. 7:07you know over time
  205. 7:09people working for companies would come
  206. 7:11to these lists engage with these people
  207. 7:13take the issues seriously
  208. 7:15before that often
  209. 7:16vendors would pretend that those issues
  210. 7:18didn't exist because there was really no
  211. 7:21way to hold them accountable
  212. 7:25another phenomenon we look at is
  213. 7:26something we call security by spectacle
  214. 7:28which is the way that hackers sometimes
  215. 7:30staged
  216. 7:32um you know spectacular
  217. 7:34media focused um actions like releasing
  218. 7:38tools that made exploitation of
  219. 7:40vulnerabilities even even more easy
  220. 7:42in order to kind of exacerbate
  221. 7:45the threat to exacerbate the potential
  222. 7:47for harm and thus motivate vendors to
  223. 7:49move more seriously
  224. 7:51um or more quickly now by the end of the
  225. 7:541990s many of the hackers that
  226. 7:56participated in these practices actually
  227. 8:00became employees of a lot of the
  228. 8:02companies that they had formerly
  229. 8:04antagonized microsoft in particular
  230. 8:07went on a hiring spree
  231. 8:10hiring many many prominent hackers and
  232. 8:12also
  233. 8:13um you know consulting with a security
  234. 8:16firm called at stake which
  235. 8:18also uh you know hired many of the
  236. 8:20hackers that have been involved in full
  237. 8:22disclosure research
  238. 8:23and so there's kind of a you know from
  239. 8:25the early 1990s to the to the early
  240. 8:282000s there was kind of a water a sea
  241. 8:30change where hackers suddenly were often
  242. 8:33working for the very companies that they
  243. 8:34had been
  244. 8:35um uh
  245. 8:37exposing vulnerabilities in
  246. 8:39now
  247. 8:40this is important context because
  248. 8:43bug bounty programs the topic of which
  249. 8:45we're going to discuss today was the
  250. 8:46major kind of counter trend
  251. 8:49uh in a lot of that kind of profession
  252. 8:52like
  253. 8:53hiring of standing professional security
  254. 8:56researchers and bug down he's basically
  255. 8:58created a casualized market
  256. 9:01by which
  257. 9:02companies could uh solicit the
  258. 9:05submission of vulnerabilities in a very
  259. 9:08private directed way and pay piecemeal
  260. 9:11uh to the workers who did that and we're
  261. 9:12going to hear a lot more about the
  262. 9:14dynamics of that in just a second as i
  263. 9:17turn it over to i believe uh ryan alice
  264. 9:20ryan is uh is the is starting
  265. 9:23um
  266. 9:24so yeah take it away and um i'm excited
  267. 9:27for this thanks everyone
  268. 9:29all right great thanks matt i appreciate
  269. 9:30it hello everybody welcome from my
  270. 9:33basement in boston massachusetts i'm
  271. 9:34sorry we can't be together but i'm glad
  272. 9:36we can connect this way
  273. 9:38so i thought what um i would do with you
  274. 9:40ann my co-author on this new report
  275. 9:41bounty everything hackers in the making
  276. 9:43of the global bug marketplace which we
  277. 9:44published with dad and society a couple
  278. 9:46weeks ago was provide you with like the
  279. 9:48cliff notes overview of the report it's
  280. 9:50a long report these are all very
  281. 9:52detailed excellent long reports but i
  282. 9:54thought it'd be useful to have like a
  283. 9:55quick summary so you ann and i are going
  284. 9:57to spend a little time just walking
  285. 9:58through maybe 10 minutes what the report
  286. 10:00argues sort of top line conclusions
  287. 10:02so a little bit of context here um for
  288. 10:04our report we were really curious about
  289. 10:06bhagnani programs we wanted to
  290. 10:08understand them where they came from
  291. 10:09where they're going and most importantly
  292. 10:11what they mean for the workers who
  293. 10:13participate in them so we went out and
  294. 10:14we interviewed over 40 different folks
  295. 10:17who participate in the market that's
  296. 10:18hackers who find and sell flaws people
  297. 10:20who do triage and run and manage these
  298. 10:22programs as well i think a couple of the
  299. 10:24folks we spoke with might be listening
  300. 10:26today and i can't wait for them to chime
  301. 10:28in and tell us what we got wrong
  302. 10:30at the end during q a um but those
  303. 10:32stories really informed our report and
  304. 10:34what we found was
  305. 10:35that bounty programs offer a lot of
  306. 10:38fantastic opportunities there's pleasure
  307. 10:40to be found in the market there's new
  308. 10:41career opportunities they stabilize they
  309. 10:43provide opportunities for recognition
  310. 10:44for hackers that have been missing they
  311. 10:46provide rewards to hackers as well
  312. 10:48however
  313. 10:50some of the more celebratory accounts of
  314. 10:51the market seem to miss what the labor
  315. 10:53dynamics actually are and the ways in
  316. 10:55which bug bounty programs in some ways
  317. 10:57have created unanticipated risks risks
  318. 11:00both for the workers themselves who are
  319. 11:02participating in this market and in some
  320. 11:04ways broader security risks for all of
  321. 11:06us when they're not designed correctly
  322. 11:08or implemented appropriately bug bounty
  323. 11:10programs can actually be
  324. 11:12counterproductive and can undermine
  325. 11:13security
  326. 11:14so by going out and speaking with these
  327. 11:16people we got a little bit better
  328. 11:17insight into how the market operates
  329. 11:19what makes it tick and we're going to
  330. 11:20share all that with you today
  331. 11:22um so the report does and sort of walks
  332. 11:24through a couple of key topics first we
  333. 11:26provide a sort of overview of what bug
  334. 11:28bounty programs are and i'll do that in
  335. 11:29just a moment
  336. 11:30then we talk about where they came from
  337. 11:32their history starting in the mid 1990s
  338. 11:34with netscape
  339. 11:35then we look at the motivations for
  340. 11:37people who participate in this market
  341. 11:38and the risks that they face
  342. 11:40and then finally we conclude with some
  343. 11:41recommendations about how we can maybe
  344. 11:43imagine a future where bug bounty
  345. 11:44programs serve not only um the interests
  346. 11:47of the programs that run them but
  347. 11:48workers and society at large
  348. 11:50so very quickly um i'm going to give a
  349. 11:52quick overview of what bug bounty
  350. 11:54programs are in case any of you are
  351. 11:55unfamiliar this is new to you
  352. 11:57so bug body programs are fairly simple
  353. 11:59and straightforward there are ways in
  354. 12:01which hackers sell bugs to programs and
  355. 12:03platforms
  356. 12:05they can be operated in a few different
  357. 12:06ways they can be open or closed open
  358. 12:08anyone can submit closed also only
  359. 12:10invitation only
  360. 12:12additionally they can be run by the
  361. 12:14vendor themselves so microsoft or google
  362. 12:16or facebook might run their own bug
  363. 12:17bounty program or they can be run by a
  364. 12:19platform like hacker one or bug crowd
  365. 12:21that runs them for them now these
  366. 12:23programs were once upon a time like
  367. 12:24really
  368. 12:25novel
  369. 12:26and the province of high-tech companies
  370. 12:28now it seems like everybody has one
  371. 12:30united airlines department of defense we
  372. 12:31always are updating the slides my
  373. 12:33favorite recent one is lululemon the
  374. 12:34clothing uh the clothing company
  375. 12:37so they become pretty common
  376. 12:39but for the folks that working in them
  377. 12:40as we'll see um they can have
  378. 12:42unanticipated risks and hazards so
  379. 12:44briefly i'll walk through the history if
  380. 12:45you go to the next slide and tell you
  381. 12:46where they came from
  382. 12:47how they started out
  383. 12:49so bug bounty programs sort of emerge
  384. 12:52from two competing different interests
  385. 12:54on the one hand there's something of a
  386. 12:55pr stunt a way of
  387. 12:58sweeping under the rug bad press so to
  388. 13:00understand that sort of thrust and where
  389. 13:02they come from we have to go back to it
  390. 13:04seems like yesterday to me and maybe
  391. 13:05some of the other folks on the call but
  392. 13:06from some other people might be ancient
  393. 13:08history it's the mid 1990s
  394. 13:10and netscape so netscape was at the time
  395. 13:12in 1995 one of the largest and most
  396. 13:15stunning successes on wall street they
  397. 13:17just gone public in their browser
  398. 13:18netscape navigator you see the little
  399. 13:20logo there on the left hand side that's
  400. 13:21sort of aqua n
  401. 13:24um dominated the market it was the first
  402. 13:26most successful widely used web browser
  403. 13:29netscape had gone
  404. 13:31public in a stunning display and had
  405. 13:34sort of dominated
  406. 13:36wall street expectations and was a real
  407. 13:38star however they had two serious
  408. 13:40problems at the time the first problem
  409. 13:42was they didn't really make any money
  410. 13:43which is always a problem
  411. 13:44the second problem which was equally
  412. 13:46annoying to the folks who ran that scape
  413. 13:48was that every time a security
  414. 13:50researcher or hacker found a new flaw in
  415. 13:52netscape's software it seemed to make
  416. 13:54headline news and we're not just talking
  417. 13:56like in the computer security press
  418. 13:57we're talking the new york times the
  419. 13:58wall street journal the boston globe npr
  420. 14:01repeatedly security researchers were
  421. 14:03finding bugs disclosing them to the
  422. 14:05public through what matt described as
  423. 14:06full disclosure and making headline news
  424. 14:09this was a serious problem a serious
  425. 14:11headache for netscape
  426. 14:12and in the fall of 1995 they decided to
  427. 14:15do something about it
  428. 14:16they decided to launch what they
  429. 14:18described at the time as a bugs bounty
  430. 14:19program
  431. 14:20it was a way in which hackers would not
  432. 14:22be sued their voices wouldn't be
  433. 14:24restrained in that way they'd be invited
  434. 14:26to submit their bugs to netscape
  435. 14:27privately and netscape would pay them
  436. 14:29t-shirts a couple hundred bucks
  437. 14:32in exchange for submitting their bug to
  438. 14:34them directly it was a brilliant idea it
  439. 14:37was a way of short-circuiting and
  440. 14:38cutting off the sort of headaches bad
  441. 14:41press that was associated with full
  442. 14:42disclosure while borrowing some of the
  443. 14:44ethos of the free and open source
  444. 14:46software movement of collaboration
  445. 14:48inviting hackers in
  446. 14:50netscape's sort of gambit was pretty
  447. 14:52successful the press attention quickly
  448. 14:54changed and for a while this no longer
  449. 14:56was a big problem for netscape so one of
  450. 14:58the things that this story tries to
  451. 14:59bring out and the reason why i think the
  452. 15:00history is interesting not just like is
  453. 15:02a historical curiosity is it shows us
  454. 15:05that power and control in some ways were
  455. 15:07baked into the model of bugs from day
  456. 15:09one it was a way of restraining and
  457. 15:11counteracting full disclosure if we go
  458. 15:13to the next slide that'd be helpful
  459. 15:17but bug bug body programs didn't just
  460. 15:19emerge from the desire of companies to
  461. 15:21sort of
  462. 15:22enclose disclosure and sort of cut off
  463. 15:24the sort of free flow of information
  464. 15:25that hackers were celebrating at the
  465. 15:27time i had a different genesis as well
  466. 15:29in the early 2000s hackers were starting
  467. 15:32to
  468. 15:33demand more respect
  469. 15:34more recognition more legal protections
  470. 15:37and money so here we have a great sign
  471. 15:40scrawled on a piece of cardboard no more
  472. 15:41free bugs and that's dino de xavi and
  473. 15:44alex sauron charlie miller is sort of
  474. 15:46the third of the three musketeers and
  475. 15:48they got up on stage in 2009 in a big
  476. 15:50conference at cansec west a security
  477. 15:52conference and said that no more would
  478. 15:54they be submitting bugs free of charge
  479. 15:56they wouldn't release them to the public
  480. 15:57they weren't going to lease them to
  481. 15:58vendors unless they got paid
  482. 15:59this is an important moment hackers were
  483. 16:02standing up and articulating a new
  484. 16:03desire and a new sort of conception of
  485. 16:05their work as work from now on they said
  486. 16:08you're not going to get this from free
  487. 16:09you got to pay us
  488. 16:11companies like google and then facebook
  489. 16:13and microsoft were listening and they
  490. 16:15basically agreed
  491. 16:16they instituted bug bounty programs as a
  492. 16:18way to recognize the work hackers were
  493. 16:20doing the serious and important
  494. 16:21contribution contributions they were
  495. 16:23making providing them also with some
  496. 16:25legal protections and a pathway to gain
  497. 16:27some recognition and it was very
  498. 16:28important and useful
  499. 16:30what happened next was bug value
  500. 16:32programs did just stay in that little
  501. 16:33corner of the world of the high-tech
  502. 16:34world they started to spread out
  503. 16:36significantly and the way they did so
  504. 16:38was by being adopted by bounty companies
  505. 16:41platforms like hacker one and bug crowd
  506. 16:43they would take this model and spread it
  507. 16:45seemingly everywhere so you can chart it
  508. 16:47from netscape to microsoft and google to
  509. 16:50the lululemons of the world
  510. 16:52and when that happened bug bounty
  511. 16:53programs no longer were just a way for
  512. 16:55covering up bad pr they were no longer a
  513. 16:58way to just simply provide recognition
  514. 16:59for security researchers they became a
  515. 17:02way of transforming hacky into gig work
  516. 17:04and that transformation is very
  517. 17:05important so i think we'll go on to the
  518. 17:06next slide and i'll turn it over to my
  519. 17:08co-author yuan yuan i think this is
  520. 17:10where you jump in yes thank you thank
  521. 17:12you everyone for having me super i'm
  522. 17:14glad to be here and talk about our
  523. 17:15research on bug bounties so i wanted to
  524. 17:17talk about who bug bounty workers are
  525. 17:20and what motivates them
  526. 17:22we found in our work that bug bounty
  527. 17:23work draws on a young and global
  528. 17:25workforce
  529. 17:27of people working hard to find security
  530. 17:28flaws in systems so when bug-bounding
  531. 17:31programs became predominant in
  532. 17:32particularly in 2010 and beyond
  533. 17:35um
  534. 17:36uh it attracted a global workforce
  535. 17:38reports from bug money programs and
  536. 17:40platforms hacker one and bug crowd
  537. 17:42provide a window into this labor market
  538. 17:45we found from looking at the reports
  539. 17:47from 2019 2020
  540. 17:49that a large majority of workers are
  541. 17:50under 30 and under 20 and many are
  542. 17:53students hacker ones report from 2020
  543. 17:56shows as well that 40 of hackers spend
  544. 17:5820 plus hours a week hacking to find
  545. 18:00bugs which is a lot of time
  546. 18:02and despite bug bounty platforms
  547. 18:04advertising about high worker wages
  548. 18:06research by ryan and others shows that
  549. 18:08only a small handful of hackers earn the
  550. 18:10bulk of these bounty payouts and his
  551. 18:12work ryan um is in this book new
  552. 18:15solutions for cyber security and feel
  553. 18:17free to add to anything i've missed on
  554. 18:18that ryan because i know you did such
  555. 18:20important research on that no i think
  556. 18:22you got it you and that's great thank
  557. 18:23you
  558. 18:25yeah so what that means though is that
  559. 18:26there's stratification there is uh you
  560. 18:29know a lot of money to earn but a small
  561. 18:30amount of people are earning a lot of
  562. 18:32money and the majority of people are
  563. 18:34earning small amounts of money so the
  564. 18:36promises of bugbendi uh bug menu work as
  565. 18:39really lucrative don't come true
  566. 18:40necessarily for a lot of the people
  567. 18:43so as mentioned the bugbending workforce
  568. 18:44is international and hacker one and bug
  569. 18:46credit reports um say that upwards of
  570. 18:49seventy eighty percent of people
  571. 18:50disclosing flaws to their platforms are
  572. 18:52based outside of the u.s
  573. 18:54these platforms have also reported that
  574. 18:5610 to 20 of their registered hackers are
  575. 18:58based in india who make up a significant
  576. 19:01portion of this workforce
  577. 19:03and the last thing we found too is that
  578. 19:05most of the companies with bug money
  579. 19:06programs are in the us showing that
  580. 19:08these companies are relying on a young
  581. 19:09workforce outside of the country with
  582. 19:12many people coming from the global south
  583. 19:14so to go to the next side i wanted to
  584. 19:16talk about what motivates big bounty
  585. 19:18workers
  586. 19:20we have a text heavy slide here showing
  587. 19:21uh what motivates people but i you know
  588. 19:24i'm just pulling some highlights from a
  589. 19:26report and the first thing i wanted to
  590. 19:27say is that there is no single
  591. 19:29motivation for hacking or engaging in
  592. 19:30bug bunny work motivations often overlap
  593. 19:33and work by gabriela coleman shows that
  594. 19:35hackers constitute a constellation of
  595. 19:38loosely tethered and evolving
  596. 19:39subcultures with shifting members morris
  597. 19:41and rights but what we found is that
  598. 19:43many people who do have bug banner work
  599. 19:45do it full-time some people do it
  600. 19:47part-time and many do on the side for
  601. 19:48extra spending money and it's important
  602. 19:50to acknowledge as well that several
  603. 19:52hackers we spoke to appreciated the
  604. 19:54flexibility of bug binding work in terms
  605. 19:55of working hours and choosing what to
  606. 19:57hack on and many of you engaging in bug
  607. 19:59bunnies as an on-ramp to more secure
  608. 20:01work there's even this entire industry
  609. 20:04of training people to do bug bound new
