Live data from Hacker News

United Airlines Bug Bounty: An experience in reporting a serious vulnerability

randywestergren.com

61–70 of 80 posts

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#61

If you've participated in their program, you'll probably find that they have their fair share of issues. This is probably where their delay is coming from (but not a valid excuse). I found two serious problems in less than a hour. I reported the issues to them and was subsequently told that both submissions were out of scope and a firm warning to follow the rules. You're welcome for the free findings.

It's pretty ridiculous that actual problems are "out of scope".

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#62

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

I think bug disclosure should be based on how dangerous it is, not how fast/slow the company is in fixing it. The attackers won't work on the company's own schedule after all.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#63
post #60
post #32

Earlier quoted context omitted.

yes, absolutely. 2 freaked me out the most. I managed to get enterprise github installed, taught people how to use it, set up the client on their computers, pointed them at tutorials, and pestered them regularly. For all that effort, over the 6 months the adoption rate was pretty much just 1 developer in one department - me. It's just so damn hard to get people to change.

I'm in the position of trying to push towards changes just like these- introducing better issue management, team communication. Anyone aware of useful resources on rolling out institutional changes like that?

Yes. See "The Phoenix Project" (book)

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#64
post #49

Earlier quoted context omitted.

Does the company not have any legal recourse against people going public (or threatening to go public) with a bug like this before it's fixed? If not, how is it that United can just mark unfixed bugs "as duplicates" and refuse to pay out for them? Shouldn't all those devs immediately go public with them?

There can be a fine line between full disclosure and blackmail. I would be concerned "give me airpoints or else" would go over it.

There's never really a line between blackmail and anything, only Cantor dust. :/

Blackmail is one of those rare crimes that consist entirely of legal conduct.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#66
post #38
post #20

Earlier quoted context omitted.

[deleted]

Why are you looking for off-site vulnerabilities? Would this be something you did even if they weren't running a bounty? You should be careful testing sites out of scope. The bounty gives you implied permission to test for vulnerabilities on sites in-scope, but "I was just security testing" is demonstrably not sufficient to insulate you from civil litigation or even criminal charges --- you would probably win in cour…

They are not explicit in what domains or ip addresses are in scope. This makes it difficult. You'd expect them to have a list of approved sites for testing.. But they don't (or didn't when I tested.)

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#67
post #20

Earlier quoted context omitted.

[deleted]

You may as well give them an 'fix this or else I go public' with a reasonable deadline then. That's in everybody's interest.

You could, but they have lawyers.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#68

If you've participated in their program, you'll probably find that they have their fair share of issues. This is probably where their delay is coming from (but not a valid excuse). I found two serious problems in less than a hour. I reported the issues to them and was subsequently told that both submissions were out of scope and a firm warning to follow the rules. You're welcome for the free findings.

It's pretty ridiculous that actual problems are "out of scope".

Maybe it is, but given that the original commentor did not describe what the problems were, we have no idea as to their severity.

Re: United Airlines Bug Bounty: An experience in reporting a serious vulnerability

#69

Is six months really unreasonable for a big bloated bureaucracy like United Airlines? I've worked on projects for smaller tech companies with release cycles longer than that. Not defending--obviously they should be set up to be able to put out small emergency fixes quickly especially if they're running a bug bounty. But, hey, it's an airline: releasing software is not exactly their bread and butter.

> Is six months really unreasonable for a big bloated bureaucracy like United Airlines?

It's unreasonable for anyone, no matter how big and bureaucratic they are. The fact that they're bloated and incompetent doesn't excuse their incompetence.

Post reply on HN