Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

141–150 of 562 posts

Re: Instagram's Million Dollar Bug

#141
post #22

Earlier quoted context omitted.

No, it can't be either of those things.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

> Presumably he didn't email Facebook with a corporate email account

"At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes."

From Alex Stamos's writeup: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Re: Instagram's Million Dollar Bug

#143
post #120

Earlier quoted context omitted.

Really? The article states: "To say that I had gained access to basically all of Instagram's secret key material would probably be a fair statement". How on earth would holding on to that data not be a privacy violation?

Holding credentials is not violating privacy. It would be possible to use those credentials to violate privacy, but merely having them is not that act.

Holding sensitive credentials is absolutely a violation of privacy. This is like saying that having a user's password is not a privacy violation unless you use it to gain access to their account.

Re: Instagram's Million Dollar Bug

#145

Earlier quoted context omitted.

This isn't a single key. It's, like, maybe all the keys? The bad stuff that happened here all happened in a single day, the day that the researcher disclosed the AWS creds for the first time, more than a month after the server he dumped them from was shut down.

I would act as if an unknown malicious party had all the keys at that point. It might not be true, but it might be true .

Oh I 1000% agree about that.

Re: Instagram's Million Dollar Bug

#146
The fact that Alex Stamos from Facebook contacted this researchers employer talking about potential lawsuits to threaten the employee via a proxy is probably the single most damning thing in the entire article.

That to me is entirely unacceptable, if you want to threaten someone then have your legal team send them a cease and desist. Don't go after their livelihood.

Re: Instagram's Million Dollar Bug

#147
post #69

As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…

Alex Stamos' (CSO of Facebook) reply to OP: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

The problem that Alex is skimming over here is that if Wes got access to this data, you have to ask yourself - WHO ELSE GOT THE DATA?

If Alex knows anything about his job he should know that he has to refresh all those keys even if Wes didn't report it or say anything.

The diff between Wes and everyone else is Wes just explained to Facebook how completely screwed they are. Alex is just pissed because Wes made it bluntly clear how much he screwed up.

Re: Instagram's Million Dollar Bug

#149

Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…

Assuming that's true (and I personally don't believe Stamos would flagrantly fabricate a detailed story like this publicly), this is a game changer. It's fully reasonable to escalate to an employer if they seem to be affiliated with the security researcher's report.

Also worth noting that this is frequently done in the security industry - folks will often credit not only themselves but also the companies they work with and are associated with in a security report.

Re: Instagram's Million Dollar Bug

#150
post #15

Note to self: Don't report any chained attacks to any large companies bug bounty programs. Alex Stamos contacting the employer of the bug reporter is completely out of line. This is the fastest and easiest way for Facebook to stop good submissions to their bug bounty program.

[deleted]
Post reply on HN