6 ms·
Probably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a go
by jermier 6y ago
Probably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a good 'first responder' when it comes to high-profile exploits of their system.
There was a recent post about some researcher who exposed flaws in Tor's architecture (which allowed third parties to detect Tor traffic easily) and Tor's staff didn't respond; so she published the finding without going through the proper channels, both embarrassing Tor staff, and simultaneously strengthening the Tor network.
The 'I'm going to publish this sploit because you didn't respond' is a good tactic and I want to see more people do it. It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly.
[0] https://www.hackerone.com/ https://www.hackerone.com/
- gruez 6y agodoes hackerone cover social engineering exploits? I doubt it.
- MattGaiser 6y agoThey should. You should get $200 if you can get an employee's password.
- dane-pgp 6y agoI'm wondering what the objection is against this. There might be a conflict of interest in allowing an employee to share a bounty with a friend by giving the friend their password, but the rules of the bounty (and the employment contract) should be able to prevent that scenario. In theory, any sensitive operation (such as changing the email address of a verified account) could be made to require approval from a second (randomly chosen) employee, and that second employee should see a log of recent actions taken by the first employee. An attacker may still manage to avoid raising suspicion for the first few targets, though.
- thaumasiotes 6y ago> You should get $200 if you can get an employee's password. That's never going to fly; all Twitter bounties are multiples of $140.
- jermier 6y agoNot sure, but I hope they do, as it's an often forgotten avenue for exploitation. You can't deny the human factor in a lot of these instances. Humans are humans. Also see: https://en.wikipedia.org/wiki/Human_intelligence_(intelligence_gathering) https://en.wikipedia.org/wiki/Human_intelligence_(intelligen...
- tptacek 6y agoNo.
- btx 6y agoThe following issues are outside the scope of our vulnerability rewards program (either ineligible or false positives): ... - Social engineering of Twitter staff or contractors ... https://hackerone.com/twitter https://hackerone.com/twitter Pretty standard for most if not all of the program rules I have come across.
- Kalium 6y ago> It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly. A lot of the bug bounty programs don't pay as well as using exploits to steal money. Some estimates put this particular breach at having netted upwards of $120k. I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing is in the range of $40k. If you don't think you'll get caught, why would you take the $40k instead of tripling that?
- tptacek 6y agoThe opposite thing is true; people have wildly inflated expectations of how much money marginal bugs like XSS can earn, or even game-over bugs in marginally important applications. And if you're doing the financial comparison, as you note, you have to do it risk-weighted. Your intuitions about the risk of exploiting a vulnerability are likely heavily biased by the fact that most exploitation, or at least most of the exploitation you hear about, is non-monetary. Monetizing an exploit ratchets the risk up significantly.
- Kalium 6y agoI remember being 17. I was spectacularly bad at evaluating risks. You're right - a lot of people who want to file bug bounties overestimate how much marginal ones are worth. At the same time, this scenario suggests to me that bug bounties aren't currently doing a good job of incentivizing people away from attempting to monetize significant exploits and towards more responsible security practices. If we have to depend on the risk analyses of teenagers, we may be in trouble. Which is to say I suspect we have both problems.
- thaumasiotes 6y ago> Some estimates put this particular breach at having netted upwards of $120k. > I don't think I've ever seen a bug bounty that high. The highest I've ever heard of or see documentation describing is in the range of $40k. You're not paying attention. https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1 https://www.microsoft.com/en-us/msrc/bounty-hyper-v?rtc=1
- bawolff 6y agoHe allegedly social engineered access. The vast majority of bug bounties i have seen consider this out of scope. Also do x or i release the sploit could be considered extortion if you word it wrong, and then you are in all sorts of additional trouble
- ggggtez 6y agoIt's evident that it wasn't an exploit. It was just a stolen password of an employee.