Earlier quoted context omitted.
No, it can't be either of those things.
What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…
Instagram's Million Dollar Bug
41–50 of 562 posts
Re: Instagram's Million Dollar Bug
#42Re: Instagram's Million Dollar Bug
#43Re: Instagram's Million Dollar Bug
#44Earlier quoted context omitted.
What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…
To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?
It's neither harassment or slander, but it could be tortious business interference, where one party induces a second party to break a contract with a third party.
His contract employers are neither his parents or legal guardians - who have no more power to "ensure" this as anyone else.
As a corollary to this - this is exactly why it's illegal for debt collectors to call your friends and family to "encourage" them, or you by humiliation, to pay up.
Re: Instagram's Million Dollar Bug
#45So if I'm reading this correctly, this massively compromising attack was made possible by doing a little research? e.g. Knowing about one of the admin services used by Instagram, looking in that admin's public repo, and musing whether Instagram had bothered to change the secret key from the default entry in the repo? We'll probably never see a post mortem on this but it'd be interesting to hear how this got moved to…
Never expose anything that doesn't need to be, SSH tunnels, openvpn... heck, use HTTP authentication wrapped SSL tunnels if you have to. Web servers tend to be more secure than webapps.
Mistakes like this are far too easy to make. So anything that isn't part of your business application needs to be tunneled with authentication or isolated completely.
Re: Instagram's Million Dollar Bug
#46Earlier quoted context omitted.
What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…
Pointing out that this doesn't meet the legal definition of slander or criminal harrassment doesn't mean sticking up for Facebook or defending its motivation.
Re: Instagram's Million Dollar Bug
#47Earlier quoted context omitted.
I don't see anything in the description of that call that qualifies as either slander (which requires a false statement of fact) or harassment (which requires a pattern of repeated contact intended to cause emotional distress).
If bringing unrelated parties to dialogue in the background is not harrasment, then what is? Imagine I will contact your significant other over your comment on HN. Would not you be deeply disturbed even if I do it just once? Bonus points for frivolous legal threats on my side.
Exactly what parent said, " . . . a pattern of repeated contact intended to cause emotional distress". Yes, doing as you said would be deeply disturbing, but it wouldn't be harassment.
Re: Instagram's Million Dollar Bug
#48In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
Alex is good friend of mine and I've known him since college. He's definitely a good guy and understands the ins and outs of security vulnerability research, having done it himself for many years. I'm sure he didn't take the action of calling the researcher's employer lightly, and probably had a really good reason to do so.
There has to be a side of this story we aren't hearing, and probably never will.
Re: Instagram's Million Dollar Bug
#49Earlier quoted context omitted.
To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?
Then threaten him with legal action (not that I necessarily condone this - I will say that I did like your breakdown down thread to providing another perspective and balance). It's neither harassment or slander, but it could be tortious business interference, where one party induces a second party to break a contract with a third party. His contract employers are neither his parents or legal guardians - who have no m…
Option 1: Call the pentest firm he works for.
Option 2: Threaten legal action.
Option 3: This dude might still be walking around with god knows what shit he's pulled out of S3 buckets or lord knows what else was accessible with those AWS keys or what other keys were in other S3 buckets or
wow i'm having a small panic attack just trying to complete that sentence