Live data from Hacker News

United Airlines Bug Bounty: An experience in reporting a serious vulnerability

randywestergren.com

41–50 of 80 posts

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#41
post #15

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

>But, hey, it's an airline: releasing software is not exactly their bread and butter. it's not pilots and flight attendants coding that application. they've got an IT department whose bread and butter IS releasing software.

The point is they don't get sufficient resources to do their job properly because they are seen as a cost center.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#42
post #13

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…

If they were genuinely behind on patching vulnerabilities, I can sort-of understand.

Then again, how hard is it for a company of their size to hire some 1099's for a brief time...

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#43
post #18
post #10

Earlier quoted context omitted.

Bloated beauracracies need agile ways to respond to important situations. Giving them a pass because they are bloated won't make that happen any sooner, and it does need to happen.

Organizations like that have no code hygiene. They have smart talented people that are entrenched in their way of doing things. They don't have the money to throw the code away and start over. They don't have the control to enforce code standards. There are a couple of terrible effects that slow them down. I'll bet you a nickel that the json is generated by a stored procedure. In that kind of environment, you can't r…

Basically it is all the result of aa long series of shortsighted "business decisions" based on simply doing whatever costs the least or brings the least short-term risk at the given time.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#44
post #40
post #37

Earlier quoted context omitted.

What are some examples of bullshit out-of-scope judgements? Some scope issues are more bullshit than others.

[deleted]

Can you escalate one of the 3-rd party vulnerabilities to give you access to something that is in scope?

I agree that United's attitude on this is silly.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#45

Earlier quoted context omitted.

You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.

Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?

Is there a kind of "union" for bug finders, some corporate shell anonymous hackers can hide behind to avoid legal crushes?

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#46
post #38
post #20

Earlier quoted context omitted.

[deleted]

Why are you looking for off-site vulnerabilities? Would this be something you did even if they weren't running a bounty? You should be careful testing sites out of scope. The bounty gives you implied permission to test for vulnerabilities on sites in-scope, but "I was just security testing" is demonstrably not sufficient to insulate you from civil litigation or even criminal charges --- you would probably win in cour…

What are your thoughts on the bug bounties that have extremely limited scopes, considering the in-scope domains typically rely on the out-of-scope parts?

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#47
post #13

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…

He should have worded 'tech savvy terrorists' in his request and the result would have been much different.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#48
post #13

Earlier quoted context omitted.

Let's rephrase your question: "Is six months really unreasonable for an airline to fix a vulnerability that allows customer data to be stolen?" Yes, I would say so.. especially since this is a 'duplicate' meaning that multiple people were already aware of this, and on top of that it seems the only reason it was eventually fixed was because they couldn't delay fixing the problem any more. I don't think anyone would co…

If they were genuinely behind on patching vulnerabilities, I can sort-of understand. Then again, how hard is it for a company of their size to hire some 1099's for a brief time...

About 10 years ago everyone got super sensitive with regards to airline security. So you problem couldn't just let a bunch of craigslist temps come in and apply some patches working on the live system.

I think the guys over at US could work a bit faster, but I will grant them they aren't exactly in an unregulated industry where they can "challenge the status quo". When kalanick bears down on the red tape, people aren't reminded that taxis were the attack vector of America's biggest security event.

But yeah, out-source it to one of the hundred or so DoD contractors or security professionals allowed to work on something like this, it likely wasn't that big of a job to patch that vuln.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#49

Earlier quoted context omitted.

You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.

Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?

There can be a fine line between full disclosure and blackmail. I would be concerned "give me airpoints or else" would go over it.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#50

Earlier quoted context omitted.

You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.

Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?

It sounds like they are disqualified from receiving any rewards any time in the future.

But other than that, there is nothing preventing you from revealing the vulnerability, or worse, selling it on the grey market. The US government is a heavy buyer of vulnerabilities (although usually in applications, not in airline websites).

Post reply on HN