Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

131–140 of 562 posts

Re: Instagram's Million Dollar Bug

#132
post #5

Facebook's calling his employer could be slanderous, possibly even criminal harassment. Between stories like this demonstrating companies' apparent lack of understanding of whitehat infosec, and Weev's incarceration demonstrating the American legal system's apparent lack of understanding of whitehat infosec, it's hard to believe people still participate in such endeavors.

Also remember that the story we have here is a one sided narration from a bug bounty researcher. The story tells us his side of things but what specifically Facebook perceived as threat is still unknown ? Why would a CSO get involved unless they specifically think that the data has been accessed violating the goodwill of the bug bounty research in the first place.

He claims he had access to so many credentials. That's a P1 security protocol. You can't just let a manager to handle it. Your executive boss, CSO, has to step in.

Re: Instagram's Million Dollar Bug

#133

Sort of an interesting conflict these bug bounties create. You have someone who wants to hack as deeply as possible to have a bigger bug bounty based on stated rules, but at the same time they will invalidate your bounty if they arbitrarily determine it as too much? I imagine the initial report by his friend that the server was accessibly would not be a very high paying bounty compared to one accessing the server. Bu…

Exactly how I see it. People want a higher bounty, and are also curious of any more bugs deeper. But companies want them to stop at the first layer.

It seems too difficult to define how deep is too deep, especially since at least he reported him doing it. He didn't decide to go that deep and then just report the RCE and collect $10 million from people far more interested in this.

Re: Instagram's Million Dollar Bug

#134
post #69

As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…

I understand how dumping SENSITIVE data can make you a flight risk, but he specifically outlined that he avoided dumping anything sensitive (that is anything directly related to Users and their data). He did dump S3 buckets that had a treasure trove of other files (such as the API keys for the other services and static content), so I guess my question here is at what point does dumping of any kind become bad?

Re: Instagram's Million Dollar Bug

#135
Alex responds:

https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Critically:

At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes.

Alex's timeline seems like it matches what I wrote earlier:

https://news.ycombinator.com/edit?id=10754627

Re: Instagram's Million Dollar Bug

#137

Earlier quoted context omitted.

Where is option "change the keys that were publicly accessible for who knows how long"?

This isn't a single key. It's, like, maybe all the keys? The bad stuff that happened here all happened in a single day, the day that the researcher disclosed the AWS creds for the first time, more than a month after the server he dumped them from was shut down.

I would act as if an unknown malicious party had all the keys at that point. It might not be true, but it might be true.

Re: Instagram's Million Dollar Bug

#139

In my opinion, the author is feigning shock... He claims to have downloaded the content listed below. And he is surprised that Facebook responds coldly? Note the string "private keys" in this list... Doesn't the author know how long it will take them to recover from this breech? How much it will cost them? On the other hand, it does sort of re-enforce the idea that he should be paid handsomely, doesn't it? :) * Stati…

Key quote: "Since the Faceboook Whitehat rules state that researchers need to "make a good faith effort to avoid privacy violations", I avoided downloading any content from those buckets" Listing the contents of the bucket is very different from fetching them. Without listing the contents, he wouldn't know the severity of the vulnerability. There's nothing wrong with that.

While I'm on his side, his wording seems to indicate he did download data from SOME of the buckets, just not those specifically containing user sensitive data.

Re: Instagram's Million Dollar Bug

#140

Earlier quoted context omitted.

But like he said in the article, he was unable to find a clear policy that gave him the "Stop, no further" point. It may have been a bad assumption to think Facebook was going with the Tumblr stance of "give us a thorough POC," but where should he have drawn the line in his hack and why here instead of where he did?

Getting the credentials is clearly enough to prove the point. Digging through user data is just celebrating.

He didn't dig through user data.

60 accounts on the admin console are not users, and he did not touch the buckets with actual user data.

Post reply on HN