5 ms·
GitHub Account hijack through broken link in developer.twitter.com
- rvz 6y agoThe severity of the bug is around 7 - 8.9 which is very serious and after 3 months of waiting, Twitter gives no bounty. Might as well say that this bounty hunter got scammed and was rewarded with a pat on the back for 'great effort'.
- ganoushoreilly 6y agoExactly, if this doesn't meet the threshold for their bug bounty program, why would anyone submit the bugs? At this point, the bug bounty programs are to encourage fair disclosure to the vendor with an economic reward to deter the other options. I Imagine the researcher could have sold that off to someone for a nice chunk of change.
- tester756 6y agoscammed by twitter?
- jcun4128 6y agoKinda curious people in this line of work. If they prep some automated processes that they've found in the past and then just hit up big names to see if any apply. Then it pings them like "vulnerability found at"... Seems neat
- atarian 6y agoThis seems less serious than the title implies. Basically one of their links went to a 404 on GitHub and the reporter just created an account to catch the click through.
- rognjen 6y agoThe title on HN is misleading yes. But the issue is still serious as the severity in the report indicates.
- londons_explore 6y agoThis is a real issue, and could have affected the security of real users, but I wouldn't fault Twitter for not rewarding this. At the end of the day, they had a hyperlink to an external site (GitHub) which they didn't control. Even if the link went to an official Twitter GitHub account, there is no guarantee GitHub doesn't change its URL structure tomorrow causing that bug again. At the end of the day, when website A links to website B, at least some responsibility goes to the user to check they are where they intend to be.
- stevemk14ebr 6y ago'but I wouldn't fault Twitter for not rewarding this' I would. A researcher who may do this for a living did not get paid for valid work they did. By definition that is a scam. And it flys in the face of what a bug bounty program is supposed to insentivise. Every unpaid report is a signal to not submit other valid bugs, undermining the whole program.