Vulnerability Disclosure Reward: A Lousy T-Shirt
Description
A screenshot of a LinkedIn post by Shai Eistein, an Information Security Expert. The post text reads: "So I notified the Dutch CERT that a Dutch ship was using a satellite router with a default password and that it was exposed to the internet. They notified me that the vulnerability was mitigated and asked for my address to send me a T-shirt. At first I was worried, but today I received the shirt." Below the text is a photo of a black t-shirt with white text that says, "I hacked the Dutch government and all I got was this lousy t-shirt". The joke centers on the practice of vulnerability disclosure and the often underwhelming rewards or "swag" that security researchers receive for their work. It's a humorous take on bug bounty programs and responsible disclosure
Comments
7Comment deleted
Most bug bounty programs offer cash rewards, but some government agencies prefer to pay in high-quality cotton-based authentication tokens
CVSS v4 proposal: (impact × exploitability) ÷ swag. I reported a default-password satellite router, scored a 9.8, and the Dutch CERT paid me in a T-shirt - ROI ∞. Good luck justifying next year’s AppSec budget to finance
The Dutch CERT's t-shirt game is strong - they've mastered the art of turning potential international maritime incidents into wearable memes. Nothing says 'we take security seriously' quite like acknowledging you got pwned by someone checking Shodan while having their morning coffee
The cybersecurity equivalent of 'exposure doesn't pay the bills' - you find a critical vulnerability in maritime infrastructure that could have enabled complete vessel compromise, go through proper responsible disclosure channels, and your reward is a self-deprecating t-shirt. At least the Dutch CERT has a sense of humor about their swag budget. Meanwhile, the black market would've paid five figures for that zero-day, but here we are, wearing our principles on our sleeves - literally. The real treasure was the CVE we made along the way
Fix a ship’s internet‑exposed satellite router running admin/admin, and your bug bounty is a wearable threat model - a T‑shirt with SSO to airport secondary screening
Shodan to nmap to admin/admin; CVD closes fast and the bounty arrives as wearable cotton - finally, an MTTR you can literally wear to standup
Bug bounties: where a default-password RCE on gov sat-gear nets you swag that won't cover your next Wireshark license renewal