  610. 20:06work you can get certificates you can
  611. 20:07you can go to um sort of informal
  612. 20:09schools and and do training for this
  613. 20:11which means that there's another even
  614. 20:12there's another you know market emerging
  615. 20:14on top of the market for flaws
  616. 20:16in terms of the actual motivations as
  617. 20:18well beyond money and and and
  618. 20:21remuneration my new hackers we spoke to
  619. 20:23said they found hacking fun and saw
  620. 20:25their efforts similar to solving a
  621. 20:26puzzle for them they think that um bug
  622. 20:29benny work is a type of technical work
  623. 20:31where they can improve their skills and
  624. 20:32get better at what they do i might come
  625. 20:34as one hacker we spoke to who said it's
  626. 20:37the intellectual satisfaction about you
  627. 20:38know just finding a bug and exploiting a
  628. 20:40program and making it do something it
  629. 20:42wasn't intended to do the puzzle solving
  630. 20:44aspect of it i think is pretty
  631. 20:46satisfying
  632. 20:48other hackers we spoke to find security
  633. 20:50work and hacking and bug money work you
  634. 20:52know thrilling or engaging there could
  635. 20:54be a rush with finding something that is
  636. 20:56serious and that can be exploited one
  637. 20:58hacker we spoke to described the ability
  638. 21:00to send negative amounts of money on a
  639. 21:02cryptocurrency platform and therefore
  640. 21:03receiving positive amounts as something
  641. 21:06that came with a rush because he
  642. 21:07realized that this thing he had found
  643. 21:09could be exploited for for serious harm
  644. 21:11potentially
  645. 21:12many others that we spoke to as well
  646. 21:14found the work satisfying from a moral
  647. 21:15standpoint they they think of what their
  648. 21:17do is as hackers as a public good and as
  649. 21:20serving their communities so for alyssa
  650. 21:22herrera another hacker we spoke to she
  651. 21:24she's motivated to quote help further
  652. 21:26protect users and help further the
  653. 21:28standard of security end quote but i
  654. 21:30want to say as well that there are
  655. 21:31parallels to bug bounty platforms and
  656. 21:33other gig work platforms like uber as
  657. 21:36analyzed by alex rosenblatt who used to
  658. 21:38be at data in society research institute
  659. 21:39and is now at uber
  660. 21:41platforms can glamorize work as heroic
  661. 21:43and for the public good they can take
  662. 21:45advantage of workers desires to do good
  663. 21:48and work in the world and you know they
  664. 21:49pay people less they take advantage of
  665. 21:51them potentially because they frame
  666. 21:53their work as community service
  667. 21:55lastly for almost all the hackers we
  668. 21:57spoke to big brand new work provides
  669. 21:59them with a sense of community a sense
  670. 22:00of belonging and of being known
  671. 22:02sometimes in a large and sometimes at a
  672. 22:04small scale as well and this is
  673. 22:05something that can also be exploited and
  674. 22:07can be used to gamify bug body work
  675. 22:10which leads very well into some of the
  676. 22:11risks of this labor
  677. 22:14and and to the next slide as well
  678. 22:21thanks jan so as you had mentioned folks
  679. 22:23participate in this market for a variety
  680. 22:24of different reasons for a significant
  681. 22:26subset this is their job it's not for
  682. 22:28beer money it's not just a hobby it's
  683. 22:30work and for many of them as yuan just
  684. 22:33mentioned it's a way of hope that they
  685. 22:35will use this as a stepping stone to a
  686. 22:37career where they can engage in
  687. 22:39full-time work
  688. 22:40it's really interesting to talk to these
  689. 22:42folks to hear about their frustrations
  690. 22:43and their pleasures
  691. 22:45one of the things we see here echoed
  692. 22:47with other forms of good work is that
  693. 22:49risks are disproportionately shifted on
  694. 22:51the workers themselves rather than the
  695. 22:52organizations so the creation of bug
  696. 22:54bounty programs as they have been
  697. 22:56designed now puts workers in some ways
  698. 22:59at risk
  699. 23:00there's legal in protections are varied
  700. 23:02some programs offer safe harbors others
  701. 23:04do not so there's legal risks that are
  702. 23:06still there we also see that there's
  703. 23:09significant risks of simply
  704. 23:10uncompensated time hackers are only paid
  705. 23:13when they're the first one to find a bug
  706. 23:15if you're the second one too bad
  707. 23:17so there's this race to be first which
  708. 23:19leads to enormous amount of
  709. 23:20uncompensated time for the people
  710. 23:21participating in this market
  711. 23:23additionally we see that the bug value
  712. 23:26programs themselves wield enormous power
  713. 23:29they define what counts
  714. 23:31they're sort of no real way to challenge
  715. 23:33that review or no meaningful ways to
  716. 23:35challenge that review in many cases
  717. 23:37so what this means is in other words you
  718. 23:38could spend hours and hours looking for
  719. 23:40bugs find new submissions submit it only
  720. 23:42be told actually it's not a valid issue
  721. 23:44or it's out of scope or it's a duplicate
  722. 23:46and the hacker themselves has put all
  723. 23:47this time in with very little return now
  724. 23:50this is fine if we think about hacking
  725. 23:52as
  726. 23:53a calling it's fine if we think about
  727. 23:55hacking as a hobby when we think about
  728. 23:57it as work what we start to see is the
  729. 23:58risks disproportionately fall on the
  730. 24:00side of the workers
  731. 24:02we also see there's challenges around
  732. 24:04access how you get access to the most
  733. 24:06lucrative corners of the market which
  734. 24:07are live hacking events or private
  735. 24:09programs is often up for grabs it's not
  736. 24:12clear it requires workers to invest more
  737. 24:14and more time with the hopes of getting
  738. 24:15one of those invitations
  739. 24:17and lastly i'll say the risks here
  740. 24:18aren't just for the hackers themselves
  741. 24:20they're for all of us
  742. 24:21one of the big worries and one of the
  743. 24:23things we tease out in the report is
  744. 24:24this idea that in some cases folks are
  745. 24:27trying to use bug bounty programs not as
  746. 24:28an added layer of security but as a
  747. 24:30replacement for in-house security work
  748. 24:32this is like a very grim irony
  749. 24:35hackers are participating in these
  750. 24:36markets with the hopes that someday
  751. 24:37they're going to land a job doing
  752. 24:39full-time security work however on the
  753. 24:41other side of the table we see folks who
  754. 24:43think that this model bounty work
  755. 24:45digital piece work as we described in
  756. 24:46our report is going to replace those
  757. 24:48very jobs they're trying to seek and so
  758. 24:50this idea that the jobs themselves might
  759. 24:51disappear is something that is very
  760. 24:53worrying not only for the workers
  761. 24:55themselves but also for the rest of us
  762. 24:57because if we're going to defer to and
  763. 24:59rely on this sort of model of
  764. 25:00maintenance and security work we're
  765. 25:02going to miss so much we're going to
  766. 25:04live in a world that perpetuates bugs
  767. 25:06rather than fixes them at the root cause
  768. 25:08now our report sometimes has a bit of a
  769. 25:11doom and gloom to it but we're academics
  770. 25:13of course there's doom and gloom but
  771. 25:14what would we you know what else would
  772. 25:15we do but at the end we end with some
  773. 25:17very hopeful and i think encouraging
  774. 25:19recommendations and so you ann i'll turn
  775. 25:21it back over to you to conclude our sort
  776. 25:22of brief summary and talk about some of
  777. 25:24the more hopeful ideas we have for how
  778. 25:26this market might be reformed in a
  779. 25:27positive way i'll turn it back over to
  780. 25:29you
  781. 25:30yeah thanks so much ryan and we do have
  782. 25:32recommendations because our report
  783. 25:34highlights a lot of the risks but we do
  784. 25:37also wanted we wanted to find solutions
  785. 25:39and begin mapping these solutions
  786. 25:42in order to better secure the working
  787. 25:45conditions of people doing this work and
  788. 25:46for security in general
  789. 25:48the first recommendation that we have
  790. 25:50and that came out of our work is that
  791. 25:52bug bounty programs should be just one
  792. 25:53layer of an organization's larger
  793. 25:55security posture
  794. 25:56security posture would look like how
  795. 25:59able an organization is to respond to
  796. 26:01bug reports
  797. 26:02how how much they can actually patch the
  798. 26:05system and
  799. 26:07security in a sense would refer to the
  800. 26:09protection of data the protection of
  801. 26:10systems the protection of intellectual
  802. 26:12property and many other things um but as
  803. 26:15biology programs are used for more uh
  804. 26:18complicated problems potentially and for
  805. 26:20socio-technical problems to build off
  806. 26:22work by matt gertzen here um
  807. 26:25you know an organization's posture will
  808. 26:28involve being able to handle reports for
  809. 26:30algorithmic bias and for problems like
  810. 26:32that and and it's really important that
  811. 26:35you know regardless of how and when bug
  812. 26:37money programs are used that this work
  813. 26:39never be a replacement for full-time
  814. 26:41infrastructure work in fact you will
  815. 26:44need um
  816. 26:46uh you know you will need a team of
  817. 26:48people who respond to reports and who
  818. 26:50fix
  819. 26:50problems that are raised and as we saw
  820. 26:52with the case of netscape it's far too
  821. 26:54easy to use bug bendy programs for pr
  822. 26:57um and to draw on uh bag bunny expert
  823. 26:59and cyber security expert katie masuris
  824. 27:01it's really easy as well for companies
  825. 27:03to use bugboundy as botox as she calls
  826. 27:05it where bounty programs would be used
  827. 27:08to cover up um
  828. 27:10systems and and security postures that
  829. 27:12are in fact uh not necessarily ready to
  830. 27:15handle
  831. 27:16uh the receipt you know the reception of
  832. 27:17flaws but then also where there are many
  833. 27:19flaws to be found and that and um
  834. 27:23and you know uh for for basically in
  835. 27:25short bug money programs um can look
  836. 27:28really good but it's really important
  837. 27:29that they have resources paired with
  838. 27:32them that brings me to my second point
  839. 27:34that bug many programs would require a
  840. 27:35huge amount of time effort skills and
  841. 27:37organizational resources in order for
  842. 27:39programs to be effective workers we
  843. 27:41spoke to consistently spoke about the
  844. 27:43less than ideal working conditions and
  845. 27:45the uncertainty they faced related to
  846. 27:47slow response times non-payment despite
  847. 27:50work being done which is indeed a part
  848. 27:52of piecework for example if you're a
  849. 27:54journalist and you publish an op-ed or
  850. 27:55if you publish a piece and no one wants
  851. 27:56to publish it that is a normal a normal
  852. 27:58thing in in journalism but it doesn't
  853. 28:00mean that this can't be improved and it
  854. 28:03also and you know workers we we spoke to
  855. 28:04said that there were valid flaws that
  856. 28:06they found but maybe they'd be
  857. 28:07duplicates or maybe that the company
  858. 28:09would say this is not a flaw but they
  859. 28:10still they'd patch it anyway and it's
  860. 28:12also a clear lack of recognition
  861. 28:15we found that hackers said for the work
  862. 28:17that they do
  863. 28:18the third thing is that hackers also
  864. 28:20need better legal protection in order to
  865. 28:22safety to safely disclose
  866. 28:23vulnerabilities there are indeed certain
  867. 28:25carve outs for security security
  868. 28:27research and anti-hacking laws both in
  869. 28:29canada and the us but good faith
  870. 28:30security researchers need legal
  871. 28:32protection that does not rely on the
  872. 28:34goodwill of organizations and companies
  873. 28:36not to pursue legal action in another
  874. 28:38project of mine i found that a promising
  875. 28:40legal approach is that in the
  876. 28:41netherlands where hacker intent and the
  877. 28:43steps that the hacker took to disclose
  878. 28:46are part of the decision-making process
  879. 28:47for prosecutors before hackers face
  880. 28:50criminal liability for disclosure so for
  881. 28:52example you may have seen the story of
  882. 28:54trump
  883. 28:54when he was president and he had a
  884. 28:57really weak password and and you know a
  885. 28:59dutch hacker had actually found out what
  886. 29:01this password was try to disclose it to
  887. 29:03trump's security team no one took this
  888. 29:05hacker seriously the hacker went public
  889. 29:07in the us it's quite possible and
  890. 29:09potentially even you know probable that
  891. 29:11this person would have faced serious
  892. 29:13legal risks but in the netherlands what
  893. 29:14the prosecutor did there because there
  894. 29:16was a main prosecutor and and they have
  895. 29:18um a fairly uh centralized system there
  896. 29:21for prosecution prosecutorial decisions
  897. 29:23the prosecutor there decided that you
  898. 29:25know this person had exhausted the
  899. 29:26recourse they had taken the steps
  900. 29:28necessary which would mean that they
  901. 29:30wouldn't be responsible criminally for
  902. 29:32disclosing this information to the
  903. 29:33public because they intended to fix the
  904. 29:35system
  905. 29:36the fourth thing is that as ryan
  906. 29:38mentioned organizations and platforms
  907. 29:40that run bunk body programs often serve
  908. 29:42many of the same functions as employers
  909. 29:44do and they play a pivotal role in
  910. 29:46deciding how bug pound bug reports are
  911. 29:48handled
  912. 29:49bug bounty programs easily perpetuate
  913. 29:51the gig work norm of renting workers to
  914. 29:53draw on the work again of alex
  915. 29:54rosenblatt but many workers crave
  916. 29:56stability beyond this precarious
  917. 29:57piecework
  918. 29:58we think that classifying hackers and
  919. 30:00other bounty workers as employees and
  920. 30:02non-independent contractors would open
  921. 30:04up opportunities for these workers to
  922. 30:06secure workplace legal protections and
  923. 30:08benefits
  924. 30:09to go to the next slide as well
  925. 30:11the fifth thing we wanted to say is that
  926. 30:13regardless of
  927. 30:14the you know employment relationship our
  928. 30:16research found that organizations need
  929. 30:18to be transparent
  930. 30:19about how they measure workers
  931. 30:21performance and what their triage and
  932. 30:22dispute resolution processes are for bug
  933. 30:25reports workers we spoke to told us they
  934. 30:27didn't completely understand how people
  935. 30:28were invited to things like private
  936. 30:30events where an elite group of people be
  937. 30:32invited to hack first then get bigger
  938. 30:34payouts and be featured
  939. 30:36and and private events where again you
  940. 30:39would be a trusted entity you'd be a
  941. 30:40trusted person to hack first
  942. 30:42um and you'd have many many perks along
  943. 30:44with that free flights to things and
  944. 30:46events and networking and all that kind
  945. 30:48of and all that and indeed
  946. 30:50um it's it's very normal in an
  947. 30:52employment context that you are measured
  948. 30:54and you don't always know how you're
  949. 30:55measured but that doesn't mean that
  950. 30:57there shouldn't be a better standard for
  951. 30:59performance metrics in the world in the
  952. 31:00world of hacking and for bug bounty
  953. 31:02workers we also believe that all workers
  954. 31:04would benefit if there were increased
  955. 31:06clarity around how these perks
  956. 31:07promotions and prestigious invites were
  957. 31:09doled out and particularly with respect
  958. 31:11to triage decisions so if you say i have
  959. 31:13a flaw i'm going to submit this it's
  960. 31:15it's really important to be clear about
  961. 31:17what your process is for triage and for
  962. 31:20handling dispute resolution because if
  963. 31:21you just ghost a worker you're not going
  964. 31:23to build goodwill with people
  965. 31:25finally we also really want to urge
  966. 31:27people to reconsider the approach that
  967. 31:29uses a global pool of insecure workers
  968. 31:32to maintain business models centered on
  969. 31:34rapid iteration and perpetual beta
  970. 31:36that's because this model and this
  971. 31:38approach can perpetuate the existence of
  972. 31:40security flaws because you rely on a
  973. 31:42market to be there because your business
  974. 31:43model functions upon and rest upon the
  975. 31:46idea that people will find flaws in
  976. 31:48systems and therefore you profit off of
  977. 31:49bugs and this approach as well can
  978. 31:51solidify stratification across racial
  979. 31:54wines
  980. 31:54what we found is that the bugbending
  981. 31:57model can create the ideal conditions
  982. 31:59for exacerbating labor inequalities in
  983. 32:01it work and can also create forms of
  984. 32:03predatory inclusion to draw on the work
  985. 32:05of tracy mcmillan cotton that absorb
  986. 32:07vulnerable workers into hacking for
  987. 32:09wages in an extractive labor
  988. 32:11relationship when bounty programs and
  989. 32:13platforms fail to address the impacts of
  990. 32:15their working conditions on certain
  991. 32:17communities such as racialized workers
  992. 32:19and these programs are not necessarily
  993. 32:20inclusive but can be exploitative and i
  994. 32:22think it's important that um combating
  995. 32:25racialized labor inequalities would be a
  996. 32:27part of this journey and part of the
  997. 32:29direction of bounty programs in general
  998. 32:31and this would require rethinking how
  999. 32:33workers are integrated into an
  1000. 32:35organization and on what terms
  1001. 32:38so those are recommendations a little
  1002. 32:39bit doom and gloom there at the end
