Earlier quoted context omitted.
Also remember that the story we have here is a one sided narration from a bug bounty researcher. The story tells us his side of things but what specifically Facebook perceived as threat is still unknown ? Why would a CSO get involved unless they specifically think that the data has been accessed violating the goodwill of the bug bounty research in the first place.
That's true, there could be large portions of the story that are omitted or inaccurate. We may never even get the full story. Assuming the story as stated is truthful or even plausible, what options do whitehat hackers have to defend themselves in such a scenario? I mean the whole point seems to be to try to penetrate a secure system, and the consequences of that action seems to be fairly obvious from the start. If a…
Instagram's Million Dollar Bug
121–130 of 562 posts
Re: Instagram's Million Dollar Bug
#122Earlier quoted context omitted.
But that's not going to stop Facebook from publicizing that they will. You're glossing over the details and attributing an aire of "old news" to the bug. Well, yes / no. If he didn't find such an ancient bug but instead someone devious did, they could have dumped all the private user photos. If that happened, what do you think the financial implications might have been?
He got $2500 for that bug. I will venture a guess that that's the most any bug bounty program will pay for that Rails YAML bug in 2015.
Re: Instagram's Million Dollar Bug
#123Earlier quoted context omitted.
Then threaten him with legal action (not that I necessarily condone this - I will say that I did like your breakdown down thread to providing another perspective and balance). It's neither harassment or slander, but it could be tortious business interference, where one party induces a second party to break a contract with a third party. His contract employers are neither his parents or legal guardians - who have no m…
Do you see what a ridiculous no-win situation this is? Option 1: Call the pentest firm he works for. Option 2: Threaten legal action. Option 3: This dude might still be walking around with god knows what shit he's pulled out of S3 buckets or lord knows what else was accessible with those AWS keys or what other keys were in other S3 buckets or wow i'm having a small panic attack just trying to complete that sentence
Re: Instagram's Million Dollar Bug
#124Earlier quoted context omitted.
I certainly wouldn't consider dumping credentials to test for reuse/continued use a privacy violation. If FB wants people not to dump data, they need to make that explicit and specific.
Really? The article states: "To say that I had gained access to basically all of Instagram's secret key material would probably be a fair statement". How on earth would holding on to that data not be a privacy violation?
Re: Instagram's Million Dollar Bug
#125Earlier quoted context omitted.
But that's not going to stop Facebook from publicizing that they will. You're glossing over the details and attributing an aire of "old news" to the bug. Well, yes / no. If he didn't find such an ancient bug but instead someone devious did, they could have dumped all the private user photos. If that happened, what do you think the financial implications might have been?
He got $2500 for that bug. I will venture a guess that that's the most any bug bounty program will pay for that Rails YAML bug in 2015.
Re: Instagram's Million Dollar Bug
#126As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…
"[Alex] then explained that the vulnerability I found was trivial and of little value"
coupled with the fact that he seemed to be very worried about the problems that could be caused by the author in exploiting it. Something seems amiss.
Re: Instagram's Million Dollar Bug
#127Earlier quoted context omitted.
Do you see what a ridiculous no-win situation this is? Option 1: Call the pentest firm he works for. Option 2: Threaten legal action. Option 3: This dude might still be walking around with god knows what shit he's pulled out of S3 buckets or lord knows what else was accessible with those AWS keys or what other keys were in other S3 buckets or wow i'm having a small panic attack just trying to complete that sentence
Where is option "change the keys that were publicly accessible for who knows how long"?
Re: Instagram's Million Dollar Bug
#128Earlier quoted context omitted.
> The Facebook Whitehat TOS explicitly forbid getting sensitive data that is not your own using an exploit. This seems to be the crux of this whole thing. The article suggests that is not true, including some quotes from what I assume is "The Facebook Whitehat TOS" at [0] along with his interpretation of those quotes. As an unsophisticated person reading through that document, I don't see anything I would describe as…
The "privacy violations" statement is what I was talking about. I suppose you could make an argument that this is not sufficiently explicit for this scenario, but I believe it covers this ground. It is a privacy violation to retrieve sensitive data via an exploit.
Re: Instagram's Million Dollar Bug
#129Re: Instagram's Million Dollar Bug
#130As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…
https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...