27 ms·
I Got Paid $0 from the Uber Security Bug Bounty
- true_religion 9y agoIf true, then Uber dropped the ball again when it came to PR.
- cyberpunk0 9y agoThe problem is you trusted Uber in the first place
- hammock 9y agoWhen a company does something immoral, why do people always say "well that's bad because it's bad PR"? How about, that's bad because it's immoral?
- tdb7893 9y agoIn my view it's because immorality only really affects a company if it's perceived as immoral (i.e. is a PR issue)
- droopyEyelids 9y agoMorality is a human standard of behavior, corporations are non-human persons. I realize this can seem like a cynical take, but if you look at the devestation to our planet, and even human life, I think you can see it's an attempt to be accurate, not cynical. The people who run a corporation can struggle to maintain a moral direction, but that aim is orthogonal to the goals of the firm and when a conflict arises, it's "logical" for the company to replace whoever diverts it from its goal.
- reificator 9y agoBecause immoral actions don't tend to hurt the bottom line, in fact generally the opposite. Until, that is, someone shines a light on said immoral behavior for the public to see. Then it tends to have an effect, small as it may usually be.
- deleted 9y ago[deleted]
- maxxxxx 9y agoBecause it's assumed that a company can do whatever it wants as long as it's self serving and not blatantly illegal.
- deleted 9y ago[deleted]
- ineedasername 9y agoHas anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value? Do you trust their code contributions on OSS to not contain malicious attack vectors?
- hackeroneuser 9y agoIf you check reports that are actually valid, you can see that Uber actually pays for valid issues. Excluding the 100,000, Uber has already paid 1million+ in bug bounty. Please check their hackerone platform :)
- arkadiyt 9y ago> Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) They've paid out more than $1,300,000 in bounties, you can view all their payouts here: https://hackerone.com/uber/hacktivity?sort_type=latest_disclosable_activity_at&filter=type%3Aall%20to%3Auber&page=1&range=forever https://hackerone.com/uber/hacktivity?sort_type=latest_discl... > Do you trust their code contributions on OSS to not contain malicious attack vectors? This has nothing to do with anything.
- ineedasername 9y agoGood to know they aren't actually deadbeats on bugbounties and can chalk up this example to honest disagreement. As for the rest, it has to do with everything. Would you trust your application's security to code libraries written by a company with the the allegations hanging over Uber? If there's a chance your customer data might be a strategic asset for Uber?
- deleted 9y ago[deleted]
- Klingo 9y ago
- sprite 9y agoUber’s bug bounty seems like a complete joke.
- GregoryVPerry 9y agoTheir bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.
- vxNsr 9y agoI assumed that was in response to the whole ransom thing, not directly related to refusing to publish vulns.
- hackeroneuser 9y agoAlright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure page with no valuable information for new hackers. 2) I haven't seen reports getting locked unless reporter goes "Can i haz update" every 2 days. Then in such cases, Locking a report is more than fair. 3) You might be confusing this with Limited Disclosure. That is allowed in both sense by companies and hackers. Most of my reports are limited disclosure because sometimes, I have to share personal details or personal information that I don't want other hackers to see. I support transparency that is why, till this day, all of my resolved reports for public programs are publicly disclosed. Even in Uber's case, I have disclosed bug but they were limited disclosure because it had my personal information. But if you check, Uber has allowed me to write public blogs on my reports. So please, learn about the platform and a program works before you make any form of assumption.
- falsedan 9y ago> So please, learn about the platform and a program works before you make any form of assumption. Welcome to Hacker News, I see it’s your first time visiting.
- netsec_burn 9y agoOnly the XSS one was a real vulnerability, they should have paid $500 at least for that though.
- reificator 9y agoClient side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.
- GregoryVPerry 9y agoYeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.
- sushid 9y agoNot the parent commenter and I get what you mean, but if they state that it's a duplicate issue (and assuming on good faith that it is), doesn't it make sense that they don't pay you out for that? I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.
- chris_wot 9y agoYeah, but we have no idea how long this has been unfixed. I reckon all security bugs not paid out to Uber at this point should just get automatically publicly documented. Also: this is Uber. At this point, they’ve used up all their good faith. I definitely wouldn’t be taking anything they say in good faith - I still haven’t forgotten them threatening a journalist or publicly tracking the ride of a CEO for an entire room of people!