  1003. 32:41still but we are indeed hopeful at the
  1004. 32:44end and i hope this summarizes well what
  1005. 32:46our report has touched on and
  1006. 32:48um welcome any and excited to answer any
  1007. 32:51questions you have about our report as
  1008. 32:52well
  1009. 32:59awesome thank you you ann uh also i just
  1010. 33:01wanted to note uan
  1011. 33:03shouted out uh some research that i've
  1012. 33:05done on the concept of social technical
  1013. 33:06security thank you for that i also want
  1014. 33:09to acknowledge that
  1015. 33:10gabrielle lim and elizabeth watkins uh
  1016. 33:14have been co-authors in some of the work
  1017. 33:15i published on that or be integral to
  1018. 33:17those ideas
  1019. 33:18so thank you for referencing that and
  1020. 33:21who's up next josh or camille i can take
  1021. 33:24it from here
  1022. 33:26all right it's such a joy to be able to
  1023. 33:28present our work after iwan ryan and
  1024. 33:32matt because we had the great pleasure
  1025. 33:34of working on similar topics at the same
  1026. 33:36time and it was very reassuring to know
  1027. 33:39that we were not alone in the rabbit
  1028. 33:40hole and we benefited greatly from their
  1029. 33:43insight their research and their work
  1030. 33:45and so i'm here today with my colleague
  1031. 33:47josh and we're representing the broader
  1032. 33:49team behind a report called bug bounties
  1033. 33:52for algorithmic harms which was just
  1034. 33:54published by the algorithmic justice
  1035. 33:56league and on this slide you can see our
  1036. 33:59co-authors which are sasha deb and joy
  1037. 34:02and this report looks at how people who
  1038. 34:06work on minimizing algorithmic harm so
  1039. 34:08the field of algorithmic harms can learn
  1040. 34:10from infosec practices particularly from
  1041. 34:13the bounties but also from other types
  1042. 34:15of vulnerability management programs and
  1043. 34:18we are particularly interested in what
  1044. 34:21lessons they are for
  1045. 34:22vulnerability reporting and
  1046. 34:24vulnerability disclosure
  1047. 34:26um
  1048. 34:27you can read the full report at agl.org
  1049. 34:31bugs
  1050. 34:32it's a bit longer than a hundred pages
  1051. 34:34and we're not gonna try to recap
  1052. 34:36everything about the report uh we're
  1053. 34:39gonna try to take you through a few
  1054. 34:40vignettes to highlight bits and pieces
  1055. 34:42here and there
  1056. 34:44josh show it to you
  1057. 34:47thanks kim uh and likewise uh you know
  1058. 34:50thanks uh to the folks of colombia for
  1059. 34:52for having us today and and to the
  1060. 34:54awesome presenters beforehand uh looking
  1061. 34:56forward to this discussion uh afterwards
  1062. 34:58so let's start with a little bit of you
  1063. 35:00know history behind uh this report back
  1064. 35:02in 2017 uh when dr joy balawini uh
  1065. 35:06founder of ajl exposed how facial
  1066. 35:10recognition technologies or or frts fail
  1067. 35:14more on on women
  1068. 35:15and on darker skinned people and and
  1069. 35:17most of all on uh women with darker skin
  1070. 35:21she and her research collaborators um
  1071. 35:23were met with a very adversarial
  1072. 35:26reaction uh from from the industry that
  1073. 35:28they were scrutinizing uh frt vendors
  1074. 35:31responded by attempting to discredit the
  1075. 35:33research and the researchers
  1076. 35:36um but eventually they had to backtrack
  1077. 35:39and and in particular you know this this
  1078. 35:41uh
  1079. 35:42this backtracking came about as a result
  1080. 35:44in part of a nist study that confirmed
  1081. 35:47the findings
  1082. 35:48of their research and this is an example
  1083. 35:50of how
  1084. 35:52there are you know parallels uh in in
  1085. 35:55what's going on right now in the fight
  1086. 35:57against algorithmic harm
  1087. 35:59um to the early history
  1088. 36:01of of infosec or of sort of cyber
  1089. 36:04security as an established discipline uh
  1090. 36:07and as as ryan and yuan just just
  1091. 36:10discussed you know the you look back
  1092. 36:13sort of the the 1990s in the early 2000s
  1093. 36:16and companies were constantly attempting
  1094. 36:18to to discredit to sue you know even
  1095. 36:20file uh criminal charges uh against
  1096. 36:23hackers just for finding and sharing
  1097. 36:25security vulnerabilities including uh
  1098. 36:28with the sort of intent to to fix those
  1099. 36:31but before we go any further let's
  1100. 36:33clarify what we mean by algorithmic harm
  1101. 36:35um so an algorithmic harm occurs uh we
  1102. 36:39we sort of speculate at ajl or not
  1103. 36:41speculate it's it's uh you know based on
  1104. 36:43the organization and the research that
  1105. 36:45comes from it but this is our working
  1106. 36:47definition uh it occurs when an
  1107. 36:49organization or an individual uses an
  1108. 36:51algorithmic system to automate
  1109. 36:52classification prediction
  1110. 36:54recommendations or scoring
  1111. 36:56in a process that harms people in some
  1112. 36:58way
  1113. 36:59algorithmic harm can involve loss of
  1114. 37:01freedom or opportunity violation of
  1115. 37:03rights or physical safety social stigma
  1116. 37:06or affronts to dignity and and even loss
  1117. 37:09of life
  1118. 37:10um and these days people often talk
  1119. 37:12about racial or gender bias in training
  1120. 37:14data and that is certainly
  1121. 37:16a part of this problem and a part of the
  1122. 37:18causes of this problem but algorithmic
  1123. 37:21harm is not just about biased data
  1124. 37:24it can arise at or as a product of any
  1125. 37:26stage in the life cycle of an
  1126. 37:29algorithmic system
  1127. 37:30or an ai system um and during data
  1128. 37:34collection and classification sure but
  1129. 37:36also in model development and testing or
  1130. 37:38after uh deployment in the context of
  1131. 37:41use by real human beings uh next slide
  1132. 37:44please
  1133. 37:46and this isn't just hypothetical this
  1134. 37:49isn't theoretical people in the real
  1135. 37:52world experience algorithmic harm in all
  1136. 37:54sorts of forms every single day
  1137. 37:57for example in 2020 the aclu
  1138. 38:01filed suit on behalf of robert williams
  1139. 38:04who's pictured here
  1140. 38:06who was falsely arrested in front of his
  1141. 38:08wife and two daughters
  1142. 38:10due to the failure of facial recognition
  1143. 38:13technology deployed by the detroit
  1144. 38:15police department he was mistakenly
  1145. 38:18wrongfully identified as someone who had
  1146. 38:20committed a theft
  1147. 38:22uh algorithmic harms can be
  1148. 38:24life-changing
  1149. 38:26um so the idea of rewarding folks
  1150. 38:29who might be well positioned to help
  1151. 38:31prevent them
  1152. 38:33or provide redress for them makes
  1153. 38:35a lot of sense in the abstract similar
  1154. 38:38to how rewarding hackers for discovering
  1155. 38:40vulnerabilities
  1156. 38:41makes sense but in both cases
  1157. 38:44and again as you know you've already
  1158. 38:46heard the devil is in the details
  1159. 38:49uh next slide please
  1160. 38:51so to help us uh more fully understand
  1161. 38:53the draws and the drawbacks of bug
  1162. 38:56bounties and whether they might really
  1163. 38:58be useful for algorithmic harms as some
  1164. 39:00had speculated previously we turned to
  1165. 39:03sort of fellow practitioners and
  1166. 39:04researchers some familiar faces up there
  1167. 39:06on the screen right now
  1168. 39:08who were kind enough to share their
  1169. 39:10wisdom expertise and ideas with us
  1170. 39:13for this report next slide and back over
  1171. 39:15to you cam
  1172. 39:16and so as we promised we're gonna go
  1173. 39:18through a few vignettes on the sort of
  1174. 39:20history of uh bug bounty on a little
  1175. 39:23journey we are going to start with a
  1176. 39:26somewhat wacky historical bounty as a
  1177. 39:29way to highlight some of the central
  1178. 39:30themes of our research but also as a way
  1179. 39:32to introduce our design lovers
  1180. 39:35then we're going to jump ahead to the
  1181. 39:37moment at which
  1182. 39:39traditional infosec bounties start to
  1183. 39:41encompass a greater range of
  1184. 39:43socio-technical issues that's happening
  1185. 39:46around 2018 which is a pivotal year for
  1186. 39:49that then we're going to look at
  1187. 39:51twitter's bias bounty challenge from
  1188. 39:53last year at defcon and finally we're
  1189. 39:56going to close with a look ahead on what
  1190. 39:58is happening right now with proctoring
  1191. 40:01software and what this may suggest for
  1192. 40:03the future of algorithmic harm's bounty
  1193. 40:07all right next slide and that's the
  1194. 40:08heavy one
  1195. 40:09okay so a key contribution of this work
  1196. 40:13we hope and again we're here to be kept
  1197. 40:15honest and to get uh criticism and
  1198. 40:17feedback and comments but we wanted to
  1199. 40:19really unpack the wide variety of the
  1200. 40:21bounties and associated mechanisms for
  1201. 40:24reporting and disclosing vulnerabilities
  1202. 40:26and abstract some key programmatic
  1203. 40:29differences which is what we call the
  1204. 40:30design levers
  1205. 40:32and how these levers are configured for
  1206. 40:34particular programs is really going to
  1207. 40:37shape what they do for transparency for
  1208. 40:40accountability for community building
  1209. 40:42and for some of these aspects that we
  1210. 40:44really cared about looking into these
  1211. 40:46programs to really understand how is it
  1212. 40:49that we can best adapt it to the
  1213. 40:50practices that we care about
  1214. 40:52and so in this uh exercise we are
  1215. 40:56building on previous work including work
  1216. 40:58from ryan in the article that you went
  1217. 41:01cited and this work had noted that these
  1218. 41:03bug bounty programs tend to vary by
  1219. 41:06how they define market access
  1220. 41:08program duration and compensation and so
  1221. 41:11we're adding on these levers to talk
  1222. 41:13about whether public disclosure is
  1223. 41:16guaranteed on a pre-established time
  1224. 41:18frame
  1225. 41:19as you can guess this is going to be
  1226. 41:21extraordinarily important for both
  1227. 41:22transparency and for accountability
  1228. 41:25we're also looking into how a given
  1229. 41:27program is managed is it fully in-house
  1230. 41:30or is it to some degree outsourced for
  1231. 41:32instance to hacker one to bug crowd or
  1232. 41:34to a platform like this
  1233. 41:36what is officially considered in scope
  1234. 41:38and what level of access are researchers
  1235. 41:41actually given
  1236. 41:42whether a program is voluntary or
  1237. 41:45adversarial in other words has the
  1238. 41:47target organization consented to
  1239. 41:50receiving vulnerability reports that
  1240. 41:52dimension is one that's really important
  1241. 41:54in our work because we have found and
  1242. 41:56we're going to return to this that the
  1243. 41:59adversarial programs haven't really
  1244. 42:01found the right way to succeed in the
  1245. 42:04space
  1246. 42:05and with this we can try to make those a
  1247. 42:08little bit less abstract in applying
  1248. 42:11this into a very old bounty josh over to
  1249. 42:14you
  1250. 42:17yeah so not at all to preempt or
  1251. 42:20contradict the sort of origins of
  1252. 42:22bounties as previously discussed this is
  1253. 42:24clearly an out of left field historical
  1254. 42:27example
  1255. 42:28um but what the uh this challenge lock
  1256. 42:31which uh is up on the screen right now
  1257. 42:34uh which is from the 18th century what
  1258. 42:37it what it sort of shows is uh
  1259. 42:40you know how the idea of of uh exposing
  1260. 42:44flaws in security um you know it has a
  1261. 42:47has a long history as a means of
  1262. 42:49providing redress so this lock was
  1263. 42:51manufactured by joseph brahma it was a
  1264. 42:54locksmith
  1265. 42:55from the united kingdom
  1266. 42:57uh it had almost 500 million possible
  1267. 43:00combinations uh of course most copies of
  1268. 43:03this lock sold weren't uh inscribed uh
  1269. 43:07in the way that you can see here rather
  1270. 43:08this particular lock was created to sit
  1271. 43:11in brahma's shop front as a kind of
  1272. 43:13advertising
  1273. 43:14you know to the effect of i'm so
  1274. 43:16confident in strength of this lock that
  1275. 43:18i'll pay you if you can pick it now
  1276. 43:21there's a familiar idea
  1277. 43:23brahma's lock remained unbreakable and
  1278. 43:25the bounty was uncollected for decades
  1279. 43:2861 years
  1280. 43:29actually until 1851
  1281. 43:32when another locksmith an american
  1282. 43:35alfred charles hobbs succeeded in
  1283. 43:36picking brahma's lock after over 50
  1284. 43:38hours of tinkering over the course of
  1285. 43:40two weeks
  1286. 43:42next slide please
  1287. 43:43so considering this early very early
  1288. 43:46security bounty through the lens of our
  1289. 43:48design levers
  1290. 43:50we can observe that the child is
  1291. 43:52voluntary rather than adversarial since
  1292. 43:54the locksmith offered the challenge
  1293. 43:56compensated in the form of a one-time
  1294. 43:58bounty and well compensated um you know
  1295. 44:01200 guineas was the prize which is a
  1296. 44:04little bit over 20 000 in today's
  1297. 44:06currency uh and just as with uh you know
  1298. 44:09the the many of the bounties that we see
  1299. 44:11today
  1300. 44:12um hobbs being the first one to break it
  1301. 44:15was the winner of the prize uh
  1302. 44:17subsequent you know lock picking
  1303. 44:19wouldn't have have earned another prize
  1304. 44:22in terms of disclosure you know hobbs
  1305. 44:24reportedly performed the feed in front
  1306. 44:25of journalists which is about that's
  1307. 44:27about as full disclosure as
  1308. 44:29it's possible to get
  1309. 44:31and around the same time hobbs was
  1310. 44:33actually also making the case for
  1311. 44:35publishing weaknesses in lock design
  1312. 44:37specifically in his 1853 book
  1313. 44:39construction of locks and safes hobbs
  1314. 44:41wrote that quote the spread of knowledge
  1315. 44:43is necessary to give fair play to those
  1316. 44:45who might suffer by ignorance this was a
  1317. 44:47bounty with open participation anyone
  1318. 44:49could participate and the duration was
  1319. 44:51ongoing really ongoing like 61 years
  1320. 44:54ongoing and lastly regarding scope and
  1321. 44:56access focused on sort of picking the
  1322. 44:59lock so there was physical access there
  1323. 45:01um and and complete access you need to
  1324. 45:04break the lock i suppose physically and
  1325. 45:06inspect what was inside and the details
  1326. 45:08of how it worked for public so
  1327. 45:11what does this show again none of this
  1328. 45:13is sort of new conceptually at a high
  1329. 45:16abstract level and the idea of sort of
  1330. 45:19compensation for finding uh flaws in
  1331. 45:22systems of assurance whether it's
  1332. 45:23security assurance or whatever you know
  1333. 45:25these these potentially can apply in
  1334. 45:27various contexts
  1335. 45:29and you already know what happens next
  1336. 45:31uh you know what
  1337. 45:33pause 100 plus years and what happens
  1338. 45:36next is bug bounties come to infosec uh
  1339. 45:38next slide and back to you camille
  1340. 45:41and so here we're going to take a
  1341. 45:42ginormous sleep forward and skip the
  1342. 45:46wonderful and fascinating development of
  1343. 45:48how and when bug bounties come to
  1344. 45:51infosec
  1345. 45:52not only because
  1346. 45:54our co-researchers here have done a
  1347. 45:56great job at documenting it in their
  1348. 45:57reports and have given some of this
  1349. 45:59history on this panel
  1350. 46:00and we're gonna sort of
  1351. 46:03regroup in the early 2010. so at this
  1352. 46:06point uh we're already seeing the
  1353. 46:08widespread use of bug bounties and it's
  1354. 46:10often used in combination with
  1355. 46:12vulnerability disclosure programs and
  1356. 46:14with pen testing we've already seen the
  1357. 46:16rise of major bug bounty programs um
  1358. 46:19and platforms like hakka one rug crown
  1359. 46:21and yes we hack to sort of centralize
  1360. 46:23them and of course we're after the first
  1361. 46:26bug bounty programs by the u.s
  1362. 46:27government like hack the pentagon
  1363. 46:30at this point some of the largest
  1364. 46:32players in tech use these platforms
  1365. 46:34these intermediary platforms to solicit
  1366. 46:37and triage reports and as yuan discussed
  1367. 46:40they are some upside for the hackers
  1368. 46:42here for instance they use those
  1369. 46:44platforms you offer a more consistent
  1370. 46:47user experience they offer access to
  1371. 46:49many programs in one place they offer a
  1372. 46:51repository of fast reports to learn from
  1373. 46:54and often a community those are aspects
  1374. 46:57that we were really interested in in
  1375. 46:59thinking about the emergence of a
  1376. 47:01younger field like algorithmic harms
  1377. 47:03trying to think about what is the role
  1378. 47:05that those templates that those previous
  1379. 47:07reports that this community can play in
  1380. 47:10bringing about a community of practice
  1381. 47:13however as we discussed at the beginning
  1382. 47:15of this conversation those are also the
  1383. 47:18heady early days of the bug bounty
  1384. 47:20everything hype
  1385. 47:22with some wise researchers cautioning
  1386. 47:24that bounties would not work unless the
  1387. 47:27organization offering them are deeply
  1388. 47:29committed to secure development
  1389. 47:31practices throughout the entire product
  1390. 47:34life cycle and that is an insight that
  1391. 47:36we think translates well in the
  1392. 47:38algorithmic harm space where there is
  1393. 47:40often a lot of emphasis on the training
  1394. 47:45data when we consider algorithmic harms
  1395. 47:47often we hear people say oh if the
  1396. 47:49algorithm is wrong it's because the
  1397. 47:50training data was biased that can be a
  1398. 47:53part of it but of course it's not the
  1399. 47:55whole explanation and if we want to
  1400. 47:57meaningfully tackle algorithmic harms we
  1401. 47:59have to think about the entire life
