Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

41–50 of 562 posts

Re: Instagram's Million Dollar Bug

#41
post #22

Earlier quoted context omitted.

No, it can't be either of those things.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

Pointing out that this doesn't meet the legal definition of slander or criminal harrassment doesn't mean sticking up for Facebook or defending its motivation.

Re: Instagram's Million Dollar Bug

#44
post #37

Earlier quoted context omitted.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?

Then threaten him with legal action (not that I necessarily condone this - I will say that I did like your breakdown down thread to providing another perspective and balance).

It's neither harassment or slander, but it could be tortious business interference, where one party induces a second party to break a contract with a third party.

His contract employers are neither his parents or legal guardians - who have no more power to "ensure" this as anyone else.

As a corollary to this - this is exactly why it's illegal for debt collectors to call your friends and family to "encourage" them, or you by humiliation, to pay up.

Re: Instagram's Million Dollar Bug

#45
post #6

So if I'm reading this correctly, this massively compromising attack was made possible by doing a little research? e.g. Knowing about one of the admin services used by Instagram, looking in that admin's public repo, and musing whether Instagram had bothered to change the secret key from the default entry in the repo? We'll probably never see a post mortem on this but it'd be interesting to hear how this got moved to…

Even if that is the case, why is it exposed to the public? They firewalled it off almost immediately, so I assume it didn't need to be...

Never expose anything that doesn't need to be, SSH tunnels, openvpn... heck, use HTTP authentication wrapped SSL tunnels if you have to. Web servers tend to be more secure than webapps.

Mistakes like this are far too easy to make. So anything that isn't part of your business application needs to be tunneled with authentication or isolated completely.

Re: Instagram's Million Dollar Bug

#46

Earlier quoted context omitted.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

Pointing out that this doesn't meet the legal definition of slander or criminal harrassment doesn't mean sticking up for Facebook or defending its motivation.

I'm not sure whether I'm sticking up for Facebook. I'm not just lawyering this thread. I think, if I was in Alex's shoes, I might have done something similar. I'm very glad I didn't have to make that call myself, because, what a nightmare this is.

Re: Instagram's Million Dollar Bug

#47
post #8

Earlier quoted context omitted.

I don't see anything in the description of that call that qualifies as either slander (which requires a false statement of fact) or harassment (which requires a pattern of repeated contact intended to cause emotional distress).

If bringing unrelated parties to dialogue in the background is not harrasment, then what is? Imagine I will contact your significant other over your comment on HN. Would not you be deeply disturbed even if I do it just once? Bonus points for frivolous legal threats on my side.

"If bringing unrelated parties to dialogue in the background is not harrasment (sic), then what is?"

Exactly what parent said, " . . . a pattern of repeated contact intended to cause emotional distress". Yes, doing as you said would be deeply disturbing, but it wouldn't be harassment.

Re: Instagram's Million Dollar Bug

#48
post #20

In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…

> † (and, to be clear, a friend, though a pretty distant one; I am biased here.)

Alex is good friend of mine and I've known him since college. He's definitely a good guy and understands the ins and outs of security vulnerability research, having done it himself for many years. I'm sure he didn't take the action of calling the researcher's employer lightly, and probably had a really good reason to do so.

There has to be a side of this story we aren't hearing, and probably never will.

Re: Instagram's Million Dollar Bug

#49
post #37

Earlier quoted context omitted.

To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?

Then threaten him with legal action (not that I necessarily condone this - I will say that I did like your breakdown down thread to providing another perspective and balance). It's neither harassment or slander, but it could be tortious business interference, where one party induces a second party to break a contract with a third party. His contract employers are neither his parents or legal guardians - who have no m…

Do you see what a ridiculous no-win situation this is?

Option 1: Call the pentest firm he works for.

Option 2: Threaten legal action.

Option 3: This dude might still be walking around with god knows what shit he's pulled out of S3 buckets or lord knows what else was accessible with those AWS keys or what other keys were in other S3 buckets or

wow i'm having a small panic attack just trying to complete that sentence

Re: Instagram's Million Dollar Bug

#50
post #10
post #4

If accurate, seems like a pretty counterproductive way to handle this.

[deleted]

Precisely - at the very least, taking care before bandying around legal action or calling someone's boss. Even without context, its a pretty weird sequence of events.
Post reply on HN