5 ms·
3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293358 https://hackerone.com/reports/293
by viclou 9y ago
3 of the bug reports are now publically disclosed:
https://hackerone.com/reports/293358 https://hackerone.com/reports/293358
https://hackerone.com/reports/293363 https://hackerone.com/reports/293363
https://hackerone.com/reports/293359 https://hackerone.com/reports/293359
- viclou 9y agoHow does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ (https://hackerone.com/reports/293359#activity-2203160 https://hackerone.com/reports/293359#activity-2203160) > Cute. Big surprise. (https://hackerone.com/reports/293358#activity-2214673 https://hackerone.com/reports/293358#activity-2214673)
- thisisit 9y agonot to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.
- thriftwy 9y agoAre you familiar with the freelancers' concept of "fuck you, pay me"? I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.
- jacquesm 9y agoGiven the nature of the game I'd say that's a mild response. On a scale of 0 to 10 that would rate a 3 or so. If there is one group I'd really avoid pissing off it would be pentesters.
- jwildeboer 9y agoThe freelancers „fuck you, pay me“ is based on very clear contracts and respectful communication, even when things go bad. This is not what’s happening here AFAICS.
- thriftwy 9y ago"Minimum payout of $500" sounds like a very clear contract. Once they have shadowbanned the author, IMO, any attempt at respectfulness is violated by bug bounty organizers. Maybe there are things more rude than shadowban, but I'm not aware of such.
- jxf 9y agoThe minimum payout is subject to various conditions — for example, not being a duplicate. The author did not meet those conditions, and resorted to personal attacks instead of keeping things professional. Uber has many, many problems as a company, but on this matter I can't say they're in the wrong.
- thriftwy 9y agoWell, it doesn't seem like the last report was a duplicate. The one they failed to recognize as XSS. If they paid for that one there would be no blog post and no name calling.
- deleted 9y ago[deleted]
- itsdrewmiller 9y agoClearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?
- EnFinlay 9y agoIt looks like a "reap what you sow" situation. No one is looking good now.
- chris_wot 9y agoIrrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!
- EnFinlay 9y agoBut that's my point. Of course he deserved a payout if he reported a previously unknown vulnerability. What I'm saying is that he (appears to have) behaved in such toxic way (sow) that someone denied something he deserved (reap). All parties in this are squishy humans with emotions. No one looks good - he doesn't look good for how he behaved/communicationed, Uber doesn't look good for denying the payout on a valid report, and Hackerone doesn't look good for not enforcing a minimum payout on a valid report.
- lordlimecat 9y agoJust because you violate social mores does not entitle someone to violate the terms of their engagement with you.
- sxcurity 9y agoA bunch of P5's that were rightly closed as informative. I completely agree w/ Uber's decisions here...
- 9y ago
- seceng 9y agoThese are low severity reports. The first two require difficult prerequisites for an attacker to exploit, and the last one was not proven to be a security flaw. #293358: it's not ideal that the certificate isn't pinned, but to exploit this an attacker needs to either install their own root certificate on the victim's device, somehow obtain a private key for a certificate already installed, or have a certificate authority misissue a certificate to them for an Uber domain used by the app. #293363: an attacker still needs to acquire the victim's X-Uber-Token somehow for this to be useful. It's also somewhat mitigated by the token being invalidated when the victim changes their password. #293359: as pointed out by Uber, no weaknesses in the token generation algorithm were actually demonstrated, and brute forcing the 2^128 keyspace is infeasible. Also, the rudeness he displayed was petty and unhelpful: > given the fact that at least one of your system architects were apparently high when they designed and implemented your bearer token assignment process > Not completely unexpected though, given the caliber of talent utilized by Uber such as the “security” group that you hail from. You would do well in government security consulting, for sure. > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ All in all, rather a poor result for this vulnerability researcher.