  1402. 48:01cycle
  1403. 48:02so long story short uh bounties have
  1404. 48:04never been silver bullets and when we
  1405. 48:07fast forward again we can arrive in 2018
  1406. 48:11which is the cambridge analytica moment
  1407. 48:14i think we can do next slide here
  1408. 48:17after cambridge analytica we're quick
  1409. 48:20and we can also do next slide sorry
  1410. 48:23we um see very quickly facebook and
  1411. 48:26shortly after that google
  1412. 48:28announced a bug bounty for data and api
  1413. 48:31abuse now that's really interesting
  1414. 48:33because of course this is uh quite
  1415. 48:36similar to a book bounty it's kind of
  1416. 48:38managed the same but when you look into
  1417. 48:40the details of it it's substantially
  1418. 48:42different because it really comes and
  1419. 48:44stretch into those socio-technical
  1420. 48:46issues and at the end of the day privacy
  1421. 48:49abuse is meaningfully functionally
  1422. 48:52different than a security bug
  1423. 48:55and so the other thing that we learn in
  1424. 48:57this story and in this moment is the
  1425. 48:59pr values of big bounties as band-aids
  1426. 49:02in a crisis which uh euan and ryan
  1427. 49:05reminded us had a long history and the
  1428. 49:07last thing in 2018 that we thought was
  1429. 49:09particularly interesting is one other
  1430. 49:12organization out there at least with a
  1431. 49:15bounty that seeks to surface algorithmic
  1432. 49:18harms and that's rockstar game
  1433. 49:20so rockstar
  1434. 49:22is putting up this new bounty we can go
  1435. 49:24next slide in response to claim of false
  1436. 49:27positive band punishments from gamer who
  1437. 49:30have faced bans at the hands of
  1438. 49:32rockstar's teeth flagging algorithm
  1439. 49:35and so the company sets up this add-on
  1440. 49:37to his traditional security bounty
  1441. 49:39promising a ten thousand dollar reward
  1442. 49:42for anyone who could successfully
  1443. 49:44identify a
  1444. 49:45reproducible incorrect ban in either
  1445. 49:48grand theft auto or in red dead so if
  1446. 49:51you're out there playing these games
  1447. 49:53know that the bounty is still up
  1448. 49:55so what are we learning overall from
  1449. 49:56this expansion of bug downies
  1450. 50:00to data and api abuse and then to cheat
  1451. 50:02flagging algorithms that happens around
  1452. 50:052018
  1453. 50:06the first one is bug branding programs
  1454. 50:09can be applied to socio-technical
  1455. 50:11challenges
  1456. 50:12beyond security vulnerability and more
  1457. 50:14importantly they have already started
  1458. 50:17getting there right so our conclusion
  1459. 50:19was also bug boundary programs are
  1460. 50:21coming to a socio-technical issue near
  1461. 50:23you we see this trend already underway
  1462. 50:26we see this trend potentially
  1463. 50:28accelerating now some of this is good
  1464. 50:30because there's indeed lessons from
  1465. 50:32cyber security that we can stretch into
  1466. 50:34a new domain not only for instance
  1467. 50:36thinking about how to better protect
  1468. 50:38researchers who do this type of research
  1469. 50:41and this is where legal safe harbor can
  1470. 50:43come and play a meaningful role
  1471. 50:45but we also realize that some of this
  1472. 50:49really is again meaningfully different
  1473. 50:51and you can't just copy-paste this model
  1474. 50:53you have to rethink what is it that
  1475. 50:56you're trying to address who are you
  1476. 50:58trying to address it with and some of
  1477. 50:59the things that we cover in the report
  1478. 51:01is also many times you need a different
  1479. 51:04community of researchers to bring a
  1480. 51:06different perspective on these
  1481. 51:08socio-technical harms and we can pick
  1482. 51:10this up in the discussion together but
  1483. 51:12we've also found that often the
  1484. 51:14community of researchers that is most
  1485. 51:16traditionally engaged in these
  1486. 51:17traditional but bounties program do not
  1487. 51:20have the wide breadth diversity and
  1488. 51:23inclusion
  1489. 51:24that we would want in order to
  1490. 51:26meaningfully tackle some of these other
  1491. 51:27socio-technical issues the last thing of
  1492. 51:30course that gets confirmed in this
  1493. 51:32moment in time is that bug bounty
  1494. 51:34programs for algorithmic harms makes
  1495. 51:36business sense to do for some specific
  1496. 51:39companies at specific moments for
  1497. 51:41instance if you need to address a pr
  1498. 51:43concern or if you need to address um
  1499. 51:47a customer concern
  1500. 51:48so with this next video and over to you
  1501. 51:51josh
  1502. 51:52thanks okay so recently for defcon 2021
  1503. 51:56uh twitter announced a one-week
  1504. 51:58algorithmic bias bounty challenge this
  1505. 52:01program was created
  1506. 52:02by the company's machine learning ethics
  1507. 52:04transparency and accountability or meta
  1508. 52:07team they were the first meta before
  1509. 52:10facebook decided on a rebrand
  1510. 52:12and they did this bounty in partnership
  1511. 52:14with hacker one it focused on an image
  1512. 52:18cropping algorithm that users had
  1513. 52:20previously um
  1514. 52:22expressed uh you know feelings that it
  1515. 52:24was biased
  1516. 52:26in ways that reinforce racism and sexism
  1517. 52:28uh and in 2020 these twitter users had
  1518. 52:31performed a participatory audit sharing
  1519. 52:34screenshots of image crop fails
  1520. 52:36on the social media platform
  1521. 52:38which you can sort of see
  1522. 52:40here in the before picture
  1523. 52:43in-house researchers from twitter later
  1524. 52:45published research confirming these
  1525. 52:46users findings and through the defcon
  1526. 52:48challenge twitter offered an opportunity
  1527. 52:50for third-party researchers to again
  1528. 52:52come in and scrutinize this model
  1529. 52:54this time with bounties for the top
  1530. 52:56three submissions
  1531. 52:58and at the same time the company also
  1532. 52:59produced a scoring rubric for
  1533. 53:01algorithmic bias and harms
  1534. 53:04um next slide please uh we were thrilled
  1535. 53:07at ajl to see this happen and we think
  1536. 53:09that twitter did a lot of things right
  1537. 53:11uh in setting up this bounty we also
  1538. 53:13think that this case study though
  1539. 53:14illustrates the difficulty of applying
  1540. 53:16bug bounties um to the problem of
  1541. 53:18algorithmic harms for example their
  1542. 53:21scoring rubric gave more points for
  1543. 53:23problems that affected um the most
  1544. 53:25people even though that implies
  1545. 53:27de-prioritizing
  1546. 53:28small groups of people who are at risk
  1547. 53:30of suffering some of the worst kinds of
  1548. 53:32algorithmic harm um twitter didn't
  1549. 53:34provide any scores publicly so it's hard
  1550. 53:36to assess how sort of useful the rubric
  1551. 53:38was in practice
  1552. 53:40but we're sort of really excited to see
  1553. 53:42where that kind of of framework um can
  1554. 53:44go from here uh in addition while it's
  1555. 53:47you know great to see these kinds of
  1556. 53:49programs emerging in response to
  1557. 53:50controversies in all the cases that we
  1558. 53:53looked at
  1559. 53:54um of these sort of more uh
  1560. 53:57socio-technical bounties so google
  1561. 53:59facebook and twitter you know the
  1562. 54:00original reporters of the issues that
  1563. 54:02precipitated uh the emergence of these
  1564. 54:04bounties who first put in the work to
  1565. 54:06document and expose the harms aren't
  1566. 54:09ultimately rewarded uh aren't under
  1567. 54:11these programs um but on the other hand
  1568. 54:14you know there's an important change
  1569. 54:16management lesson here
  1570. 54:18um and in particular for those of you
  1571. 54:20who sort of work in this space and how
  1572. 54:22to how to you know make progress uh
  1573. 54:25under difficult internal conditions
  1574. 54:27um twitter saw an opportunity where the
  1575. 54:29stars were aligned in favor of doing
  1576. 54:31something novel
  1577. 54:33um and in our interviews we heard again
  1578. 54:35and again the importance of finding the
  1579. 54:36right pilot um to sort of get the ball
  1580. 54:39moving forward for instance with the
  1581. 54:41hack the pentagon program we heard from
  1582. 54:42lisa wiswell about how critical the
  1583. 54:45pilot was in ultimately motivating the
  1584. 54:47proliferation of these programs across
  1585. 54:49different government agencies
  1586. 54:51and we think several factors here were
  1587. 54:52key to minimizing the risk to the
  1588. 54:54company and therefore willingness to
  1589. 54:56sort of undertake this this pretty uh
  1590. 54:58novel approach so first the sort of
  1591. 55:01harms from the image cropping algorithm
  1592. 55:03had already been exposed by users so the
  1593. 55:05reputational damage had already been
  1594. 55:07incurred by the company
  1595. 55:08second twitter had already published an
  1596. 55:10examination of the model's flaws and was
  1597. 55:13already decommissioning the algorithm
  1598. 55:16mitigating further risk of public
  1599. 55:17criticism
  1600. 55:19and third the cropping algorithm itself
  1601. 55:21was open source rather than proprietary
  1602. 55:23so even by opening it up uh they weren't
  1603. 55:26exposing any uh ip
  1604. 55:29and you can see here as well on the
  1605. 55:30screen the sort of configuration of the
  1606. 55:32program and it's quite unusual and again
  1607. 55:33happy to sort of come back around to
  1608. 55:35that in in the q a um but with that uh
  1609. 55:38back over to cam
  1610. 55:41all right thanks for watching the next
  1611. 55:43one
  1612. 55:43next play yes let's pivot to um who else
  1613. 55:47could use bounties for algorithmic harms
  1614. 55:50so this last vignette we wanted to spend
  1615. 55:52a little bit of time on what happened
  1616. 55:53during the pandemic where many school
  1617. 55:56many universities switched very rapidly
  1618. 55:58to remote learning we know
  1619. 56:01as educators as students how
  1620. 56:03difficult this was for everybody
  1621. 56:05involved and as part of this transition
  1622. 56:07we also saw the rapid adoption of
  1623. 56:10e-proctoring systems to monitor students
  1624. 56:13remotely
  1625. 56:14now there are a lot of known and
  1626. 56:16documented problems with the systems for
  1627. 56:18instance a lot of them use facial
  1628. 56:21recognition technologies that perform
  1629. 56:23less well on students with darker skin
  1630. 56:25to the research that josh initially
  1631. 56:28mentioned that joy for instance and her
  1632. 56:30colleagues have published years ago that
  1633. 56:33part is well documented
  1634. 56:35we've also seen at least one researcher
  1635. 56:37ex-librium on their blog proctor ninja
  1636. 56:40reverse engineer the widely used remote
  1637. 56:43proctoring system proctorio to find that
  1638. 56:47proctor io was using a facial
  1639. 56:49recognition training library not meant
  1640. 56:51for production environment and known to
  1641. 56:54perform poorly on darker skin
  1642. 56:56so people who are subject to these
  1643. 56:57technologies have been speaking up like
  1644. 57:00the students activists at encode justice
  1645. 57:02and they have been turning to both uh
  1646. 57:05participatory audits online to say look
  1647. 57:08this is what i'm seeing on my screen are
  1648. 57:10you seeing the same i think this is a
  1649. 57:11problem and two more traditional reverse
  1650. 57:14engineering techniques to go and
  1651. 57:16document where those problems are coming
  1652. 57:17from so if we take a step back again to
  1653. 57:21the
  1654. 57:22history of book boundaries that we
  1655. 57:24looked at the other thing that really
  1656. 57:26stayed with us is that the few attempts
  1657. 57:28at truly adversarial programs did not
  1658. 57:32last very long or did not succeed widely
  1659. 57:35there's a notable exception for programs
  1660. 57:38who are vulnerability disclosure
  1661. 57:40programs that live within large and
  1662. 57:42well-funded corporations for instance
  1663. 57:44project zero at google but beside these
  1664. 57:47this idea of adversarial bounties in a
  1665. 57:50way or another form have not really find
  1666. 57:53their final form so at agl
  1667. 57:56we were left with a simple idea
  1668. 57:59josh over to you
  1669. 58:01that simple idea is adversarial bounties
  1670. 58:04for algorithmic harms
  1671. 58:07and these might be configured we thought
  1672. 58:09in the following way with adversarial
  1673. 58:11reporting and clues in the name
  1674. 58:14compensation bounties although certainly
  1675. 58:16cognizant that there are
  1676. 58:18um situations in which other forms of
  1677. 58:21compensation
  1678. 58:22would be more appropriate depending on
  1679. 58:24the nature of the work
  1680. 58:26delayed full disclosure to ensure
  1681. 58:28transparency and and drive
  1682. 58:29accountability public participation to
  1683. 58:32allow folks from
  1684. 58:34different uh communities different
  1685. 58:36research backgrounds uh and and
  1686. 58:38including sort of impacted folks to
  1687. 58:41um to sort of participate to contribute
  1688. 58:44and to provide their um their their
  1689. 58:46their forms of expertise um program
  1690. 58:49management would be third party as in a
  1691. 58:51platform but not uh we think a platform
  1692. 58:54uh like
  1693. 58:56hacker one or bug crowd or yes we hack
  1694. 58:59um that is you know for its business
  1695. 59:00model dependent on
  1696. 59:03the custom of target organizations uh
  1697. 59:06rather this would be an independent
  1698. 59:07third-party platform
  1699. 59:09and the thought initially is you know
  1700. 59:11perhaps time limited focused on
  1701. 59:13particular sectors or spaces or problems
  1702. 59:15would help to sort of
  1703. 59:17you know
  1704. 59:18scope this to be feasible and and and to
  1705. 59:21sort of
  1706. 59:31really drive attention towards but also
  1707. 59:34uh you know being adversarial um in
  1708. 59:37nature uh you're not going to have
  1709. 59:38access to the sort of full inner
  1710. 59:40workings of the systems under scrutiny
  1711. 59:42or the organizations that produce those
  1712. 59:44systems so if something like this sounds
  1713. 59:46exciting to you and you're interested in
  1714. 59:48participating
  1715. 59:50we invite you to sign up for ajl's
  1716. 59:52mailing list
  1717. 59:53if you have ideas for targets of
  1718. 59:55adversarial algorithmic harm bug
  1719. 59:56bounties please let us know
  1720. 59:58if you run your own adversarial
  1721. 1:00:00algorithmic harm bounty and we've missed
  1722. 1:00:02it uh we'd love to hear about it um and
  1723. 1:00:06i think we can move to the last slide
  1724. 1:00:07just to you know point you all towards
  1725. 1:00:09our report one more time it's at ajl.org
  1726. 1:00:13bugs there's design lessons in there
  1727. 1:00:16there's case study on the twitter
  1728. 1:00:17program all sorts so thanks and with
  1729. 1:00:19that i think we can go back over to matt
  1730. 1:00:21and open up the q a
  1731. 1:00:24wonderful thank you everyone um i've
  1732. 1:00:28learned i've read the reports and i'm
  1733. 1:00:30still learning from from hearing all
  1734. 1:00:32that
  1735. 1:00:33at the process um so i've got like a
  1736. 1:00:36stack of questions about an inch thick
  1737. 1:00:38and i don't know which ones to ask first
  1738. 1:00:41frankly but
  1739. 1:00:43one of the things that i'm immediately
  1740. 1:00:45thinking about on the heels of that kind
  1741. 1:00:46of lines up with some of the questions
  1742. 1:00:48we're already seeing in the chat so
  1743. 1:00:50maybe it's uh maybe it'll be interesting
  1744. 1:00:52to dig into that
  1745. 1:00:53um but
  1746. 1:00:55before before i get before i do that
  1747. 1:00:58there's this one like really point blank
  1748. 1:00:59question i want to ask all of you which
  1749. 1:01:01is
  1750. 1:01:02who needs to read these reports and what
  1751. 1:01:05should they do when they read them i
  1752. 1:01:06mean that's a hard question but i think
  1753. 1:01:09you know any any slice of that you can
  1754. 1:01:11take on i would love to hear it you know
  1755. 1:01:17i'm happy to go first i mean i think one
  1756. 1:01:20place i would love the report to get
  1757. 1:01:22read is for the folks running bounty
  1758. 1:01:23programs generally so that would be
  1759. 1:01:24hacker one bug crowd and also folks who
  1760. 1:01:27are interested in setting up their own
  1761. 1:01:28bounty programs i know
  1762. 1:01:30every day it seems like there's a new
  1763. 1:01:31bounty program that spins out from you
  1764. 1:01:33know public sector to private sector to
  1765. 1:01:36universities
  1766. 1:01:37and i think just like a pause and
  1767. 1:01:38thinking about some of the
  1768. 1:01:39recommendations that we make at the end
  1769. 1:01:41of our report
  1770. 1:01:42would be so helpful so that's that's one
  1771. 1:01:44place where i certainly hope it could
  1772. 1:01:45get read
  1773. 1:01:48yeah to add to that i think that i know
  1774. 1:01:49that the
  1775. 1:01:50federal trade commission in the us has
  1776. 1:01:53actually been trying to crack down on
  1777. 1:01:54the differences between the uh
  1778. 1:01:57remuneration that is promised by
  1779. 1:01:59platforms and then the remuneration that
  1780. 1:02:01people receive
  1781. 1:02:02i can imagine that it would be of great
  1782. 1:02:04interest
  1783. 1:02:05to the federal trade commission to
  1784. 1:02:08identify
  1785. 1:02:09um another
  1786. 1:02:11place and opportunity
  1787. 1:02:12in which uh workers
  1788. 1:02:15are being treated differently than they
  1789. 1:02:16are then you know they're then
  1790. 1:02:19in terms of the promises that are being
  1791. 1:02:20given to them i would want lawmakers to
  1792. 1:02:23read our report too because
  1793. 1:02:25uh both in terms of
  1794. 1:02:27workers who are in need of protection
  1795. 1:02:28but also because of the legal risks that
  1796. 1:02:30hackers do face particularly the u.s
  1797. 1:02:33and because many of the companies that
  1798. 1:02:34they hack on would be in the us and
  1799. 1:02:35indeed do pay for bug bounty programs i
