Zoom had a vulnerability that allowed users on MacOS to be connected to a video conference with their webcam active simply by visiting an appropriately crafted page. Zoom’s response has largely been to argue that:
a) There’s a setting you can toggle to disable the webcam being on by default, so this isn’t a big deal,
b) When Safari added a security feature requiring that users explicitly agree to launch Zoom, this created a poor user experience and so they were justified in working around this (and so introducing the vulnerability), and,
c) The submitter asked whether Zoom would pay them for disclosing the bug, and when Zoom said they’d only do so if the submitter signed an NDA, they declined.
(a) and (b) are clearly ludicrous arguments, but (c) is the interesting one. Zoom go on to mention that they disagreed with the severity of the issue, and in the end decided not to change how their software worked. If the submitter had agreed to the terms of the NDA, then Zoom’s decision that this was a low severity issue would have led to them being given a small amount of money and never being allowed to talk about the vulnerability. Since Zoom apparently have no intention of fixing it, we’d presumably never have heard about it. Users would have been less informed, and the world would have been a less secure place.
The point of bug bounties is to provide people with an additional incentive to disclose security issues to companies. But what incentive are they offering? Well, that depends on who you are. For many people, the amount of money offered by bug bounty programs is meaningful, and agreeing to sign an NDA is worth it. For others, the ability to publicly talk about the issue is worth more than whatever the bounty may award – being able to give a presentation on the vulnerability at a high profile conference may be enough to get you a significantly better paying job. Others may be unwilling to sign an NDA on principle, refusing to trust that the company will ever disclose the issue or fix the vulnerability. And finally there are people who can’t sign such an NDA – they may have discovered the issue on work time, and employer policies may prohibit them doing so.
Zoom are correct that it’s not unusual for bug bounty programs to require NDAs. But when they talk about this being an industry standard, they come awfully close to suggesting that the submitter did something unusual or unreasonable in rejecting their bounty terms. When someone lets you know about a vulnerability, they’re giving you an opportunity to have the issue fixed before the public knows about it. They’ve done something they didn’t need to do – they could have just publicly disclosed it immediately, causing significant damage to your reputation and potentially putting your customers at risk. They could potentially have sold the information to a third party. But they didn’t – they came to you first. If you want to offer them money in order to encourage them (and others) to do the same in future, then that’s great. If you want to tie strings to that money, that’s a choice you can make – but there’s no reason for them to agree to those strings, and if they choose not to then you don’t get to complain about that afterwards. And if they make it clear at the time of submission that they intend to publicly disclose the issue after 90 days, then they’re acting in accordance with widely accepted norms. If you’re not able to fix an issue within 90 days, that’s very much your problem.
If your bug bounty requires people sign an NDA, you should think about why. If it’s so you can control disclosure and delay things beyond 90 days (and potentially never disclose at all), look at whether the amount of money you’re offering for that is anywhere near commensurate with the value the submitter could otherwise gain from the information and compare that to the reputational damage you’ll take from people deciding that it’s not worth it and just disclosing unilaterally. And, seriously, never ask for an NDA before you’re committing to a specific $ amount – it’s never reasonable to ask that someone sign away their rights without knowing exactly what they’re getting in return.
tl;dr – a bug bounty should only be one component of your vulnerability reporting process. You need to be prepared for people to decline any restrictions you wish to place on them, and you need to be prepared for them to disclose on the date they initially proposed. If they give you 90 days, that’s entirely within industry norms. Remember that a bargain is being struck here – you offering money isn’t being generous, it’s you attempting to provide an incentive for people to help you improve your security. If you’re asking people to give up more than you’re offering in return, don’t be surprised if they say no.