- deleted 9y ago[deleted]
- mahdix 9y agoThis is terrible! So sad to see companies make use of people's time and effort without even acknowledging their contribution.
- chx 9y agoLet me get this straight: there's a company built to exploit the ignorance of people of just how much it costs to drive their own car and the complete disregard of law and you thought while they don't respect their drivers and various governing bodies all over the globe they will respect you ?
- XmasHijinx 9y agoThe Social Generation loves to do free work!
- kinkrtyavimoodh 9y agoI think you will realize, once you have cooled down a bit, that it is exactly people's awareness of how much it costs to own and drive a car in terms of money and mental peace that drives them to use services like Uber. And yes, I know you were referring to people who drive for Uber. For many people, the process of owning and driving a car doesn't make overall sense, which is why they pay others to do it for them. I don't see anyone complaining about how maids have to, oh my gosh, clean houses.
- Fnoord 9y ago> it is exactly people's awareness of how much it costs to own and drive a car in terms of money and mental peace that drives them to use services like Uber. The point is that its far less profitable than it seems, is very stressful, and has variable (unstable) income which further adds to the stress. See for example Uber The Game [1] based on real life examples. > I don't see anyone complaining about how maids have to, oh my gosh, clean houses. Well, of course they don't complain about that here. That'd be offtopic. Part of the problem with issues like these is that if they don't affect you, why bother caring? Reading about it? Investigating the issue? You're not a maid, so why would you bother? You not enough on your plate as it is making your own deadlines and taking care of your family and and... which creates apathy. I happen to know that regarding maids, and I won't speak for all hotels, but I happen to know from a series called RamBam [2] that at least in 2016 the Bastion and Ibis hotels in Amsterdam, cleaning service profession ("hotel maid") was 1) very stressful 2) paid by amount of rooms being cleared 3) a very low amount of minutes per room is being accounted 4) if you don't make it (setback of any kind), tough luck, you get paid less or you gotta work longer. Its a job you would only get if you can't get any other, and you desperately need the money. The company who hire know that, so the employees get exploited. If that's still the case, if its more widespread, I don't know... Cause what happens all too often in situations like these is when companies have shady, illegal, immoral behavior they resort to ostrich politics until they get exposed and it causes public uproar (in US, as a foreigner, I could think about say, Consumer Reports, or a John Oliver broadcast, or news about X in regular media). Then they start with damage control, but not necessarily with real steps to solve the issue. Just the symptom that the public perceives. Examples of damage control could be empty promises, solving the issue of the specific complaint of that one user, more empty promises, a bunch of excuses, some technicalities or pseudo-intelligent speech, yet more empty promises and excuses, shifting the blame, and all kind of other fallacies. It precisely describes what Uber did until a big change occurred (they got a new CEO). Heck, I've seen Uber employees exercise damage control on HN! Another good example is the #metoo debacles where people deny the allegations until the proof stacked up too high. [1] https://ig.ft.com/uber-game/ https://ig.ft.com/uber-game/ [2] https://nl.wikipedia.org/wiki/RamBam#Seizoen_5 https://nl.wikipedia.org/wiki/RamBam#Seizoen_5 (see 5.2)
- EnFinlay 9y agoOkay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities or b) payout everyone who reports the same vulnerability (make n accounts, report the same thing in each one, get minimum payout * n). I'd say it's off base to say that Hackerone didn't have your back. They were duplicates. No payout. Of course, this does mean taking it on faith from Uber that they WERE aware of these vulnerabilities. For the final report...that's straight bullshit. Did you ask for mediation from HackerOne on that one? Cause if it's an XSS which triggered them to change the code, that deserves a > minimum payout. [1] https://hackerone.com/uber https://hackerone.com/uber
- GregoryVPerry 9y agoIf those were vulnerabilities discovered prior, then surely they could cite to the prior report or an internal ticket to that effect. These weren't previously discovered issues, especially the certificate pinning Surface app one. Their own Bug Bounty Treasure Map specifically states that all requests to that mobile endpoint are certificate pinned, but aren't in the Surface app. But the best part is, when I was reporting various issues to the Bug Bounty, their staff is actively fixing stuff on the backend (I was getting different application responses after the initial report was filed, but only until I gave them more info on the WAF and XSS_Auditor evasion stuff did they finally pull the whole application offline). And then they still didn't pay anything on the bounty. Yeah I sent HackerOne a bunch of mediation requests, each response was a different excuse why they won't get involved with it. My "Signal" is too low or it's within Uber's discretion to close out the reports etc. Then they disabled completely the Uber Report Issue button. Yawn.