  1800. 1:02:37want lawmakers to better protect hackers
  1801. 1:02:40as workers as hackers and um and also to
  1802. 1:02:43address one point you know that ryan has
  1803. 1:02:46made a few times which i love is that
  1804. 1:02:47what do we do if bug money platforms
  1805. 1:02:49like hacker one and bug crowd leave and
  1806. 1:02:52and and
  1807. 1:02:53they run out of funding in an entire
  1808. 1:02:56swath of the industry and different
  1809. 1:02:58industries are relying on these programs
  1810. 1:02:59i think that
  1811. 1:03:01you know alternatives are needed so that
  1812. 1:03:02we don't rely on these companies to
  1813. 1:03:04provide such important infrastructure
  1814. 1:03:06and work regarding security
  1815. 1:03:09i'll take a last pivot from here and say
  1816. 1:03:11that on our end we we wrote it for a
  1817. 1:03:14wide variety of of audience researchers
  1818. 1:03:17to practitioners we try to summarize
  1819. 1:03:19some practical lessons in a design
  1820. 1:03:21companion but there are two audiences
  1821. 1:03:23that we had in mind particularly the
  1822. 1:03:25first one is um public interest
  1823. 1:03:27technologists and and civil society
  1824. 1:03:30organizations for them to look at these
  1825. 1:03:32uh programs as potential ways to
  1826. 1:03:35continue this this work of uh uh you
  1827. 1:03:38know founding algorithmic harms and the
  1828. 1:03:40second one is
  1829. 1:03:41it's it's apparent in the history of bug
  1830. 1:03:43bounties that public institutions have
  1831. 1:03:45also played an interesting role in
  1832. 1:03:48putting out these programs and shaping
  1833. 1:03:49the norms around how they're run and
  1834. 1:03:51we're interested in seeing if some
  1835. 1:03:54relevant government agencies would also
  1836. 1:03:56consider adversarial bounties for
  1837. 1:03:59algorithmic harms
  1838. 1:04:04josh did you want to add anything or do
  1839. 1:04:05you think that uh
  1840. 1:04:07can i get something evident
  1841. 1:04:09all right
  1842. 1:04:10so there's been a couple questions in
  1843. 1:04:12the chat um kind of honing in on
  1844. 1:04:16the difference between bug bounty
  1845. 1:04:18programs and hackathons
  1846. 1:04:20and
  1847. 1:04:20generally the the con the idea of like
  1848. 1:04:23community building in these programs
  1849. 1:04:25and one of the things i find super
  1850. 1:04:27interesting um
  1851. 1:04:29was the discussion of
  1852. 1:04:31um
  1853. 1:04:32[Music]
  1854. 1:04:33kind of like public explorations of
  1855. 1:04:36algorithmic
  1856. 1:04:38vulnerabilities or biases on twitter and
  1857. 1:04:40that was something that you know people
  1858. 1:04:42kind of
  1859. 1:04:44did or and organized on their own
  1860. 1:04:46and then
  1861. 1:04:47twitter kind of took the took the ball
  1862. 1:04:50running from that and
  1863. 1:04:52uh you know
  1864. 1:04:53uh hosts the def con event
  1865. 1:04:55but one of the things you know um
  1866. 1:04:58that the bounty everything report talks
  1867. 1:05:00about is how the the early you know
  1868. 1:05:03netscape
  1869. 1:05:05bugs bounty program
  1870. 1:05:06uh was very much like an attempt to kind
  1871. 1:05:09of control the narrative and
  1872. 1:05:11and co-op
  1873. 1:05:12you know co-op things i think you know
  1874. 1:05:14the the report
  1875. 1:05:16the language it uses is you know to
  1876. 1:05:18blunt negative attention
  1877. 1:05:20and and kind of
  1878. 1:05:21enclose the this this market so that it
  1879. 1:05:24could be controlled right so are there
  1880. 1:05:26are there in your
  1881. 1:05:29reports did you find like is there some
  1882. 1:05:32type of balance between companies that
  1883. 1:05:34are able to like take this information
  1884. 1:05:36from bounties
  1885. 1:05:38programs running them versus the value
  1886. 1:05:40of people doing it from the outside in
  1887. 1:05:42kind of an uncontrolled way and being
  1888. 1:05:45able to demand accountability in a
  1889. 1:05:46public way
  1890. 1:05:48what is like is there a proper balance
  1891. 1:05:50between that or
  1892. 1:05:51do are both needed or is there is it
  1893. 1:05:53possible to have a bounty program that
  1894. 1:05:56can really build that kind of community
  1895. 1:05:57and
  1896. 1:05:58uh and also serve that function if if i
  1897. 1:06:01ask the question well
  1898. 1:06:05i have some thoughts and i might even
  1899. 1:06:07answer another question while providing
  1900. 1:06:08these thoughts but someone has asked for
  1901. 1:06:10our take on federal vulnerability
  1902. 1:06:11disclosure policies and publicly funded
  1903. 1:06:13bug money programs and i have done a
  1904. 1:06:16work that looks at the canadian
  1905. 1:06:17government's use of vulnerability
  1906. 1:06:19disclosure programs which is we
  1907. 1:06:21highlighted are bug money programs minus
  1908. 1:06:24money
  1909. 1:06:24and
  1910. 1:06:26i think it is possible to have bug
  1911. 1:06:29let's say vulnerability disclosure
  1912. 1:06:30programs where people aren't paid
  1913. 1:06:32and what that means is that
  1914. 1:06:36there could be a sense of unfairness
  1915. 1:06:37because you're not getting compensated
  1916. 1:06:38for your labor but by paying people for
  1917. 1:06:41bug bounties
  1918. 1:06:42that is bugs and bug reports they submit
  1919. 1:06:45then that means that you're creating a
  1920. 1:06:47market and you're turning a person into
  1921. 1:06:49a laborer i think that there is a time
  1922. 1:06:52and a place for not paying people
  1923. 1:06:53because
  1924. 1:06:54particularly from a
  1925. 1:06:56state and government perspective to pay
  1926. 1:06:58people would be to turn the thing you're
  1927. 1:07:01paying for into a type of market
  1928. 1:07:03um so i i think that there is a lot of
  1929. 1:07:06value actually in in
  1930. 1:07:08vulnerability disclosure programs that
  1931. 1:07:10are run by governments where they pay
  1932. 1:07:11people in things like swag or they just
  1933. 1:07:14they say they pay you in in recognition
  1934. 1:07:17and i it's hard to answer because you
  1935. 1:07:19want to also respect the commander the
  1936. 1:07:21hacker demand for payment as i did in
  1937. 1:07:25kansas west but i also think that there
  1938. 1:07:27is benefit in having programs um where
  1939. 1:07:29you don't almost taint the relationship
  1940. 1:07:31with money by turning things into a
  1941. 1:07:33market
  1942. 1:07:40did anyone else want to jump in on that
  1943. 1:07:42right yeah sure i think um
  1944. 1:07:45i got your question like is there a
  1945. 1:07:46right balance between community building
  1946. 1:07:49transparency like that's such an
  1947. 1:07:50important question i saw it pop up in
  1948. 1:07:52the chat as well
  1949. 1:07:53people really enjoy working in this
  1950. 1:07:55market right it's a thrill they find
  1951. 1:07:57friends they find meaning in their work
  1952. 1:07:59and so those things are important to
  1953. 1:08:00acknowledge and not discount one of the
  1954. 1:08:02tricky things though is how
  1955. 1:08:04the desire to be part of that community
  1956. 1:08:06can be sort of turned on its head and so
  1957. 1:08:08getting access to that community whether
  1958. 1:08:09it be invited to private programs or
  1959. 1:08:11invited to like lavishly funded live
  1960. 1:08:14hackathons and live events in las vegas
  1961. 1:08:17that are sponsored by platforms and
  1962. 1:08:18companies
  1963. 1:08:20the desire to do that then drives
  1964. 1:08:21engagement and it pushes often
  1965. 1:08:23uncompensated work and so it really is
  1966. 1:08:25like a double-edged sword i think the
  1967. 1:08:27trick that like gig work always is is
  1968. 1:08:29that it sets people with different
  1969. 1:08:30motivations
  1970. 1:08:32into a pool and pushes them against each
  1971. 1:08:33other in some ways whether they want to
  1972. 1:08:35be pushed against each other or set
  1973. 1:08:36against each other or not it's the idea
  1974. 1:08:38you have people here who consider bounty
  1975. 1:08:39programs as beer money versus people who
  1976. 1:08:42see it as their way to a career and or
  1977. 1:08:44even their full-time job it creates
  1978. 1:08:46these really strange and difficult
  1979. 1:08:47dynamics that can make the sustaining of
  1980. 1:08:49a community very difficult and so that's
  1981. 1:08:51one of the things that i report try to
  1982. 1:08:52get out is not to dismiss the fact that
  1983. 1:08:55people find pleasure and community and
  1984. 1:08:56friendship and engagement in these
  1985. 1:08:58things they do but showing how it gets
  1986. 1:09:00complicated when it's mixed in with
  1987. 1:09:01these other dynamics
  1988. 1:09:04and i will say we have in the q a a
  1989. 1:09:07wonderful question by uh one of our
  1990. 1:09:10co-authors uh sasha who i think is here
  1991. 1:09:13with us and sasha is pointing at some of
  1992. 1:09:16the issues with disclosure too right so
  1993. 1:09:19how can we help mandate more systematic
  1994. 1:09:22disclosure and uh you know collectively
  1995. 1:09:25i think all of our report acknowledged a
  1996. 1:09:27difficult relationship between the
  1997. 1:09:29bounty programs and disclosure where a
  1998. 1:09:32lot of the by default settings is to
  1999. 1:09:35prevent the disclosure of the flaws and
  2000. 1:09:38vulnerabilities that are found so i'm uh
  2001. 1:09:41highlighting this question by by sasha
  2002. 1:09:44and and if you allow me to do that
  2003. 1:09:46getting it back on the on the stage
  2004. 1:09:55one thing that's really interesting and
  2005. 1:09:57that's a to follow up on that is the
  2006. 1:09:58question of like
  2007. 1:10:01when bug bounty programs like go wrong
  2008. 1:10:03and how they can be used to catch and
  2009. 1:10:05kill right so we have examples on our
  2010. 1:10:07report about uber which i think is a
  2011. 1:10:08very well known story now where the cso
  2012. 1:10:10was brought up on federal charges
  2013. 1:10:12because they essentially tried to cover
  2014. 1:10:13up a data breach through their bug
  2015. 1:10:14bounty program like don't do that that's
  2016. 1:10:16not what bug bounty programs are
  2017. 1:10:17supposed to be for we also have stories
  2018. 1:10:19from john deere and others that are
  2019. 1:10:20trying to use their bug bounty program
  2020. 1:10:21as catch and kill so the question here
  2021. 1:10:23about
  2022. 1:10:24how we think about disclosure and how do
  2023. 1:10:26you create a world where bug bounty
  2024. 1:10:28programs can be used to help get flaws
  2025. 1:10:30out in the world rather than to cover
  2026. 1:10:32them up is so important
  2027. 1:10:34and it's tricky it's difficult i mean i
  2028. 1:10:36think the federal case around uber is
  2029. 1:10:38going to make people very nervous
  2030. 1:10:40but the other thing that we can do
  2031. 1:10:43is hackers have power here they have
  2032. 1:10:44real power by which programs they decide
  2033. 1:10:46to participate in and looking at the
  2034. 1:10:48terms of service and picking and
  2035. 1:10:50choosing based on those that allow for
  2036. 1:10:51disclosure versus those that are going
  2037. 1:10:53to require ndas and so the hackers
  2038. 1:10:55themselves have maybe sometimes more
  2039. 1:10:57power than they might realize
  2040. 1:10:59one of the things that we try to
  2041. 1:11:00emphasize is that this work is very
  2042. 1:11:02difficult you hear these like eye
  2043. 1:11:03popping numbers that there's tens or
  2044. 1:11:05hundreds of thousands of people signed
  2045. 1:11:06up to participate in bug bounty programs
  2046. 1:11:08which is true but there's a much smaller
  2047. 1:11:11group of people who are incredibly
  2048. 1:11:13effective and successful and they have
  2049. 1:11:16real power to shape how this market
  2050. 1:11:17works as well if they are willing to
  2051. 1:11:19take it if they're willing to make those
  2052. 1:11:20choices and make those choices publicly
  2053. 1:11:22so i think that's one way in which we
  2054. 1:11:24can push for
  2055. 1:11:25um maybe not regulators themselves
  2056. 1:11:27pushing for it but the hackers and
  2057. 1:11:28participants themselves can help be sort
  2058. 1:11:30of that forcing function around
  2059. 1:11:31disclosure
  2060. 1:11:34i mean that leads nicely into one of the
  2061. 1:11:35things that we were sort of thinking
  2062. 1:11:36about in the context of how to make
  2063. 1:11:38adversarial programs work a little bit
  2064. 1:11:41better than they have historically which
  2065. 1:11:42is
  2066. 1:11:44you know these
  2067. 1:11:46barriers
  2068. 1:11:48of varying
  2069. 1:11:50um firmness
  2070. 1:11:52these sort of legal threats
  2071. 1:11:54uh that exist
  2072. 1:11:56to disclosure
  2073. 1:11:57um and that whether they are
  2074. 1:12:00you know whether they are realistic in
  2075. 1:12:02terms of the hacker will end up
  2076. 1:12:04incarcerated or whether they are just a
  2077. 1:12:07a looming threat
  2078. 1:12:09um i think it's been pretty well
  2079. 1:12:10documented at this point that both of
  2080. 1:12:12those create a chilling effect uh on
  2081. 1:12:14what people research and what happens to
  2082. 1:12:17that research when they find things and
  2083. 1:12:19so this is this is one of the key points
  2084. 1:12:21that we want to sort of put out there in
  2085. 1:12:23the world with respect to potential you
  2086. 1:12:25know um sort of adversarial platform
  2087. 1:12:27successors to the likes of of we own
  2088. 1:12:30token bug bounty is is we need to have
  2089. 1:12:33support in place um that can't be just
  2090. 1:12:36reliance on legal safe harbor because
  2091. 1:12:38that's not going to be offered by
  2092. 1:12:39organizations who don't want to have uh
  2093. 1:12:42the flaws uh in and about their systems
  2094. 1:12:45exposed um they're not going to offer
  2095. 1:12:47that and so what are the alternatives
  2096. 1:12:48that are out there sure there are some
  2097. 1:12:50uh you know whether it's juan
  2098. 1:12:53spoke earlier about you know
  2099. 1:12:54prosecutorial guidance to sort of take
  2100. 1:12:56away
  2101. 1:12:57that particular threat in places where
  2102. 1:12:59that can be feasibly achieved and where
  2103. 1:13:01uh governments understand these issues
  2104. 1:13:03well but then there's also just a lot uh
  2105. 1:13:06of potential benefit i think to be
  2106. 1:13:08gained by having intermediating
  2107. 1:13:10organizations that can say we have your
  2108. 1:13:12back
  2109. 1:13:12uh whether it's resourcing whether it's
  2110. 1:13:15legal guidance that's provided ahead of
  2111. 1:13:17time
  2112. 1:13:18level setting on the playing field of
  2113. 1:13:20what they are going to have your back on
  2114. 1:13:23um can can probably go quite a long way
  2115. 1:13:26i mean if legal safe harbor can solve as
  2116. 1:13:28many problems as it has in the bug
  2117. 1:13:29bounty space
  2118. 1:13:30then presumably having a well-resourced
  2119. 1:13:32intermediary that truly does have the
  2120. 1:13:34back of the people doing the scrutiny um
  2121. 1:13:36could could could support as well
  2122. 1:13:39um that's obviously not going to get off
  2123. 1:13:41to all of the challenges of of sort of
  2124. 1:13:44um cutting out some of the misaligned
  2125. 1:13:46incentives that exist in this ecosystem
  2126. 1:13:48right now
  2127. 1:13:49um but it would certainly help address
  2128. 1:13:51some of the sort of knock-on effects
  2129. 1:13:54i don't know if any others have thoughts
  2130. 1:13:56on that
  2131. 1:14:00maybe i can add a thought that um uh
  2132. 1:14:03i've been thinking you know it's a bit
  2133. 1:14:04in my head for a while um back before
  2134. 1:14:07ryan and i were writing on the poor but
  2135. 1:14:09we're doing the research we had this um
  2136. 1:14:12event that day in society um where we
  2137. 1:14:14had feedback on on
  2138. 1:14:16on the work we were doing thus far matt
  2139. 1:14:17was there um other people i i as well
  2140. 1:14:20who works at the society and she
  2141. 1:14:22actually pointed out that there is that
  2142. 1:14:24she saw similarities between hackers and
  2143. 1:14:26screenwriters and she said you know you
  2144. 1:14:28might want to look into screenwrite
  2145. 1:14:30writer's guilds and writer's guilds and
  2146. 1:14:32i actually haven't looked into that
  2147. 1:14:33unfortunately but i think there's a lot
  2148. 1:14:35there and i say that for two reasons the
  2149. 1:14:37first is that um there's this notion of
  2150. 1:14:39labor where you're doing labor it feels
  2151. 1:14:41it feels like play um and there and i
  2152. 1:14:44actually think of hacking as a creative
  2153. 1:14:45field um where you are very creative in
  2154. 1:14:48your work often and you produce outputs
  2155. 1:14:51like much like you would when you are
  2156. 1:14:53creating film or tv
  2157. 1:14:55and what what i can see is that the
  2158. 1:14:57screenwriters guild emerged and it acts
  2159. 1:14:59as a sort of union and it protects many
  2160. 1:15:01many workers and so there is a question
  2161. 1:15:03here about what are recommendations for
  2162. 1:15:05hackers and i think that
  2163. 1:15:06it would be amazing if groups of hackers
  2164. 1:15:09had you know formed
  2165. 1:15:11unions and and
  2166. 1:15:13guilds that would protect them as
  2167. 1:15:15workers and i would advocate for
  2168. 1:15:17them to receive certain compensation or
  2169. 1:15:20to be acknowledged in certain ways and i
  2170. 1:15:21think that that movement would be really
  2171. 1:15:23needed and would be really beneficial
  2172. 1:15:26for protecting the rights of hackers as
  2173. 1:15:27hackers and as workers
  2174. 1:15:35okay
  2175. 1:15:36that leads me to uh something i was
  2176. 1:15:39thinking about like one of the
  2177. 1:15:42really top-line recommendations of the
  2178. 1:15:44agl report in particular is
  2179. 1:15:47the need especially as we move into
  2180. 1:15:51the idea of bounties for
  2181. 1:15:53algorithmic harms or social technical
  2182. 1:15:55harms
  2183. 1:15:55of
  2184. 1:15:56increasing the diversity in the pool of
  2185. 1:15:59the people who are actually
  2186. 1:16:01participating in these programs so that
  2187. 1:16:03they can surface
  2188. 1:16:04harms that might be visible to them from
  2189. 1:16:06their subject position that might not be
