10 ms·
I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal
by oskarsv 6y ago
I wrote that exploit & report. Just some thoughts on comments here.
Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming.
I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money - it was a fun challenge to chain it all together and I learned a lot from it.
The most outrageous part for me was the blog post I discovered by accident - it included no references or mentions (check archive.org). Both of the code snippets there are from my RCE reports. At the same time they were denying my requests for disclosure.
Of course, I understand that coordination mistakes like this happen, so I accept their apology and move on!
Evidence - original RCE video with huge CSS injection overlay: https://www.dropbox.com/s/11pv2ghdkw5g84b/css-rce-overlay.mov?dl=0 https://www.dropbox.com/s/11pv2ghdkw5g84b/css-rce-overlay.mo...
- Yajirobe 6y ago> I find everyone talking about black markets etc. kind of ridiculous. Really? Agreed. Fuck them
- outime 6y agoI haven't said anything about black markets but: >You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money Not me, not you, but many people make it all about money. I don't think it's ridiculous to think that people can have absolutely zero ethics.
- oskarsv 6y agoSure, absolutely they exist. But in my opinion they are the absolute minority. I've been in security for long enough to know that most people are good, otherwise we'd have major problems every day. 99% of people saying something about black markets or govt agencies have never really faced this decision or thought about it for more than 5 minutes. So it was a question - have you REALLY thought about it?
- klyrs 6y agoI'd hypothesize that people are more willing to entertain the profiteering fantasy when they aren't realistically facing the consequences. Also, that people are more willing to be jerks under cloak of anonymity. As you note, perhaps only 1% of people with the drive to find these sploits are going to do something bad with them. That means the extra volume is folks who wish they had such a product to sell on the black market are just jealous wannabes. You can ignore them.
- SXX 6y agoI haven't done any security research for decade, but it was my hobby long ago. While it's not true in every case sometimes finding worthy bug and then successfully exploiting it can literally take weeks of work. Like 14 hours a day work with break for sleep in attempt to solve some puzzle. Usually without any payoff. This is profession where your actual skills mean very little until you do something exceptional to have portfolio or become famous some other way. It's very easy to talk about ethics for people who live in western countries and have easy access to well-paid jobs, but a lot of people didn't have such options. I don't try to justify actual criminals here, but don't be surprised when people sell 0-days to some Israeli companies or NSA-contractors.
- oskarsv 6y agoI don't live in a 'western country' nor do I make anything near a Silicon Valley salary
- SXX 6y agoThen I can just state huge respect to your moral standards and hope you getting paid well enough to continue doing what you do. There still are a lot of people who are not gonna be okay with said situation for long. Anyone can get more cynical and cruel / indifferent with age due to bad experiences: not getting paid well for reported issues, being cheated or getting into legal trouble for "doing the right thing". Some of us really love security research and want to make it their profession, but it's really easy to end up both without stable income or in some kind of trouble. So I think it's important to raise awareness about it in developer community since many people don't understand how much effort is going into being white hat. It's just like the story with OpenSSL before Heartbleed: half of the world used software, but there wasn't even enough funding to pay properly even for single developer.
- kamyarg 6y agoI really hope they amend the bounty paid to actually compensate you for the find. As a slack user, seeing them pay < $2K for RCE report does not make me feel safe. Next person finding something similar might be looking into this and saying "$3K? no thank you, I take the risk of getting caught but being paid fairly." To be clear I am not advocating for this, but it makes me concerned as a user "some people" will be more likely to do it.
- SXX 6y agoThe point is: you don't really need black market or doing anything illegal to being paid fairly for such research. There are plenty of absolutely legal security companies that will pay you 10x for exploit like that and then just gonna sell it to highest bidder (read: all kind of government entities). And yeah those companies in term work for 3-letter agencies and foreign governments. Of course many would consider selling to them unethical, but that would be absolutely legal.
- albntomat0 6y agoAnother likely outcome is that folks aren't going to look at all, or only at a surface level. This leaves low hanging bugs for those with malicious intent to find easily.
- Voliokis 6y agoUnfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value their work appropriately. And frankly, we shouldn't be giving companies a pass for being cheap because "reporting it responsibly" is the right thing to do. These companies are benefiting to a great degree by offloading vital security research onto unaffiliated and unknown third-parties. Your time, as well as the time of any other hacker or researcher, is valuable and needs to be compensated. I don't see why it's fair to any of us that we should have to work for free or for low pay-outs just because we might be doing the right thing. Same goes for any other career that is badly paid just because "they're helping people".
- oskarsv 6y agoI agree with you. It's super low, but I and others will just ignore it in the future and ultimately they lose. However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. I consider bug bounties like competitions. The 'prize money' is defined beforehand. You don't have to compete if you don't want it. You can also compete for the 'notoriety'. Knowing the stakes, do you complain after getting 'first place'? Everything you own or do is only worth as much as someone is willing to pay for it, everything else is just speculation.