- EnFinlay 9y ago> Then they disabled completely the Uber Report Issue button I don't have enough signal to make a report, but the button doesn't 404 for me, so my guess is you've been shadowbanned. > then surely they could cite to the prior report or an internal ticket to that effect Yeah, they should, at least to build the relationship. Public programs have so many erroneous report they probably stopped doing the "nice" thing ages ago. > But the best part is, when I was reporting various issues to the Bug Bounty, their staff is actively fixing stuff on the backend - that XSS issue they were trying to fix on the backend, but without paying anything for the discovery. I was getting different application responses after the initial report, but only until I gave them more info on the WAF and XSS_Auditor evasion stuff did they finally pull the whole application offline. And then still didn't pay. If this is true, that's really bad. I'd be curious to hear the other side of the story if there is one.
- vxNsr 9y agoThis is why I see these programs in general as foolish. Either you're an employee of the company and you're being paid as such or you've got a proper contract that specifies objectives and compensation. But these bounty programs that leave all the power in the hands of the company just aren't really a great idea. I wonder how many times something like this happened and it went unreported because the hacker just didn't want to sink more time into something that clearly wasn't paying out.
- ztjio 9y agoAre you basing this opinion on this one account? I would like to point out that Uber has a history of sleaze and would absolutely not use their behavior to judge any such programs. Are there other well described, similar instances of such poor behavior from legitimate companies? It seems to me that most of the bigger corps offering bug bounties may be paying too little but at least they follow their own rules.
- bangonkeyboard 9y agoKhaos Tian published a writeup a few days ago about how he discovered a wide-open HomeKit vulnerability [0]. He reported it properly months prior, but Apple ignored his followups and was unresponsive. After this extended radio silence, Tian reached out to a media contact. Within hours of being contacted by the website, Apple finally pushed a hotfix for the vulnerability. Apple subsequently denied Tian access to their bug bounty program because going to the press "voided the qualification for the invitation." [1] [0]: https://medium.com/@khaost/your-home-was-not-so-secure-after-all-af52fbd6777c https://medium.com/@khaost/your-home-was-not-so-secure-after... [1]: https://twitter.com/KhaosT/status/943283519119179776 https://twitter.com/KhaosT/status/943283519119179776
- amelius 9y agoI'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
- gaius 9y agohow we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.
- rpmcmurphy 9y ago^^^ What he said. How about "eBay for car rides"
- roywiggins 9y agoIt's not even eBay, since Uber sets the prices.
- Barrin92 9y agoand tightly controls and rates customers and drivers. Think back to the 2014 downgrading of Uber drivers who worked for competing services.
- testouts 9y agoyea make it dude see if its successful , no one is stopping you
- millzlane 9y agoIn Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar off of the ride to encourage reviews. Leave a tip option to give the dollar back if the passenger liked the ride. Baltimore could benefit from this. Cheaper transportation that connects people that is.
- phyzome 9y agoI'm gonna need a response from HackerOne on this one. It's a very bad look for both Uber (yet again) but also HackerOne.
- sxcurity 9y agoHow? These were terrible P5 reports that would get closed as informative in ANY PROGRAM. He has no evidence behind the claims of the "xss" and the "OneLogin bypass" which they would have indeed paid out if it was valid. I'm highly disappointed in people here, geez.
- phyzome 9y agoI'm pretty disappointed too, now that I've seen the actual reports and his awful behavior. :-( No, I was too eager to jump on Uber, here.