  2190. 1:16:08visible to others or others might not
  2191. 1:16:10even think to look at
  2192. 1:16:11um but it seems to me like is there is
  2193. 1:16:13there a bit of a wicked problem between
  2194. 1:16:15that kind of imperative and also the
  2195. 1:16:18imperative to
  2196. 1:16:19improve job security and pathways to
  2197. 1:16:22secure employment for the existing pool
  2198. 1:16:25of laborers i mean there's got to be
  2199. 1:16:26some way to balance that kind of tension
  2200. 1:16:29of wanting to draw in as much as many
  2201. 1:16:31people from as many diverse perspectives
  2202. 1:16:33with as many skill sets as possible and
  2203. 1:16:35also make sure that these people are not
  2204. 1:16:37not being treated to the worst effects
  2205. 1:16:39of casualized labor
  2206. 1:16:41um
  2207. 1:16:42and i guess that gets back to some
  2208. 1:16:44extent to the idea of how people who are
  2209. 1:16:47voluntarily doing this as communities
  2210. 1:16:49aren't necessarily expecting to be
  2211. 1:16:50rewarded but they should be as well so
  2212. 1:16:52i'm just curious if if you have thoughts
  2213. 1:16:54on that it's a very hard problem i'm
  2214. 1:16:55sorry to to put it out there but
  2215. 1:16:58if anyone knows hopefully it's you guys
  2216. 1:17:06i mean i can i can i can sort of
  2217. 1:17:07speculate i think
  2218. 1:17:09you are right it is a it is a wicked
  2219. 1:17:11problem
  2220. 1:17:12and
  2221. 1:17:15if we look across
  2222. 1:17:16our technology ecosystem more broadly
  2223. 1:17:19right now
  2224. 1:17:20um
  2225. 1:17:22the challenges of of building diverse
  2226. 1:17:25inclusive communities absolutely with
  2227. 1:17:27respect to background um
  2228. 1:17:31but also with respect to sort of you
  2229. 1:17:33know professional expertise research
  2230. 1:17:36interests and methods and so on like
  2231. 1:17:38this is not something that we have
  2232. 1:17:41got answers to today i do think there
  2233. 1:17:43are places um
  2234. 1:17:44you know that are looking at how to do
  2235. 1:17:46this
  2236. 1:17:47uh
  2237. 1:17:48and and and making progress
  2238. 1:17:50my
  2239. 1:17:51um sense based on our research is that
  2240. 1:17:56there's not going to be a sort of
  2241. 1:17:58one-size-fits-all solution with respect
  2242. 1:18:01to sort of the institutions that can
  2243. 1:18:02facilitate community building let alone
  2244. 1:18:05the programs that those um institutions
  2245. 1:18:08might offer to
  2246. 1:18:10um attract in participants to protect
  2247. 1:18:14them in the various ways they need to be
  2248. 1:18:15protected and to compensate them where
  2249. 1:18:17they are producing
  2250. 1:18:19something of value
  2251. 1:18:22but the question of who gets to
  2252. 1:18:23determine what is valuable and what um
  2253. 1:18:27kinds of work and contributions deserve
  2254. 1:18:29to be compensated i mean this ties into
  2255. 1:18:32what are your templates what are your
  2256. 1:18:34impact scoring frameworks who
  2257. 1:18:35contributed to
  2258. 1:18:37um to building those the idea that sort
  2259. 1:18:40of certain work has value in this space
  2260. 1:18:42and and others that's a political
  2261. 1:18:44question and it's a social question a
  2262. 1:18:45cultural question and so you know you
  2263. 1:18:48sort of have to have
  2264. 1:18:49i think an open-mindedness to
  2265. 1:18:52um to to to work out what salute you
  2266. 1:18:55know to trial and error to work with
  2267. 1:18:58stakeholders and communities to figure
  2268. 1:18:59out what solutions are going to work for
  2269. 1:19:01them best and and the idea that we're
  2270. 1:19:02going to come in and a panel today and
  2271. 1:19:04be like yes if you do xyz you will have
  2272. 1:19:06a diverse community of practitioners on
  2273. 1:19:08your platform no
  2274. 1:19:10you're right we're not um and and that's
  2275. 1:19:12okay
  2276. 1:19:18thanks did anyone else want to wait on
  2277. 1:19:20that or should we move on to a lighter
  2278. 1:19:23lighter
  2279. 1:19:26affair okay
  2280. 1:19:28um
  2281. 1:19:29so that also that uh
  2282. 1:19:32touches on a couple other directions we
  2283. 1:19:34can take this one is exploring the
  2284. 1:19:36idea of the security development life
  2285. 1:19:38cycle a little bit more
  2286. 1:19:40and
  2287. 1:19:41one is exploring the kind of role that
  2288. 1:19:44these kind of existing institutions in
  2289. 1:19:46the bug county
  2290. 1:19:48space place so let's see maybe i'll go
  2291. 1:19:50with the latter one first so as as
  2292. 1:19:53josh's answer kind of just suggests like
  2293. 1:19:56some of these existing big players in
  2294. 1:19:59the you know bug bounty
  2295. 1:20:01infosec space are starting to also
  2296. 1:20:04move into
  2297. 1:20:06you know providing
  2298. 1:20:07their existing infrastructure platform
  2299. 1:20:10for
  2300. 1:20:10more algorithmic harm type issues
  2301. 1:20:13um
  2302. 1:20:14is there what are the kind of you know
  2303. 1:20:17pros and cons of seeing that happen
  2304. 1:20:20versus
  2305. 1:20:22having you know new organizations kind
  2306. 1:20:24of come up and try to try to start you
  2307. 1:20:26know develop
  2308. 1:20:27protocols for these types of bug many
  2309. 1:20:29programs from scratch suited to you know
  2310. 1:20:32algorithmic carbs in particular
  2311. 1:20:37yeah that's a great question matt i'm
  2312. 1:20:38going to try not to answer we wrote 100
  2313. 1:20:40pages about this
  2314. 1:20:42but it was sort of one of the key
  2315. 1:20:44questions which is you know what does it
  2316. 1:20:46take to meaningfully take those programs
  2317. 1:20:48and stretch them to those
  2318. 1:20:49socio-technical issues to your question
  2319. 1:20:52on like things that immediately come to
  2320. 1:20:53mind as trade-offs when you use
  2321. 1:20:56platforms who've been managing programs
  2322. 1:20:58for a long time like they can accompany
  2323. 1:21:01those you know those those companies and
  2324. 1:21:03like how do you do triage how do you
  2325. 1:21:05develop an impact scoring uh how do you
  2326. 1:21:08make sure that you recruit for your
  2327. 1:21:10program how do you pay people and so
  2328. 1:21:12they make that transition uh much easier
  2329. 1:21:16now
  2330. 1:21:17the other thing of course that comes
  2331. 1:21:18with that is you know you also don't
  2332. 1:21:21have adversarial programs by definition
  2333. 1:21:23here you have programs that are hosted
  2334. 1:21:26on platforms by targets who have agreed
  2335. 1:21:29and who are participating and as a
  2336. 1:21:32result you're also targeting
  2337. 1:21:34the um sort of existing community of
  2338. 1:21:37people who participate in these
  2339. 1:21:39platforms and we can talk a little bit
  2340. 1:21:41more uh there was an interesting uh you
  2341. 1:21:43know set of questions in the chat about
  2342. 1:21:45the lack of diversity uh of the current
  2343. 1:21:48communities who most often engage with
  2344. 1:21:50these types of programs so again if we
  2345. 1:21:52go through all of our our libraries we
  2346. 1:21:54can um we can spend quite a bit of time
  2347. 1:21:57trying to figure out like all right is
  2348. 1:21:58this a good first step right like we
  2349. 1:22:00definitely think that it is we think
  2350. 1:22:02it's important to have these programs
  2351. 1:22:04we're grateful that we have a little bit
  2352. 1:22:05of transparency of course as researchers
  2353. 1:22:08we always want more transparency i think
  2354. 1:22:10josh said it we really wanted to see how
  2355. 1:22:12those uh scoring framework had been
  2356. 1:22:15applied to the different submissions so
  2357. 1:22:17you know using these platforms is an
  2358. 1:22:19interesting first step in stretching
  2359. 1:22:21these programs but then you also end up
  2360. 1:22:23in situations where um you know some of
  2361. 1:22:26the harder questions of what needs to be
  2362. 1:22:29done differently for these models to
  2363. 1:22:32succeed on issues that are fundamentally
  2364. 1:22:34different
  2365. 1:22:35doesn't doesn't really get i think the
  2366. 1:22:36full treatment that it sometimes
  2367. 1:22:38deserves
  2368. 1:22:45one interesting like follow-on point
  2369. 1:22:47that recalls this i don't think it made
  2370. 1:22:48it into our report but one of the
  2371. 1:22:49interesting conversations we had was
  2372. 1:22:51talking to someone who had set up a bug
  2373. 1:22:52binding program inside a large public
  2374. 1:22:54agency an organization and when they
  2375. 1:22:56talked about it that one of the measures
  2376. 1:22:58of success that they had in their mind
  2377. 1:22:59was that it allowed them to argue
  2378. 1:23:01internally to their managers and their
  2379. 1:23:03higher-ups that things needed to change
  2380. 1:23:05and so beyond the value of like a
  2381. 1:23:07particular bug or particular submission
  2382. 1:23:09it allowed them to say like we need to
  2383. 1:23:10change our contracting policies we need
  2384. 1:23:12to change
  2385. 1:23:13sort of how we do development and
  2386. 1:23:14testing all these other things and so it
  2387. 1:23:16occurs to me that thinking about the
  2388. 1:23:18value of like an experiment like the
  2389. 1:23:19twitter
  2390. 1:23:20and other socio-technical experiments
  2391. 1:23:22some of the value might be that they
  2392. 1:23:25enable folks who are already trying to
  2393. 1:23:26work for change inside to have the power
  2394. 1:23:29and the resources and something they can
  2395. 1:23:31point to that allows them to
  2396. 1:23:33advocate for those changes more
  2397. 1:23:34effectively internally that's not like
  2398. 1:23:36that certainly wasn't the way i thought
  2399. 1:23:37about bug bounty programs going into
  2400. 1:23:39this but certainly it was an interesting
  2401. 1:23:40wrinkle that sort of camille hearing you
  2402. 1:23:42talk about it made me think about that
  2403. 1:23:43as well
  2404. 1:23:46just to be caring like we totally agree
  2405. 1:23:48we think there's a lot of value in that
  2406. 1:23:50right like we've seen over and over
  2407. 1:23:52practitioners talk to us about like book
  2408. 1:23:54bounties as a way to accelerate change
  2409. 1:23:56and then wait to sort of demonstrate
  2410. 1:23:58that more transparency is possible to
  2411. 1:24:01demonstrate that more scrutiny can can
  2412. 1:24:04lead to good outcomes so there's
  2413. 1:24:06definitely um
  2414. 1:24:07you know change management of value to
  2415. 1:24:10to these book family
  2416. 1:24:14programs yeah i mean doubling down on
  2417. 1:24:17that i think if you asked even some of
  2418. 1:24:19the executives at bug bounty platforms
  2419. 1:24:21they know
  2420. 1:24:23that the organizations who are doing
  2421. 1:24:24this
  2422. 1:24:25the most impactfully and effectively
  2423. 1:24:28shore in dolls and sense terms for these
  2424. 1:24:30companies but those who are doing it
  2425. 1:24:32really well
  2426. 1:24:33they're doing root cause analysis on
  2427. 1:24:35vulnerabilities which not every
  2428. 1:24:37organization does some some say they do
  2429. 1:24:39they they don't um
  2430. 1:24:41you know they are looking for the
  2431. 1:24:42reasons why these things occurred and
  2432. 1:24:44that then does tie into matt's first
  2433. 1:24:47question which we you know i guess maybe
  2434. 1:24:49we can pivot back to of of you know what
  2435. 1:24:51what does the life cycle look like and
  2436. 1:24:53and and where do these lessons apply
  2437. 1:24:56um
  2438. 1:24:58and are you willing to go beyond
  2439. 1:25:01you know
  2440. 1:25:02technical fixes to look at
  2441. 1:25:04organizational questions processes
  2442. 1:25:07controls
  2443. 1:25:09culture
  2444. 1:25:10that form
  2445. 1:25:12the sort of underlying bedrock of why
  2446. 1:25:15security is a relentless uphill battle
  2447. 1:25:19um
  2448. 1:25:21i think if we look across it you know
  2449. 1:25:23for algorithmic harms you know for
  2450. 1:25:25example to it's it's it's as cam said
  2451. 1:25:28you can't map across perfectly
  2452. 1:25:31an an algorithmic you know a sort of
  2453. 1:25:33algorithmic
  2454. 1:25:34harms
  2455. 1:25:36an algorithmic system life cycle that
  2456. 1:25:38has the right components in place to
  2457. 1:25:41address all the myriad harms is
  2458. 1:25:43is going to include a data governance
  2459. 1:25:45life cycle uh it's got you know it's
  2460. 1:25:49it needs to be more than just industry
  2461. 1:25:51setting what this life cycle looks like
  2462. 1:25:53you have to bring in community
  2463. 1:25:54organizations so that you can understand
  2464. 1:25:56what are the risks on the back end when
  2465. 1:25:57the products are being used
  2466. 1:25:59and what are the different risk domains
  2467. 1:26:00there are security risks in ai which
  2468. 1:26:02also implicate fairness
  2469. 1:26:05as well as sort of inherent
  2470. 1:26:07characteristics of the products being
  2471. 1:26:08deployed um and and you know how do you
  2472. 1:26:11tie these pieces together
  2473. 1:26:13and how do you learn from reports in
  2474. 1:26:15ways that are meaningfully impactful
  2475. 1:26:16across that life cycle i think is
  2476. 1:26:19is a wide open question um for sort of
  2477. 1:26:22ai practitioners scholars
  2478. 1:26:25communities of all
  2479. 1:26:27shape and sizes to sort of help you know
  2480. 1:26:29work through
  2481. 1:26:30um but that's where the real value comes
  2482. 1:26:32from is is can you tie this back into
  2483. 1:26:35what is going wrong the organizational
  2484. 1:26:37route with people with processes
  2485. 1:26:40you know there are humans behind and in
  2486. 1:26:43front of technology
  2487. 1:26:44and map perhaps that's an area where we
  2488. 1:26:46can turn the question back to you and
  2489. 1:26:48say you know what are sort of some of
  2490. 1:26:50the
  2491. 1:26:51you know what are some of the lessons
  2492. 1:26:52here for security bug bounties
  2493. 1:26:55of how to address the sort of
  2494. 1:26:57socio-technical characteristics of these
  2495. 1:26:58problems more effectively than they do
  2496. 1:27:00today
  2497. 1:27:02yeah so well that actually tight i'm
  2498. 1:27:05going to answer
  2499. 1:27:06that by asking the next question that i
  2500. 1:27:09was formulating in my head for you
  2501. 1:27:11because
  2502. 1:27:12you know one one thing my understanding
  2503. 1:27:15of early
  2504. 1:27:16uh you know software development
  2505. 1:27:18security
  2506. 1:27:19development life cycle
  2507. 1:27:20type of
  2508. 1:27:22practices and processes
  2509. 1:27:24was that one thing that was very
  2510. 1:27:26important was like vulnerability
  2511. 1:27:28databases
  2512. 1:27:29and i think this this gets to some of
  2513. 1:27:32the questions that are in the chat and
  2514. 1:27:34kind of synthesize them together because
  2515. 1:27:36one of the things disclosure allowed
  2516. 1:27:39was for you know different people to
  2517. 1:27:42gather
  2518. 1:27:43various vulnerabilities classify them by
  2519. 1:27:46different types see when
  2520. 1:27:47they remained you know
  2521. 1:27:50in existence
  2522. 1:27:52uh it allowed engineers or developers to
  2523. 1:27:55have an awareness of where other people
  2524. 1:27:57had gone wrong so that when they start
  2525. 1:27:59building their software they can
  2526. 1:28:00incorporate those
  2527. 1:28:02you know known problems and address them
  2528. 1:28:04preemptively
  2529. 1:28:05so one thing like i've wondered is like
  2530. 1:28:08what
  2531. 1:28:09is there anything like a vulnerability
  2532. 1:28:11database being developed for algorithmic
  2533. 1:28:14harm socio-technical harms
  2534. 1:28:18how you know how integral is that to an
  2535. 1:28:20effective stl
  2536. 1:28:22you know type of thing type of framework
  2537. 1:28:24for
  2538. 1:28:25algorithmic systems what are the bare
  2539. 1:28:28you know what are the things stopping
  2540. 1:28:29that from happening how do bug bounty
  2541. 1:28:31programs relate to that i'm just curious
  2542. 1:28:32if any of you have thoughts on that if
  2543. 1:28:33you know of any any projects already at
  2544. 1:28:36you know in an ex
  2545. 1:28:39existent on that front
  2546. 1:28:43yeah i'm so glad that you brought this
  2547. 1:28:44up because this is something that we got
  2548. 1:28:46really excited about in thinking about
  2549. 1:28:48what is it you know what would it mean
  2550. 1:28:50to translate the
  2551. 1:28:52central and public uh databases for
  2552. 1:28:55vulnerabilities to the space of
  2553. 1:28:57algorithmic harms i think there are a
  2554. 1:28:59lot of um
  2555. 1:29:01ways in which this makes sense and not
  2556. 1:29:03only because you also see some of the
  2557. 1:29:07same problems of having underlying
  2558. 1:29:09pieces of technologies or underlying
  2559. 1:29:12databases that are used by multiple
  2560. 1:29:15projects and it can help the
  2561. 1:29:16transparency and it can help
  2562. 1:29:18the accountability that being said i
  2563. 1:29:20think here and we already have some
  2564. 1:29:23examples of some of these databases
  2565. 1:29:25appearing uh josh can talk about a few a
  2566. 1:29:28few of them but i will say i think the
  2567. 1:29:30the difficulties you have to circle
  2568. 1:29:32around
  2569. 1:29:33what is the topic that you're aiming to
  2570. 1:29:35cover
  2571. 1:29:36back to your last question a metaphor
  2572. 1:29:39that we really liked and and used is
  2573. 1:29:41what uh katie mussoris calls the
  2574. 1:29:43digestive systems that are needed for
  2575. 1:29:46bug bounties right it's the point that
  2576. 1:29:47josh was explaining if you are opening
  2577. 1:29:50yourself to receiving bugs you need the
  2578. 1:29:52digestive systems internally to actually
  2579. 1:29:55process those bugs and you need the
  2580. 1:29:57teams on the other side to impact them
  2581. 1:29:59and to address them and when we take the
  2582. 1:30:01entire space of socio-technical harms we
  2583. 1:30:03realize that those digestive systems in
  2584. 1:30:05industry are so scattered and different
  2585. 1:30:07right so the people who will address for
  2586. 1:30:09instance some of these algorithmic harms
  2587. 1:30:12on the machine learning side are very
  2588. 1:30:13different people that some of the other
