Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.
>But, hey, it's an airline: releasing software is not exactly their bread and butter. it's not pilots and flight attendants coding that application. they've got an IT department whose bread and butter IS releasing software.
United Airlines Bug Bounty: An experience in reporting a serious vulnerability
41–50 of 80 posts
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#42Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.
Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…
Then again, how hard is it for a company of their size to hire some 1099's for a brief time...
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#43Earlier quoted context omitted.
Bloated beauracracies need agile ways to respond to important situations. Giving them a pass because they are bloated won't make that happen any sooner, and it does need to happen.
Organizations like that have no code hygiene. They have smart talented people that are entrenched in their way of doing things. They don't have the money to throw the code away and start over. They don't have the control to enforce code standards. There are a couple of terrible effects that slow them down. I'll bet you a nickel that the json is generated by a stored procedure. In that kind of environment, you can't r…
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#44Earlier quoted context omitted.
What are some examples of bullshit out-of-scope judgements? Some scope issues are more bullshit than others.
[deleted]
I agree that United's attitude on this is silly.
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#45Earlier quoted context omitted.
You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.
Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#46Earlier quoted context omitted.
[deleted]
Why are you looking for off-site vulnerabilities? Would this be something you did even if they weren't running a bounty? You should be careful testing sites out of scope. The bounty gives you implied permission to test for vulnerabilities on sites in-scope, but "I was just security testing" is demonstrably not sufficient to insulate you from civil litigation or even criminal charges --- you would probably win in cour…
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#47Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.
Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#48Earlier quoted context omitted.
Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…
If they were genuinely behind on patching vulnerabilities, I can sort-of understand. Then again, how hard is it for a company of their size to hire some 1099's for a brief time...
I think the guys over at US could work a bit faster, but I will grant them they aren't exactly in an unregulated industry where they can "challenge the status quo". When kalanick bears down on the red tape, people aren't reminded that taxis were the attack vector of America's biggest security event.
But yeah, out-source it to one of the hundred or so DoD contractors or security professionals allowed to work on something like this, it likely wasn't that big of a job to patch that vuln.
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#49Earlier quoted context omitted.
You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.
Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?
Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability
#50Earlier quoted context omitted.
You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.
Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?
But other than that, there is nothing preventing you from revealing the vulnerability, or worse, selling it on the grey market. The US government is a heavy buyer of vulnerabilities (although usually in applications, not in airline websites).