- qaq 9y agoWhat is the end game here? There is black market for this stuff and payouts are orders of magnitude higher than the bounty programs, why would they skew things even more in favor of that route by behaving like this is a mystery.
- arkadiyt 9y ago> payouts are orders of magnitude higher than the bounty programs This is mostly false except for a narrow class of products and bug classes. You could get more on the black market for an iOS jailbreak than Apple would pay you, yes. You could not get more on the black market for any of the bugs the author submitted - most likely you wouldn't find a buyer at all.
- qaq 9y agoFor reflection attack you sure would find a buyer at a rate far beyond $500
- kazuki 9y agoUber's response is a joke, but I'm more surprised by how HockerOne is not helpful here. Sure their revenues come from corporations but if they don't maintain healthy community (where hackers get rewarded appropriately) the platform will lose any attraction.
- morganvachon 9y agoMy firing-from-the-hip response is that HackerOne is possibly making more bank from Uber and other big corporate clients in the short term than they would from building an established userbase, and they are going to cash out and dump the project soon. Corporations get what they wanted (effectively free quality pentesting), and HackerOne can run the narrative that it was a "foolish venture" all the way to the bank. But, I'm probably wrong; the company seems to be well financed and has attracted a ton of clients that would be pissed if their investments were to disappear like that. Maybe it's just growing pains combined with fear of pissing off bad actors like Uber. They supposedly have nearly 100,000 active pentesters contracted, so they can stand to lose a little face to keep Uber happy.
- sxcurity 9y agoNo no no no no. What is it that you guys are not understanding about the severity of these reports??? Everyone PLEASE do yourself a favor and familiarize yourself with this: https://bugcrowd.com/vulnerability-rating-taxonomy https://bugcrowd.com/vulnerability-rating-taxonomy All his bugs were trash P5 bugs
- viclou 9y ago3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359 https://hackerone.com/reports/293359
- viclou 9y agoHow does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ (https://hackerone.com/reports/293359#activity-2203160 https://hackerone.com/reports/293359#activity-2203160) > Cute. Big surprise. (https://hackerone.com/reports/293358#activity-2214673 https://hackerone.com/reports/293358#activity-2214673)
- thisisit 9y agonot to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.
- thriftwy 9y agoAre you familiar with the freelancers' concept of "fuck you, pay me"? I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.
- jacquesm 9y agoGiven the nature of the game I'd say that's a mild response. On a scale of 0 to 10 that would rate a 3 or so. If there is one group I'd really avoid pissing off it would be pentesters.
- 9y ago
- circadiam 9y agoThis Uber company makes me so angry. I go to the Hacker News and I always see bad things about them. I just want to scream! What are they even doing for society—aside from employing hundreds of thousands of people and reducing drunk driving deaths. Doesn’t this stupid company realize that there are 500 angry journalists and technologists who don’t care about those two things.
- deleted 9y ago[deleted]
- hackeroneuser 9y agoHere is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report number assigned. If you use HackerOne application frequently (which it does not look like you do), a report number is only assigned if it was submitted by another hacker. There are situations when internal findings are also on process on being fixed. Uber treasure map is simply a guide. If you find something that is bypass of what they said they have, does not mean its an original finding. I work at a company where we have our own security team breaking applications every day. Sometimes hacker submit similar findings that our security team found before. In such cases, if it is a low priority issue, it will take time for us to fix because we do not prioritize it. In that case, a hacker will get a report marked as Duplicate with no report number assigned. For the first three report that is exactly what happened. 2) Personal attack against a employee of a company will not help you anyways. You went after an employee just based on your degree. If you look closely in the industry, it is the matter of experience not degrees. I have worked with colleagues who are way smarter than me in the field and have way more experience. I never judge them based on their degree. 3) I am still not sure about your reflected XSS bug. Were you able to get a XSS actually execute? Seeing reply from Rob makes me thing you probably found a valid xss that works on an old browser. In addition, you also said you gained access to internal uChat: "I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system." but you did not prove that anywhere in your blog so I don't know if that is legit. To conclude, considering the recent media attention at Uber due to security mishaps that occurred before, it seems to me that you are just looking for a media attention. Your title first is clickbait because 3 of your reports are duplicate so I am not sure why you expected any bounty. To make this clear: I am a hacker in the community and an active participant in Uber's bug bounty and also in HackerOne. I have never seen Uber be unfair to hackers in the platform. Hell, to even encourage hackers, they started to pay 500 on triage. That said, I am looking forward to your comment on this and would love to see your discussion on my points listed above.
