3 ms·
Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or
by GregoryVPerry 9y ago
Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.
- sushid 9y agoNot the parent commenter and I get what you mean, but if they state that it's a duplicate issue (and assuming on good faith that it is), doesn't it make sense that they don't pay you out for that? I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.
- chris_wot 9y agoYeah, but we have no idea how long this has been unfixed. I reckon all security bugs not paid out to Uber at this point should just get automatically publicly documented. Also: this is Uber. At this point, they’ve used up all their good faith. I definitely wouldn’t be taking anything they say in good faith - I still haven’t forgotten them threatening a journalist or publicly tracking the ride of a CEO for an entire room of people!
- deleted 9y ago[deleted]