  2589. 1:30:16type of issues that should be routed
  2590. 1:30:18through the trust and safety teams or
  2591. 1:30:20the anti-cheat teams and so i think that
  2592. 1:30:22the first question is like
  2593. 1:30:24yes this is a super promising idea we
  2594. 1:30:26would love to see more people working on
  2595. 1:30:28this what would it mean to create those
  2596. 1:30:29centralized
  2597. 1:30:31databases
  2598. 1:30:32and i think that in order to succeed at
  2599. 1:30:34it you would have to be super specific
  2600. 1:30:37on which actual type of harm are you
  2601. 1:30:40trying to circle around and does this
  2602. 1:30:41type of harm have kind of i don't want
  2603. 1:30:44to call it unified digestive system
  2604. 1:30:45because it sounds like a bizarre
  2605. 1:30:47metaphor now but like do do we have some
  2606. 1:30:49form of agreements on where does it go
  2607. 1:30:52and where does it need to be digested
  2608. 1:30:54um
  2609. 1:30:55josh over to you i know that you and i
  2610. 1:30:57have had long long conversations around
  2611. 1:30:59this
  2612. 1:31:00yeah and i'll try not to i'll try not to
  2613. 1:31:02be as long-winded on this one as i was
  2614. 1:31:03on the last i mean i think there's
  2615. 1:31:05there's some nascent projects out there
  2616. 1:31:07i know that in the course of sort of
  2617. 1:31:08other crash project research streams
  2618. 1:31:11um and community engagement work we came
  2619. 1:31:13across
  2620. 1:31:14a partnership on ais artificial
  2621. 1:31:16intelligence incident database
  2622. 1:31:19um
  2623. 1:31:20but i think that you know you hit the
  2624. 1:31:22nail on the head with what uh what is it
  2625. 1:31:24that we are taxonomizing or planning to
  2626. 1:31:26taxonomize planning to itemize here
  2627. 1:31:30incidents are tracked separately from
  2628. 1:31:32vulnerabilities in the cyber security
  2629. 1:31:34space
  2630. 1:31:35um we shouldn't necessarily assume you
  2631. 1:31:38know that harms versus
  2632. 1:31:40um
  2633. 1:31:43the sort of sources of harm should be
  2634. 1:31:45uh tracked
  2635. 1:31:47collectively together they should tie
  2636. 1:31:49together but but you know that that is i
  2637. 1:31:51think uh something to consider
  2638. 1:31:53um
  2639. 1:31:55i would just suggest that you know
  2640. 1:31:58double down on the more visibility we
  2641. 1:32:00can get here the more thoughtfully we
  2642. 1:32:02can start organizing these
  2643. 1:32:04these things and understanding how to
  2644. 1:32:05prevent them um in a in a sort of
  2645. 1:32:08structured way
  2646. 1:32:09um
  2647. 1:32:10and you know if there's
  2648. 1:32:13if there if there's i mean there's many
  2649. 1:32:15lessons in the history of bug bounties
  2650. 1:32:18uh for today's security practitioners um
  2651. 1:32:20but perhaps there's there's a key one
  2652. 1:32:21there which is i i don't think we are
  2653. 1:32:23getting the the value out of this as a
  2654. 1:32:25you know across
  2655. 1:32:27across the sort of security space as we
  2656. 1:32:30could be from bug bounties from
  2657. 1:32:32vulnerability disclosure programs
  2658. 1:32:33because
  2659. 1:32:35even when things get fixed they
  2660. 1:32:37generally don't get disclosed i mean
  2661. 1:32:38we've read through hundreds of program
  2662. 1:32:41terms from hacker one
  2663. 1:32:42and it was a small minority that
  2664. 1:32:45afforded any kind of you know guarantee
  2665. 1:32:48of subsequent disclosure upon for
  2666. 1:32:49example patching or 90 days or 120 days
  2667. 1:32:53and this is what we're getting at with
  2668. 1:32:54these you know independent
  2669. 1:32:55intermediaries and what they can achieve
  2670. 1:32:57google project zero they say you know x
  2671. 1:32:59days later we are going to release this
  2672. 1:33:01vulnerability with details you know and
  2673. 1:33:04and and they do and they can do that
  2674. 1:33:06because
  2675. 1:33:07you know they are empowered in this
  2676. 1:33:09ecosystem um to to sort of speak in that
  2677. 1:33:12way
  2678. 1:33:13um and and i think
  2679. 1:33:15what can we learn from sort of that
  2680. 1:33:17model and to bring back and to scale up
  2681. 1:33:20the the sort of learnings that we get
  2682. 1:33:22out of out of vulnerability disclosure
  2683. 1:33:24and
  2684. 1:33:25um really actually start to get after
  2685. 1:33:27some of the um you know the fundamental
  2686. 1:33:30misaligned economic incentives in tech
  2687. 1:33:33space when it comes to security i i
  2688. 1:33:35think this this is promising but we have
  2689. 1:33:37to figure out how to get past the nobody
  2690. 1:33:39wants to talk about x problem
  2691. 1:33:43i wanted to chime in too um i think
  2692. 1:33:46camilla you really highlighted well how
  2693. 1:33:48if you're going to have a database it
  2694. 1:33:49means it's harder in some ways when you
  2695. 1:33:51when it comes to augmented harm and bias
  2696. 1:33:54and accountability because systems are
  2697. 1:33:56so different
  2698. 1:33:57and what harm means in a certain context
  2699. 1:34:01is going to be different in another
  2700. 1:34:02context i did want to share two links i
  2701. 1:34:04didn't know about this incident
  2702. 1:34:07ai incident um database which is super
  2703. 1:34:09interesting so i'll just share a link to
  2704. 1:34:11that for anyone interested thank you for
  2705. 1:34:12mentioning that josh and then the very
  2706. 1:34:14sexy topic of vulnerability databases um
  2707. 1:34:18also brings me to the the first link i
  2708. 1:34:20shared um
  2709. 1:34:21i i would think that there is much value
  2710. 1:34:23in having a database of ai incidents but
  2711. 1:34:25acknowledging the issues that you raised
  2712. 1:34:27camille and then i also can't help but
  2713. 1:34:29think of your work mat where in a way um
  2714. 1:34:32uh email lists where hackers would
  2715. 1:34:34disclose flaws they found was served as
  2716. 1:34:36a sort of database it's just that it
  2717. 1:34:38does it was harder to search for it
  2718. 1:34:40wasn't you know information wasn't
  2719. 1:34:41necessarily indexed in the same way
  2720. 1:34:43um and i think before there would be um
  2721. 1:34:46a really useful database of algorithmic
  2722. 1:34:49harms i think it would need to you know
  2723. 1:34:52there need to be research on how are
  2724. 1:34:53these vulnerability programs or
  2725. 1:34:55databases being used in cyber security
  2726. 1:34:57more traditionally understood
  2727. 1:34:59you know who visits them how does that
  2728. 1:35:01inform other people's work and then
  2729. 1:35:03you'd want to figure out you know what
  2730. 1:35:05taxonomies like you mentioned josh would
  2731. 1:35:07make sense in the algorithm the carb
  2732. 1:35:08space
  2733. 1:35:09um because otherwise if you just create
  2734. 1:35:11a database it could just exist in the
  2735. 1:35:13ether at the same time i'm also
  2736. 1:35:15conscious of other work that i feel like
  2737. 1:35:16you've um done to matt where you've
  2738. 1:35:19tried to catalog
  2739. 1:35:20the um affordances of things like social
  2740. 1:35:23media platforms and the harms that can
  2741. 1:35:24arise but there can also be features as
  2742. 1:35:26someone mentioned in the q a
  2743. 1:35:28and i think those kind of databases are
  2744. 1:35:30really valuable as well and i know that
  2745. 1:35:32there's actually um a u.s freedom of the
  2746. 1:35:34press tracker where journalists are
  2747. 1:35:36trying to track how
  2748. 1:35:38they've been treated by governments by
  2749. 1:35:40entities in terms of harm and that the
  2750. 1:35:42experience and the work that they do and
  2751. 1:35:43i think of that as a kind of database as
  2752. 1:35:45well that you know serve as inspiration
  2753. 1:35:47but i think more research would be
  2754. 1:35:49needed and especially in order for this
  2755. 1:35:50kind of database to be useful when it
  2756. 1:35:52comes to ai harms
  2757. 1:35:57yeah they're oh sorry ryan go ahead no
  2758. 1:36:00just to reiterate and emphasize um one
  2759. 1:36:02of the things we found in our interviews
  2760. 1:36:05is like the common source of frustration
  2761. 1:36:06for people working on the infosec bug
  2762. 1:36:08bounty side is like what counts as a
  2763. 1:36:11valid flaw is so deeply contested and so
  2764. 1:36:14i think it's attractive as outsiders
  2765. 1:36:16think well in the technical world flaws
  2766. 1:36:17are clear the socio-technical world
  2767. 1:36:19squishy like they're squishy all the way
  2768. 1:36:21down
  2769. 1:36:22and so thinking about common taxonomies
  2770. 1:36:25databases like it is so important
  2771. 1:36:27because it's such a recurring point of
  2772. 1:36:28friction even on the technical side that
  2773. 1:36:30when you move into the world of
  2774. 1:36:31socio-technical harms it's going to be
  2775. 1:36:34so open to
  2776. 1:36:36competing interpretations and
  2777. 1:36:37contestation that anything you could do
  2778. 1:36:39to have like baselines and agreed upon
  2779. 1:36:40metrics or agreed upon frameworks that
  2780. 1:36:42aren't just um defined by one
  2781. 1:36:44organization or one institution would be
  2782. 1:36:46really helpful right because it's like a
  2783. 1:36:48recurring point of friction that drives
  2784. 1:36:50the participants absolutely batty with
  2785. 1:36:52good reason so i think that just
  2786. 1:36:54underlines the point of like why this is
  2787. 1:36:55both needed and also the the hazards the
  2788. 1:36:57risks of thinking about like where would
  2789. 1:36:59it live where would it sit and how could
  2790. 1:37:00it be developed
  2791. 1:37:02yeah i just want to echo echo this point
  2792. 1:37:04by ryan i think um you know and there's
  2793. 1:37:06a great question in the chat too about
  2794. 1:37:08have we given some thought about the
  2795. 1:37:09ways in which uh algorithmic harms and
  2796. 1:37:12cyber security bugs are different we
  2797. 1:37:14wrote an entire section on this i can i
  2798. 1:37:16can send the
  2799. 1:37:18specific portion of the report but i
  2800. 1:37:19think that what ryan is saying is so
  2801. 1:37:21important right we have a tendency to
  2802. 1:37:23say like oh isn't it nice on the cyber
  2803. 1:37:25security side that everybody agrees on
  2804. 1:37:27whether it's a bug and whether you can
  2805. 1:37:29fix it and you say this to a to a hacker
  2806. 1:37:31or to someone who routinely participates
  2807. 1:37:33in a bug bounty and they just laugh you
  2808. 1:37:35out of the room right this
  2809. 1:37:37so much dispute so much uh interesting
  2810. 1:37:40and fascinating questions on what's in
  2811. 1:37:42scope out of scope what's the feature
  2812. 1:37:43what's a bug what's fixable what has
  2813. 1:37:46been fixed uh what is duplicative and i
  2814. 1:37:48think this is also part of the what
  2815. 1:37:50we're hoping to learn right like um none
  2816. 1:37:53of this is is trivial all of this is
  2817. 1:37:55actually quite complicated and so it's
  2818. 1:37:57interesting and important to see those
  2819. 1:38:00mechanisms that have been set up to
  2820. 1:38:02address these um
  2821. 1:38:04these questions and which way have they
  2822. 1:38:06worked and in which ways have they
  2823. 1:38:07failed right this is why we really
  2824. 1:38:09enjoyed reading iwan and ryan's uh
  2825. 1:38:12examination of um
  2826. 1:38:15dispute resolution mechanisms in bug
  2827. 1:38:18bounty programs and in which ways uh do
  2828. 1:38:21they help clarify
  2829. 1:38:23uh what what what really we were trying
  2830. 1:38:25to solve with uh with the reporting and
  2831. 1:38:27vulnerability management
  2832. 1:38:33i mean they can just add to that
  2833. 1:38:34actually um i i think that it's just
  2834. 1:38:37these are all such good points and maybe
  2835. 1:38:39um that perhaps it could it could make
  2836. 1:38:41sense then for there to be many
  2837. 1:38:43databases of ai harms and that maybe
  2838. 1:38:46certain communities decide for them what
  2839. 1:38:47is what is a harm to them just as
  2840. 1:38:49journalists are creating this database
  2841. 1:38:51in the us and they're going to be doing
  2842. 1:38:52like i know people are doing this in
  2843. 1:38:54canada where they're saying here are the
  2844. 1:38:55harms we face or hear the risks we face
  2845. 1:38:57we want to catalog this for transparency
  2846. 1:38:59for accountability and to and so that
  2847. 1:39:01people can learn from us and in terms of
  2848. 1:39:03freedom of information requests and even
  2849. 1:39:05being and harassed by police or or or
  2850. 1:39:07arrested by them for doing their
  2851. 1:39:09journalistic
  2852. 1:39:10work and
  2853. 1:39:11and i think that it could make sense for
  2854. 1:39:13communities themselves to decide what
  2855. 1:39:15constitutes harm and i can't help but
  2856. 1:39:17think of sasha's work on this topic of
  2857. 1:39:18participatory design and how the human
  2858. 1:39:20um the people who are most impacted by
  2859. 1:39:24um the harms of a system might be the
  2860. 1:39:25best place to decide what what we talk
  2861. 1:39:28what we mean when we say harm or or
  2862. 1:39:30weakness or security or even exploit
  2863. 1:39:34i will paste the link to sasha's
  2864. 1:39:36wonderful book design justice for
  2865. 1:39:38everybody in the chat
  2866. 1:39:42yeah that's
  2867. 1:39:43great sorry go ahead josh
  2868. 1:39:46i was just going to put an exclamation
  2869. 1:39:47point on that i mean you look into the
  2870. 1:39:49way that cvss the common vulnerability
  2871. 1:39:52scoring system works and there is a base
  2872. 1:39:54score a sort of temporal score you know
  2873. 1:39:56and then an environmental score which is
  2874. 1:39:58supposed to figure in context
  2875. 1:40:04it doesn't work perfectly
  2876. 1:40:06but there is at least an acknowledgement
  2877. 1:40:09even in that sort of you know uh
  2878. 1:40:11component of the metric that it matters
  2879. 1:40:14where a vulnerability sits in a system
  2880. 1:40:16and who is interacting with that system
  2881. 1:40:19who is authorized and able to access
  2882. 1:40:21that system and and sort of what are the
  2883. 1:40:24you know the sort of
  2884. 1:40:25more socio-technical elements of it you
  2885. 1:40:27know what data is flowing through this
  2886. 1:40:29vulnerable system you know those things
  2887. 1:40:31really matter whether you can
  2888. 1:40:34access something that you shouldn't be
  2889. 1:40:36able to access is sort of secondary to
  2890. 1:40:38what are the effects of that access and
  2891. 1:40:42we definitely do identify some
  2892. 1:40:44distinctions between algorithmic harms
  2893. 1:40:47as a sort of outcome
  2894. 1:40:49versus vulnerabilities as a mechanism
  2895. 1:40:51towards an outcome that can be harmful
  2896. 1:40:54and there's there's some stuff going
  2897. 1:40:56back in there but
  2898. 1:40:58these
  2899. 1:41:01i think
  2900. 1:41:02a lot of the issues that we've seen in
  2901. 1:41:04security in the last 25 years
  2902. 1:41:06um have at their root some in some part
  2903. 1:41:09um a failure to acknowledge
  2904. 1:41:11uh that
  2905. 1:41:13this is these are socio-technical
  2906. 1:41:14problems and
  2907. 1:41:16if we could start getting after that and
  2908. 1:41:18if that comes about as a result of you
  2909. 1:41:20know other socio-technical issues being
  2910. 1:41:21taken more seriously i think that would
  2911. 1:41:22be a really great thing uh for the for
  2912. 1:41:25the sort of so for cyber security
  2913. 1:41:26practitioners and and ultimately the
  2914. 1:41:29sort of users and and subjects of tech
  2915. 1:41:33just want to
  2916. 1:41:34quickly pick up on that because i think
  2917. 1:41:36josh is talking about something that's
  2918. 1:41:38really important and that matt your
  2919. 1:41:40writing has really helped eliminate
  2920. 1:41:41which is cyber security itself is really
  2921. 1:41:44dealing with its own borders and
  2922. 1:41:46expanding as a field infosec is
  2923. 1:41:48expanding into a right what are all
  2924. 1:41:50those technological issues that are
  2925. 1:41:52adjacent which ones are infosec which
  2926. 1:41:54ones are not we've seen some of these
  2927. 1:41:56discussions fascinating with privacy as
  2928. 1:41:59we said api abuse i'm you know closed to
  2929. 1:42:02to my work i think i've really seen this
  2930. 1:42:04in the way infosec tackled information
  2931. 1:42:07operations as some of these were indeed
  2932. 1:42:10conducted by traditional apt actors in
  2933. 1:42:13the field was very familiar with and
  2934. 1:42:14some of that felt very much close to
  2935. 1:42:18close to the field another dimension of
  2936. 1:42:20it felt very far from it so i think that
  2937. 1:42:22what we're talking about is also a field
  2938. 1:42:24that's very much in movement very much
  2939. 1:42:27negotiating its own boundaries uh and
  2940. 1:42:30were our small hope was that you know on
  2941. 1:42:33the socio-technical side we could
  2942. 1:42:35extract some lessons for
  2943. 1:42:38people working on algorithmic harms but
  2944. 1:42:40perhaps too there are some lessons from
  2945. 1:42:42people who work closer to the
  2946. 1:42:44socio-technical side of things that can
  2947. 1:42:46help infosec and overall the cyber
  2948. 1:42:49security field in its own transition to
  2949. 1:42:51better understanding what's um
  2950. 1:42:54on its borders on the frontiers of the
  2951. 1:42:56field sorry that was very abstract
  2952. 1:43:01now this is one i mean i love that this
  2953. 1:43:04this got into such abstract kind of
  2954. 1:43:06epistological questions because i think
  2955. 1:43:08that's really
  2956. 1:43:09where a lot of these
  2957. 1:43:11problems are at which is interesting and
  2958. 1:43:13i mean that's not just from our
  2959. 1:43:14discussion these are also the types of
  2960. 1:43:16questions that are repeating over and
  2961. 1:43:18over
  2962. 1:43:19in the chat and it's just reminding me
  2963. 1:43:21that you know even
  2964. 1:43:22passwords were even controversial on
  2965. 1:43:26you know shared mainframes because some
  2966. 1:43:28people
  2967. 1:43:29saw that as
  2968. 1:43:30entity
  2969. 1:43:32you know opposed to the philosophy of
  2970. 1:43:35shared resources and
  2971. 1:43:36there's always going to be
  2972. 1:43:38i mean maybe maybe buffer overflow