- 9y ago
- hitekker 9y agoFrom the comments and the article. it seems HackerOne cares for security researcher and white hat hackers insofar as they attract companies to their platform. I guess their apathy makes sense from a short-term, bottom-line perspective, but it still seems a little unseemly. Is there a better alternative to HackerOne for the security community?
- z3t4 9y agoWhat do you expect from a company who's motto is "always be hustlin" !?
- tyingq 9y agoThis seems like it will self correct. Get a reputation for not paying, and now you have skilled adversaries with a grudge to settle. Bug bounties aren't the only way to monetize this particular skill set. Or maybe getting paid becomes less important than getting even.
- deleted 9y ago[deleted]
- meritt 9y agoOP needs to learn the difference between poor application design and exploitable bugs.
- dickbasedregex 9y agoWith all the horror stories I've been reading since the 90's I'd never help any company like this (again). Discover a vulnerability and get sued or punished. Fix their bugs for them, get nothing for doing their job for them. I remember contributing to BigCommerce's crappy software just because I needed it to actually do it's job (despite the fact that my boss was paying their enterprise rate). I got shitty responses from their devs and nothing got fixed when I forked and submitted patches. I kept and then hid my working fork and never looked back. Yeah, a company can fix it's own problems. Open source, perhaps... Helping a profitable business for nothing? Never again.
- sxcurity 9y agoI agree w/ Uber on these bugs, they're trash and would be considered informative by almost every program
- eXpl0it3r 9y agoSo what protects HackerOne users from companies claiming that every report is a known issue and not paying anything out ever?
- unitboolean 9y agoYep, hackerone lost any credibility to me
- kindawinda 9y agoevery character you write is worth less than $0 due to your inabality to collect your bismal worth.
- sxcurity 9y agoPosted this as a response on Medium but got blocked cause I guess he just wants yes men around lol: “I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system.” Where’s the proof? I don’t see any whatsoever. I highly doubt that you were actually able to bypass the OneLogin because if you did, they’d definitely pay out and it’d be an actual issue rather than some crappy bugs. Lack of certificate pinning IS NOT a critical issue. Critical issues are code execution, file read, etc. The odds of you actually guessing UUIDs are super low and pretty difficult, they did the right thing in closing as informative. You’d have to try “~ 10²⁹ values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second.” You claimed their PRNG was broken but had no evidence or support to back it. “Are you seriously the Program Manager for Uber’s Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting?” — you’re a complete moron, glad you know how to personally attack people, Uber definitely had the right to ban you from their program. Programs CANNOT delete comments from HackerOne Reports (as you claim in https://hackerone.com/reports/293359) Uber DEFINITELY made the right choices in closing your reports as informative, but go ahead, fool yourself
- Klingo 9y agoMore like you got paid $0 for obvious and shit findings along with a crappy attitude.
- lilfatbitch 9y agoThis. Seriously rate limiting??
- wonderingif 9y agoI wonder if this is the same Gregory V Perry who claimed there'd been an attempt to backdoor OpenBSD IPSec code: https://marc.info/?l=openbsd-security-announce&m=129237531405260 https://marc.info/?l=openbsd-security-announce&m=12923753140... Just like this one, his story back then didn't quite add up either.
- Gigablah 9y agoHm, both profiles have one thing in common: VMware training/instruction. You might be on to something.
- samat 9y agoThis looks like a complete failure on HackerOne side - do they care to comment publicly?
- mannykannot 9y agoThis is not just about Uber; it also indicates problems at HackerOne, if this is its response to a mediation request: "we have contacted the Uber App Sec team and they have confirmed with us that these are not security issues that are in scope on their program." Contacting the other party and reporting back what they say is not what is meant by mediation. This is underscored by the next sentence: "I understand that this can be a disappointment but I can assure you that they looked at this report and gave it the proper attention it deserved." [my emphasis.]