Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

151–160 of 562 posts

Re: Instagram's Million Dollar Bug

#151
post #71

Earlier quoted context omitted.

No, this is not the point of bug bounties. The point of a bug bounty is to find and fix bugs. That's why they're called "bug bounties". This person took a bug bounty and ran it as a penetration test. Facebook fixed the one bug he found and paid him for it.

What is the protocol for assuming that a bug might have previously been exploited and keys already compromised? Is that just not worried about unless they see evidence in logs?

Especially considering Alex Stamos apparently requested reassurance that he _hadn't_ accessed particular classes of data - instead of looking in their own presumably non-existent audit logging of people who've had access to the private keys ssl of instgram.com and *.instagram.com!!!

(Seriously??? That's some world-class enterprise-grade "moving fast and breaking things"...)

Re: Instagram's Million Dollar Bug

#152
post #37

Earlier quoted context omitted.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

To ensure that this person deleted the credentials they had taken from the server they popped with the RCE, obviously. Again: read the timeline. He submitted a finding with AWS creds taken from the server he popped on October 22 --- on December 1, more than a month after Facebook shut the server down . He took AWS creds from a Facebook server and saved them on his laptop for more than a month. WHY?

Surely a competent technology company would realize the using creds that were stored on a known-compromised server is bad and change them immediately, right?

Re: Instagram's Million Dollar Bug

#153
post #69

As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…

Running a bug bounty is not a suicide pact. A team had to convince a finance group that it was valuable to give money away to people who might be assholes. Bounty hunters are not a community- but if you are a bounty hunter, you should understand that many of your peers are total assholes. The company that wants to pay you a reward has to figure out if you are going to make them regret offering you a reward.

There are 4 categories of reporters: great, good, shit and crazy. Again- if you are a reporter, you should be trying to make it easy for the team to distinguish you in one of the first two categories by being simply being polite & respectful.

I will take a side- it's Facebook. Dumping data is the end of the Proof of Concept. Trying to determine if there is more data you can access through a single vulnerability chain is over the line.

Boats sink. The engineers know it. If you sink a boat in order to prove the boat had a hole, you will not get your payout.

And one final thought-

In my experience, bounty hunters almost never realize the full consequences of a vulnerability that receives a reward. Most of the time, the "Bad thing" that they identify is just the tip of the iceberg.

The choices of the researcher reflect inexperience and immaturity. The researcher has a significant misunderstanding about what is happening in the bug bounty marketplace. I think they need to apologize if they want a future in the infosec world.

Publishing this blog post was a huge error. Going to the journalist was another huge error. I don't see how this person could ever be considered employable by a reputable company.

Re: Instagram's Million Dollar Bug

#154

Earlier quoted context omitted.

Alex Stamos' (CSO of Facebook) reply to OP: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

The problem that Alex is skimming over here is that if Wes got access to this data, you have to ask yourself - WHO ELSE GOT THE DATA? If Alex knows anything about his job he should know that he has to refresh all those keys even if Wes didn't report it or say anything. The diff between Wes and everyone else is Wes just explained to Facebook how completely screwed they are. Alex is just pissed because Wes made it blun…

Alex has been a vulnerability research since the 1990s, and co-ran iSEC Partners, one of the best-known software security firms in the world, through the 2000s. I'm pretty sure they're on top of the key situation.

Re: Instagram's Million Dollar Bug

#156

In my opinion, the author is feigning shock... He claims to have downloaded the content listed below. And he is surprised that Facebook responds coldly? Note the string "private keys" in this list... Doesn't the author know how long it will take them to recover from this breech? How much it will cost them? On the other hand, it does sort of re-enforce the idea that he should be paid handsomely, doesn't it? :) * Stati…

> Doesn't the author know how long it will take them to recover from this breech?

I assume Facebook would need to regenerate API keys anyways. Simply showing that author could have accessed the API keys is reason enough to think that he may have even if he claims to not have, or that someone else may have access the API keys.

Re: Instagram's Million Dollar Bug

#157
post #5

Facebook's calling his employer could be slanderous, possibly even criminal harassment. Between stories like this demonstrating companies' apparent lack of understanding of whitehat infosec, and Weev's incarceration demonstrating the American legal system's apparent lack of understanding of whitehat infosec, it's hard to believe people still participate in such endeavors.

Or likely tortious interference - https://en.wikipedia.org/wiki/Tortious_interference

Re: Instagram's Million Dollar Bug

#159
post #92
post #87

Earlier quoted context omitted.

Bug bounty appears to be a misnomer in this instance. Facebook is specifically asking for reports of security vulnerabilities in their policy: > If you believe you have found a security vulnerability on Facebook, we encourage you to let us know right away.[1] Which then begs the question to me: how do you differentiate an acceptable and unacceptable probing of security vulnerabilities when you can't capture the full…

I don't know. I feel bad for Alex but if we want to suggest that Facebook's vulnerability disclosure policy was poorly written, I will ruefully agree. When you stand up a bug bounty program, you are giving strangers permission to do something that they would otherwise be prosecuted for doing. You should be extraordinarily careful when you do that, and your rules of engagement should be crystal clear. These weren't.

EDIT: Having read the CSO's explanation that the guy was using his company work email, it makes more sense why the CSO would contact the company (and explains away the pettiness my comment was referring to)

One thing I notice: if the CSO felt like this person did something grossly illegal and irresponsible, why not go straight to the police? Why instead go to the man's employer and speak passively aggressively?

Paradoxically, contacting the authorities could have helped facebook's argument. It would communicated to the community at large: "Hey Facebook believes it has clear standing to pursue this guy. Maybe, he really did do something wrong."

Instead, what I'm reading is: "Facebook doesn't actually believe what the guy did was illegal per se... but they wanted to spite the guy anyway."

For me, it seems petty.

Re: Instagram's Million Dollar Bug

#160
Summarizing what I've seen here in analogy form:

  Researcher: "I found a way to unlock your door"

  Facebook: "Thanks, here's $2500. We've now fixed the problem."

  Researcher: "Oh, BTW when I unlocked your door I rifled through
    your stuff and found your passport, your banking details, and a
    lot of personal information. I've kept copies of these. I also
    found the keys to your car and looked inside, where I found a box
    in the trunk. That box contained sensitive documents including an
    employee badge / proximity card. I used this card to gain access
    to your workplace. In doing this, I also managed to get into the
    janitor's closet which had a set of keys. I used these keys to
    get access to the complete building and took a look at all the HR
    files and rifled through a bunch of corporate contracts."

  Facebook: 

  Researcher: "Can I have my million bucks now?"
Where the researcher stepped over the line is using the door attack to escalate further attacks. It's little different than finding a way to reliably impersonate Mark Zuckerberg's credentials in such a way that others will 100% believe it. That finding is worthy of a reward. But then using that vulnerability to social engineer others to reveal passwords, using that as a launching point for mounting further attacks is going way too far.
Post reply on HN