- hashkb 6y agoWhat you do, though, is objectively more valuable to Slack than you were paid. They have reframed security as the competition you mention, but the stakes are much higher and they're sidestepping with this issue of "responsible reporting".
- chrisseaton 6y ago> What you do, though, is objectively more valuable to Slack than you were paid. This is a meaningless statement. Obviously all work is more valuable to the company than what they pay you to do the work... otherwise they wouldn't pay you would they? Because they'd get nothing out of it. If your work generates £5 for a company, then why would they pay you £5 or £6 for it? What's in it for them?
- fouc 6y agoOut of curiosity, what do you feel a competitive bug bounty would be for this type of report? It would be interesting if security reporters had a habit of ending their reports with what they feel is the fair market rate.
- krageon 6y ago> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actually pay independent researchers properly. Edit: That's not to say your work wasn't cool btw. It's very admirable for you to view it the way you do.
- namdnay 6y ago> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation
- jcims 6y agoThey can be when they try to live off of bug bounties alone. There are a lot of young folks that try to make this their full time job after some success, then get into a dry spell. The panic robs them of the lateral thinking that brought them to the dance to begin with, and they get into spirals of ravenously hunting simple bugs that end up as dupes and out of scope.
- panpanna 6y ago> They can be when they try to live off of bug bounties alone. I think that's the problem. You shouldn't be entirely dependent on bounty money, because sooner or later you will find a bug that is worth 10x or 1000x on the black market. I have seen white hat bounty hunters go rouge in such situations and entirely blame it on the cheap ass companies that won't offer the "right" amount. Nobody owns you anything, you are doing this mostly for fun. The bounty is just a bonus.
- albntomat0 6y ago> Nobody owns you anything, you are doing this mostly for fun. The bounty is just a bonus. That's missing a key point of the bounty system. Slack and its users are better off that this bug was 1: discovered and 2: responsibly reported. The bounty increases the number of eyes looking, but also incentivizes folks to look into weird crashes or fight through the drudgery of triaging odd behavior. The bug value also shows how much Slack here values their security, and makes me wary of them if I was in the place to be a customer of theirs.
- securitron 6y ago> I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? I work with some security engineers who in previous jobs used to write exploits for the highest bidder. Their stuff ended up being used for exactly this. One of them even told me quite proudly, you know that exploit that was in the news, that was mine. The lack of any ethical framework other than "I want to make as much money as possible" viscerally disgusts me. And there is far too much of this in our industry, it's rife with this sort of ingrained dollar-chasing selfishness with not a care of the consequences. Good on you for taking a positive ethical stand against this. It's very refreshing to hear.
- cutemonster 6y ago> being used for exactly this That refers to "spied upon" or sth like "chopped to pieces"? In which continent?
- hartator 6y agoRead your report and the way you handled things both on technical and human perspective was perfect. Sorry that they made it so difficult to disclose. We are hiring if you ever need a job! https://serpapi.com/team https://serpapi.com/team
- albntomat0 6y ago> I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money - it was a fun challenge to chain it all together and I learned a lot from it. Slack is directly taking advantage of that being the only alternative. You can do whatever you want with the money. However, having a robust bug bounty program ensures a wide range of people are both willing and able to look for and report vulnerabilities. This needs to be a requirement for any large successful company handling a large amount of user data. Slack can definitely afford it, and this can be used against them the next time they report a breach.
- ActorNightly 6y agoDo you have more info on the javascript piece? I cant find docs for those object properties like delegate anywhere
- oskarsv 6y agoThe app has been updated multiple times since, but you can debug Slack and other Electron apps to see the context they are running with. Electron apps merge desktop functionality with web and sometimes it's possible to find abusable functions - e.g. filesystem, leaking dangerous Electron objects etc. In this case it was possible to abuse lack of context isolation to overwrite functionality (first part of the JS exploit). This changed function behaviour to return (leak) a BrowserWindow class (https://www.electronjs.org/docs/api/browser-window https://www.electronjs.org/docs/api/browser-window) when calling window.open(). A BrowserWindow class allows to instantiate a new window with your own security settings :) Some of the current non-standard functions in Slack: https://imgur.com/a/OSjS0kJ https://imgur.com/a/OSjS0kJ More info: https://www.electronjs.org/docs/tutorial/security https://www.electronjs.org/docs/tutorial/security
- vmception 6y ago> Sure the bounty is low, but ultimately it's their money and their decision. Uh lol. Bug bounties gravitate to their market value by showing companies how valuable they actually are and forcing them to learn.
- Mandatum 6y agoI'm so sorry this happened, the CSO reached out and acknowledged the issue which was.. The minimum, but I'd be doing an internal RCA at Slack for how that post made it public without any acknowledgement. Just sucks - marketing, legal, the engineer and peers who reviewed it, security..
- make3 6y agoyour response wrt black markets strikes me as incredibly naive knowing all the crime, murder, gross negligence causing death and corruption there is and has been literally everywhere on the planet, since forever, for money