  2973. 1:43:40attacks and things like that are an
  2974. 1:43:42example of something that probably
  2975. 1:43:44everyone agreed was a
  2976. 1:43:46a
  2977. 1:43:47security challenge but there's always
  2978. 1:43:48going to be a political
  2979. 1:43:50dimension that's informed by where
  2980. 1:43:52people are doing the analysis from and
  2981. 1:43:54it's it's i'm very excited to see where
  2982. 1:43:57people take that
  2983. 1:43:58um
  2984. 1:43:59and and how this work contributes to it
  2985. 1:44:02um but we are
  2986. 1:44:04you know running low on time so maybe
  2987. 1:44:06instead of getting more abstract my
  2988. 1:44:08brains is already worrying we can we can
  2989. 1:44:10track back to a couple um
  2990. 1:44:12more concrete questions
  2991. 1:44:14i mean one is you know one of the
  2992. 1:44:16panelists noted in our panelists chat
  2993. 1:44:19that there's so much agreement on
  2994. 1:44:21different issues but i was wondering
  2995. 1:44:22when when you were each reading each
  2996. 1:44:23other's reports were there any insights
  2997. 1:44:25or
  2998. 1:44:26findings that you found particularly
  2999. 1:44:28interesting that you hadn't hit upon in
  3000. 1:44:31your own work um
  3001. 1:44:35yes that's a is that is that a fair
  3002. 1:44:37question
  3003. 1:44:43i mean it's not something i disagree
  3004. 1:44:45with but i was very struck by you know
  3005. 1:44:48the the the deep
  3006. 1:44:49digging that joanne and ryan did on the
  3007. 1:44:52netscape bounty
  3008. 1:44:54uh i think is something that will that
  3009. 1:44:56there's a section of their paper that
  3010. 1:44:58has is worth reading even aside from
  3011. 1:45:01everything else that's worth reading in
  3012. 1:45:02that paper it is
  3013. 1:45:04you know how persistent is the idea that
  3014. 1:45:06you can use these kinds of mechanisms to
  3015. 1:45:09just shoe a pr problem under the rug
  3016. 1:45:11well it was the from the first one
  3017. 1:45:13onwards um
  3018. 1:45:15so i was very struck by that and and
  3019. 1:45:17really enjoyed reading that part in
  3020. 1:45:18particular um
  3021. 1:45:21cam i know you were about to jump in
  3022. 1:45:22there as well no i was gonna say i think
  3023. 1:45:24some of the first thing that that
  3024. 1:45:27was very odd for for us when we started
  3025. 1:45:29this research project is initially we
  3026. 1:45:31thought it was going to be short and we
  3027. 1:45:33were going to get away with a small
  3028. 1:45:35paper which of course we massively
  3029. 1:45:37failed at this and one of the first
  3030. 1:45:38thing that was just very puzzling is
  3031. 1:45:41how much feelings and disagreements
  3032. 1:45:43people had on both bounties and they
  3033. 1:45:45would just you know like our
  3034. 1:45:46interviewees they would just like really
  3035. 1:45:48disagree with each other and it would be
  3036. 1:45:49different schools of bug bounties and
  3037. 1:45:51such strong disagreements within the
  3038. 1:45:53field and i think at first it was a bit
  3039. 1:45:55head spinning for us being
  3040. 1:45:57how is it that people can disagree on
  3041. 1:45:59everything here so much including the
  3042. 1:46:02history of bug bounties what is or is
  3043. 1:46:04not about boundaries things on which you
  3044. 1:46:05could see like you know you you you
  3045. 1:46:07could conceive perhaps that there would
  3046. 1:46:09be more agreements and um i felt for us
  3047. 1:46:12it's at that time that we
  3048. 1:46:13met juwan and ryan whose research was
  3049. 1:46:15very grounding both in putting some you
  3050. 1:46:19know some some semblance of like all
  3051. 1:46:21right these are the things that are
  3052. 1:46:23actually documented that people align on
  3053. 1:46:25and perhaps on explaining some of the
  3054. 1:46:28deeper dynamic that explained some of
  3055. 1:46:31the passion and disagreements that we
  3056. 1:46:34very quickly saw and i will admit that
  3057. 1:46:36we that we took a hot second to to
  3058. 1:46:39process and pack
  3059. 1:46:42one thing i mean i learned so much from
  3060. 1:46:44reading um matt your report as well as
  3061. 1:46:46josh mcmillan your report but one thing
  3062. 1:46:47that like
  3063. 1:46:49wasn't front of mind for me when i was
  3064. 1:46:51doing this work was thinking about like
  3065. 1:46:52this alternative model of adversarial
  3066. 1:46:54bounties
  3067. 1:46:55like how useful it might be how fraud it
  3068. 1:46:57might be how difficult it can be but
  3069. 1:46:59really ultimately how useful
  3070. 1:47:01um in our space of the infosec world
  3071. 1:47:03adversarial boundaries like don't really
  3072. 1:47:06they're not really there that's not
  3073. 1:47:07where the market went if you talking
  3074. 1:47:08about adversarial bounty it kind of
  3075. 1:47:09looks more like the offensive market
  3076. 1:47:11right people buying and selling exploit
  3077. 1:47:13kids like that's the adversarial market
  3078. 1:47:15which is beyond the scope of sort of
  3079. 1:47:16what we look into for a variety of
  3080. 1:47:18reasons but it made me wonder like um
  3081. 1:47:21in a very serious way like did we
  3082. 1:47:23institutionalize the wrong model here
  3083. 1:47:25like did bug bounties evolve in a way
  3084. 1:47:27through good intentions and bad
  3085. 1:47:29intentions and happenstance and
  3086. 1:47:31everything else that we detailed did we
  3087. 1:47:32institutionalize the wrong model and so
  3088. 1:47:36reading camille and josh's work and the
  3089. 1:47:38report from ajl more generally it made
  3090. 1:47:40me think like
  3091. 1:47:42here we have a chance maybe to get it
  3092. 1:47:43right and i hope we do and so that was
  3093. 1:47:46something i took away that was not you
  3094. 1:47:48know on my radar at all one of the many
  3095. 1:47:49things but really resonated with me
  3096. 1:47:51reading the report and resonated even
  3097. 1:47:52more today hearing um it talked about in
  3098. 1:47:55such a clear way
  3099. 1:47:58so we're supposed to disagree now here
  3100. 1:48:00we are just patting each other in the
  3101. 1:48:01back again we failed we failed in
  3102. 1:48:02running short reports and we failed and
  3103. 1:48:04arguing oh no
  3104. 1:48:09um
  3105. 1:48:09[Music]
  3106. 1:48:11okay so yeah so i'm i'm walking away
  3107. 1:48:13from this thinking like i mean there's
  3108. 1:48:15this one
  3109. 1:48:16big level of challenges which is you
  3110. 1:48:18know how do we even think of what the
  3111. 1:48:20buckets and the classifications and
  3112. 1:48:21these kind of epistemological challenge
  3113. 1:48:23there's also this very pressing much
  3114. 1:48:25more concrete need just to bring people
  3115. 1:48:28you know a more diverse pool of people
  3116. 1:48:30who can identify
  3117. 1:48:32uh more
  3118. 1:48:34you know wider range of of issues and
  3119. 1:48:36also be heard right to amplify them
  3120. 1:48:40and these are two two big challenges i'm
  3121. 1:48:42also curious you know if having finished
  3122. 1:48:44this work what are was there were there
  3123. 1:48:46any things that you wished you could
  3124. 1:48:48answer that you couldn't get at or
  3125. 1:48:50things that you would like
  3126. 1:48:52you know the students or other
  3127. 1:48:53researchers who are watching this or
  3128. 1:48:55reading a report to kind of
  3129. 1:48:57pick up on and continue the thread
  3130. 1:49:00forward to um you know for the next
  3131. 1:49:03round of phase of research on this
  3132. 1:49:04important
  3133. 1:49:05topic
  3134. 1:49:07um
  3135. 1:49:08i have thoughts immediately on that um
  3136. 1:49:10and
  3137. 1:49:11the first thing i think of is the
  3138. 1:49:14question of labor issues and our report
  3139. 1:49:16you know focuses significantly on the
  3140. 1:49:18working conditions and labor issues
  3141. 1:49:19related to bugbani programs and bounty
  3142. 1:49:21programs in general
  3143. 1:49:23i don't think we've solved the problem
  3144. 1:49:24and i don't know if there ever will be a
  3145. 1:49:26solved problem here but
  3146. 1:49:27i don't know if we have
  3147. 1:49:30solved the problem of figuring out what
  3148. 1:49:32the solution looks like i did mention
  3149. 1:49:34the idea of creating guilds or groups of
  3150. 1:49:38hackers aka unions who would advocate
  3151. 1:49:40for baseline standards of treatment that
  3152. 1:49:42seems like a really
  3153. 1:49:43great way forward according that will be
  3154. 1:49:45extremely hard given the international
  3155. 1:49:48labor market we're dealing with whereas
  3156. 1:49:50in in you know historically and
  3157. 1:49:52typically unions are based on people who
  3158. 1:49:54work at least in a country because you
  3159. 1:49:57have certain rules are applied in your
  3160. 1:49:59region and by the governments that have
  3161. 1:50:01jurisdiction where you live
  3162. 1:50:03and so with that said i think that how
  3163. 1:50:06will the labor conditions improve in
  3164. 1:50:08this market that is an open question and
  3165. 1:50:10i would hope that um people begin
  3166. 1:50:13working on that because we've looked at
  3167. 1:50:14how hackers experienced this we've
  3168. 1:50:16looked at
  3169. 1:50:18what people's experience of this market
  3170. 1:50:20is and we know that many dr benefit from
  3171. 1:50:23it um benny loved this field they love
  3172. 1:50:26working in this in in this
  3173. 1:50:28field and doing this work and i would
  3174. 1:50:30assume that it's going to be the same
  3175. 1:50:31case for algebra algorithmic arms um but
  3176. 1:50:34i hope that there is
  3177. 1:50:36more work and better answers to the
  3178. 1:50:39question of how do hackers then how do
  3179. 1:50:41workers and infrastructure workers
  3180. 1:50:43protect their rights because of the
  3181. 1:50:45issues that we've highlighted
  3182. 1:50:50there's
  3183. 1:50:51two things i really wish
  3184. 1:50:52i could know and hope to find out in the
  3185. 1:50:54future the first is like we look so much
  3186. 1:50:57on the side of the labor of the people
  3187. 1:50:59who are finding and disclosing bugs i
  3188. 1:51:00would love to know more about the people
  3189. 1:51:02who have the most thankless job in the
  3190. 1:51:04world which is triaging the incoming
  3191. 1:51:05reports and bugs it's like seeing their
  3192. 1:51:08perspective understanding how the market
  3193. 1:51:10works from their view is something i
  3194. 1:51:11would love to know more about and i hope
  3195. 1:51:13to find out in the future
  3196. 1:51:14the other thing that i would love to
  3197. 1:51:15know more about if i could wave my magic
  3198. 1:51:17wand is to get access to sort of the
  3199. 1:51:19books for the bug bounty platforms like
  3200. 1:51:22i am dying to know about more details
  3201. 1:51:25about their financial model are they
  3202. 1:51:26going to survive are they going to make
  3203. 1:51:28it
  3204. 1:51:29um these are big vc backed companies but
  3205. 1:51:32they've been around now they're coming
  3206. 1:51:33up on a decade
  3207. 1:51:34and they've become important parts of
  3208. 1:51:37the vulnerability disclosure pipeline
  3209. 1:51:39for many many companies and in the back
  3210. 1:51:41of my mind i have like a real serious
  3211. 1:51:43worry about what happens if they go away
  3212. 1:51:46because we built a lot of things on that
  3213. 1:51:47foundation but we still don't really
  3214. 1:51:48understand
  3215. 1:51:50like the plumbing of those companies in
  3216. 1:51:52a way that i would like to know so that
  3217. 1:51:53would be if i could wave wave my wand go
  3218. 1:51:55back to the plumbing slash digestive
  3219. 1:51:56metaphors i want to know more about the
  3220. 1:51:58financing on that side so those are my
  3221. 1:52:00two my two things i'd like to know more
  3222. 1:52:02about
  3223. 1:52:03ryan if i could say like hey we've built
  3224. 1:52:05a lot of things on this foundation but
  3225. 1:52:07does anyone have any clear idea of the
  3226. 1:52:09plumbing is the overall story of cyber
  3227. 1:52:11security
  3228. 1:52:16um i think there's so much uh that that
  3229. 1:52:19we would love to know more about i'm
  3230. 1:52:20hoping that our report sort of helps uh
  3231. 1:52:24you know
  3232. 1:52:25give give others research directions
  3233. 1:52:27from what happened to adversarial
  3234. 1:52:29bounties to or how do some of these
  3235. 1:52:32concepts translate to other spaces i
  3236. 1:52:35will add a small note of something that
  3237. 1:52:37came up in our work which is doing this
  3238. 1:52:39work with the perspective of um
  3239. 1:52:42inclusion in mind and translating to
  3240. 1:52:45spaces that are very uh more
  3241. 1:52:47socio-technical and perhaps more aware
  3242. 1:52:49of uh the language we use and how we
  3243. 1:52:52talk about this and how words shape uh
  3244. 1:52:55shape who participates and how those
  3245. 1:52:57programs are seen we struggled a bit
  3246. 1:53:00with the vocabulary that is widely used
  3247. 1:53:02in infosec starting with the word bounty
  3248. 1:53:05that uh it's you know that's that's
  3249. 1:53:07something that came up for us and and i
  3250. 1:53:09think there's also a little bit more to
  3251. 1:53:10do here to reinvent not just how these
  3252. 1:53:13programs work but you know the the
  3253. 1:53:15really the words we use to talk about um
  3254. 1:53:18some key concepts in infosec so i'll
  3255. 1:53:21just add this small note
  3256. 1:53:28and i am fully seated on the topic of
  3257. 1:53:30bug bounties this
  3258. 1:53:32i'm good no i'm kidding uh i think i
  3259. 1:53:34would share ryan's interest in the
  3260. 1:53:37financial plumbing of the
  3261. 1:53:38platforms um
  3262. 1:53:40particularly given what we've seen in
  3263. 1:53:42sort of other
  3264. 1:53:44loosely comparable um
  3265. 1:53:47i'm gonna use the word crowdsourcing
  3266. 1:53:50it's not quite right read the report to
  3267. 1:53:51find out more
  3268. 1:53:53but those kinds of approaches may not be
  3269. 1:53:55as sort of scalable durable profitable
  3270. 1:53:58as
  3271. 1:53:59um
  3272. 1:54:00i think some in silicon valley have
  3273. 1:54:03led
  3274. 1:54:04founders the public governments to
  3275. 1:54:06believe
  3276. 1:54:07and it comes with
  3277. 1:54:09really really serious costs for the
  3278. 1:54:12people who are
  3279. 1:54:13working in these ecosystems and i would
  3280. 1:54:16just like to express gratitude to have
  3281. 1:54:18been able to
  3282. 1:54:20work on this topic at the same time
  3283. 1:54:22um as these wonderful folks and many
  3284. 1:54:24others who are sort of pushing the boat
  3285. 1:54:25out in this space it's been really
  3286. 1:54:27really interesting and
  3287. 1:54:30um
  3288. 1:54:31can't wait to see uh how folks build
  3289. 1:54:33upon this and and move forward
  3290. 1:54:37uh yeah to add to that matt is an
  3291. 1:54:38extremely humble person but it's because
  3292. 1:54:41of matt that we know each other because
  3293. 1:54:43he had these conversations with both of
  3294. 1:54:45us
  3295. 1:54:46through dave's society and connected us
  3296. 1:54:47and so i just gotta give credit where
  3297. 1:54:49it's due and matt thank you for
  3298. 1:54:51connecting us and making this happen
  3299. 1:54:53um despite never taking credit for what
  3300. 1:54:55you do
  3301. 1:54:57that's very flattering but there's a lot
  3302. 1:54:59of other people at that society integral
  3303. 1:55:01to that so it's it's it it's a it's a
  3304. 1:55:05community right
  3305. 1:55:07yeah
  3306. 1:55:08one tiny correction as well i said i
  3307. 1:55:10really said the federal trade commission
  3308. 1:55:12and i realized
  3309. 1:55:13about 20 minutes ago i met federal
  3310. 1:55:15communications commission so i just
  3311. 1:55:16wanted to correct that for the record
  3312. 1:55:21nice the transcript will be appended
  3313. 1:55:23suitably i don't know if there's going
  3314. 1:55:25to be transfer but
  3315. 1:55:26yeah well this is great i mean thanks
  3316. 1:55:28everyone for uh inviting me to
  3317. 1:55:30participate in this i learned so much
  3318. 1:55:32from you all thanks to columbia for
  3319. 1:55:34hosting this
  3320. 1:55:36jason do you have some final thoughts
  3321. 1:55:38for us
  3322. 1:55:39yeah absolutely hope i just learned a
  3323. 1:55:42ton out of this this was really
  3324. 1:55:44fantastic these are topics that i kind
  3325. 1:55:45of thought i knew something about and i
  3326. 1:55:48guess i did but i just learned so much
  3327. 1:55:50more so thank you very much
  3328. 1:55:53um also um we've got a ton of other
  3329. 1:55:55things coming up uh that we hope that
  3330. 1:55:58you that have joined here uh will will
  3331. 1:56:00like to
  3332. 1:56:02visit also for example we have teamed up
  3333. 1:56:05our uh salzman institute of war and
  3334. 1:56:07peace studies has teamed up with
  3335. 1:56:09columbia's school of the arts
  3336. 1:56:11the digital storytelling labs for defrag
  3337. 1:56:13which is the hacked
  3338. 1:56:15film festival we've got an event on war
  3339. 1:56:17games that is going to be coming out
  3340. 1:56:19on the 24th of february that's going to
  3341. 1:56:22be featuring we're pretty sure um
  3342. 1:56:25director of sissa jen easterly one of
  3343. 1:56:28the top
  3344. 1:56:29cyber security officials in the country
  3345. 1:56:32as well as and i think this is the first
  3346. 1:56:33time
  3347. 1:56:35for this we're actually going to have a
  3348. 1:56:37general from norad we hope to have on
  3349. 1:56:39the panel so both from the norad angle
  3350. 1:56:41and from that we have a lot of other
  3351. 1:56:44events coming up as part of our nigella
  3352. 1:56:46rhoden digital futures forum so please
  3353. 1:56:49keep an eye out for that and also the
  3354. 1:56:51events coming up from the salsman
  3355. 1:56:53institute of war and peace studies thank
  3356. 1:56:56you very much have a great weekend
  3357. 1:56:59but happy lunar new year for those that
  3358. 1:57:01are celebrating

About this transcript

This page contains the full transcript of Debugging Bug Bounties in Cyberspace: From Vulnerability Discovery to Algorithmic Harms Redress by Columbia SIPA, generated from the public captions YouTube serves with the video. The transcript has 20,677 words across 3,358 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.