6 ms·
Sounds like FB acted pretty unprofessionally both in the infrastructure department and in handling of the situation. You had some embarrassing mistakes and ins
by meshko 11y ago
Sounds like FB acted pretty unprofessionally both in the infrastructure department and in handling of the situation. You had some embarrassing mistakes and instead of acknowledging them you tried to scare the reporter into shutting up and leaving you alone. That part is pretty clear. Whether he violated your rules and how much you pay him I don't care.
- blazespin 11y agoEspecially in the infrastructure department. This is the huge story here.. putting all your creds on S3 in the open protected by one key?? Craziness.
- meshko 11y agowhy would private keys be on any system somehow accessible from the internet? gotta put all in the cloud?
- lox 11y agoYes, exactly this. Without escalating an RCE, how would he have been able to expose this absolutely huge flaw? The initial report was inconsequential, but this seems like at the very least a much more than $2500 bug. If things like this are considered "unethical" it kind of makes finding million dollar bugs in a bug bounty close to impossible.
- joshuahutt 11y agoI agree. According to Stamos, though, there was no flaw: > The fact that AWS keys can be used to access S3 is expected behavior and would not be considered a security flaw in itself.
- option_greek 11y agoIf he thinks that is how it should be and nothing needs to be changed then god save their user data. He conveniently missed out the key separation and privilege escalation shown by the researcher.
- BHSPitMonkey 11y agoYeah, that's like gaining root access on a server and being told "well, the fact that those commands will execute is merely Linux working as designed". Talk about missing the point...
- lovelearning 11y agoThat surprised me too. Of course, AWS keys can be used to access S3, but I don't see how exposing private AWS keys on a public facing server can be "expected behavior".
- onewaystreet 11y agoHe only got $2500 because the bug had already been reported by others. Most programs pay nothing in that case.
- msravi 11y agoThen the first one to report it should have been paid a lot more than the $2500. The fact is that FB didn't understand the impact of the bug, and it needed Wes to show them how severe the bug was. And once they knew how severe it was, they ought to have acknowledged the severity and paid him a lot more.
- wepple 11y agoI feel that privilege escalation/lateral movement is implicitly discluded from almost all bug bounty programs, most researchers know that. It's a really grey area beyond an initial 'access bug', so it pays not to go there. Otherwise, where should Wes have stopped? keep proving more vulnerabilities until he's downloaded their code? or got private photos of Zuckerbergs kid? Just to show that it is indeed a serious bug?
- zenincognito 11y agoHow is this unprofessional behaviour ? They are trying to condone the behaviour of data access which in all honesty falls on borderline unethical behaviour. Any professional who participates in any company's bug bounty should respect their rights as well. Whether the keys were accessible and it is a technical blunder is secondary but the action the researcher took a) accessing the data he did not need to b) making this into a big deal when he was the one not respecting the bug bounty's limits makes this a case for FB.
- meshko 11y agoI am not saying that the sec researcher is right here. I don't care about him, he is just some random guy who wants publicity. Talking about FB is more interesting because it is a huge public corporation which should behave smartly. But if you want talk ethical/not ethical -- he found a serious problem in their infrastructure. Had he not looked at the data ("respected their privacy") he wouldn't have found it. You can't make the omelette w/o breaking eggs. Perhaps this is more of penetration testing, not bug bounty stuff, but again, i don't care. He found stuff. He didn't use it (AFAIK) for anything bad. FB has to thank him and quickly fix their process. Complaining to his boss and acting all pissed suggests that they do not understand they they did mess up big time.
- deleted 11y ago[deleted]
- forgottenpass 11y agoI am not saying that the sec researcher is right here. I don't care about him, he is just some random guy who wants publicity. Talking about FB is more interesting You're right. An important thing has gotten lost in the shuffle. We should be pointing and laughing at Facebook. Then when the giggling dies down, asking: Something this bad and with such a "trivial" vuln manged to get published, what else have their now-proven-to-be-shitty practices left open? He found stuff. He didn't use it (AFAIK) for anything bad. Reminds me of the way business dudes and non-security devs used to react before security got all popular and legit. And they could have even avoided the whole public brewhaha if communication had been better between the tester and the product staff. Classic blunder. Complaining to his boss and acting all pissed suggests that they do not understand they they did mess up big time. They jumped to contacting someone over his head before engaging in real talk with him. And then their public response is covering their ass by arguing over the fine print of how he shouldn't have been poking around where he was. Obviously there are differences, but similarities are fun too!
- itsthecourier 11y agoYeah, scaring the guy with his employer and telling him that kind of bug is USD2,500 worth makes me think about how important is my data for them
- tomlongson 11y agoThe hypothetical question Facebook should ask is: "If the security researcher did not disclose the RCE, but instead sold it to highest bidder, how much would that likely pay in this situation?" Paying security researchers to properly disclose is a way of financially encouraging the right behavior. While it may be tough to stomach a large payout for responsible disclosure, do you really want them considering the alternative? It's like tipping in a restaurant to ensure food quality.
- gbhn 11y agoAgreed. To me as an outsider, this escalation bug looks a max bug, definitely dwarfing any particular admin console vulnerability, and that the processes the researcher claims to have followed were pretty much necessary to show it. Whether or not this followed the letter of the policy, by responsibly reporting the escalation in the spirit of the policy, the researcher has fulfilled the spirit of the goal.