Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

171–180 of 562 posts

Re: Instagram's Million Dollar Bug

#171
post #149

Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…

Assuming that's true (and I personally don't believe Stamos would flagrantly fabricate a detailed story like this publicly), this is a game changer. It's fully reasonable to escalate to an employer if they seem to be affiliated with the security researcher's report. Also worth noting that this is frequently done in the security industry - folks will often credit not only themselves but also the companies they work wi…

No, Alex just assumed. Why didn't he just ask Wes if he was doing this for Synack?

Re: Instagram's Million Dollar Bug

#172
post #126
post #69

As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…

As someone outside the infosec industry, I think the dissonance I feel reading this comes from this line: "[Alex] then explained that the vulnerability I found was trivial and of little value" coupled with the fact that he seemed to be very worried about the problems that could be caused by the author in exploiting it. Something seems amiss.

I feel he meant the original RCE Ruby bug which then allowed all this extra access. It was not some huge, architecture-changing security problem, just a simple upgrade to fix.

Re: Instagram's Million Dollar Bug

#173

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?

Yeah, why not just a quick email- "Hey are you working for Synack here or independently?"

Re: Instagram's Million Dollar Bug

#174

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Thank you for the response, Alex, especially the details about the researcher's email address and affiliation. It makes your actions seem reasonable, in my opinion. As a security researcher, I personally would not be dissauded from reporting to the Facebook Whitehat program due to this incident.

I'm glad companies can offer transparency like this.

Re: Instagram's Million Dollar Bug

#175
post #167

Earlier quoted context omitted.

Alex has been a vulnerability research since the 1990s, and co-ran iSEC Partners, one of the best-known software security firms in the world, through the 2000s. I'm pretty sure they're on top of the key situation.

A lot of things has changed since 1990...

Yes, that's true, and Alex is one of the reasons they've changed.

Re: Instagram's Million Dollar Bug

#176
post #71
post #62

Earlier quoted context omitted.

Is this not the point of a Whitehat bounty program? To entice someone to discover and disclose a bug in a trustworthy manner? If they react this way, and can't trust people to attempt to find exploitable security holes on their system (even those that yield private keys), then what is the point at all? The only people that find them then, are not going to be as cooperative about it. > Doesn't the author know how long…

No, this is not the point of bug bounties. The point of a bug bounty is to find and fix bugs. That's why they're called "bug bounties". This person took a bug bounty and ran it as a penetration test. Facebook fixed the one bug he found and paid him for it.

Which is fine. But threatening to call the cops was really bad.

Re: Instagram's Million Dollar Bug

#177

Earlier quoted context omitted.

Severity on a vulnerability assessment is based on the bug itself; it's the severity of the RCE.

Yeah - but it's 100% clear from this that FB wanted to brush the RCE under the carpet with a "not at all severe $2500" classification - without ever admitting to losing their private ssl keys or auth token seeds. He clearly _did_ have a "security vulnerability" that gave him the keys to the kingdom. He knew it, and Facebook know it - and they wanted to pretend it was no big deal. Any bets on how many months till ther…

That certainly is the fun and exciting way to read this story.

Re: Instagram's Million Dollar Bug

#178

Earlier quoted context omitted.

Running a bug bounty is not a suicide pact. A team had to convince a finance group that it was valuable to give money away to people who might be assholes. Bounty hunters are not a community- but if you are a bounty hunter, you should understand that many of your peers are total assholes. The company that wants to pay you a reward has to figure out if you are going to make them regret offering you a reward. There are…

Are you saying that if Wes hadn't pointed it out, than Alex wouldn't have to refresh all those keys? That if Wes hadn't dumped the keys than they were 100% secure?

Good lord no.

I am saying explicitly- Wes went past the point at which he should have stopped.

He also should have known better, and the fact that he didn't is a problem in itself.

Re: Instagram's Million Dollar Bug

#179
post #71
post #62

Earlier quoted context omitted.

Is this not the point of a Whitehat bounty program? To entice someone to discover and disclose a bug in a trustworthy manner? If they react this way, and can't trust people to attempt to find exploitable security holes on their system (even those that yield private keys), then what is the point at all? The only people that find them then, are not going to be as cooperative about it. > Doesn't the author know how long…

No, this is not the point of bug bounties. The point of a bug bounty is to find and fix bugs. That's why they're called "bug bounties". This person took a bug bounty and ran it as a penetration test. Facebook fixed the one bug he found and paid him for it.

Holy christ that is SO wrong. The system should not be so easy to pivot in that way. That was definitely the real bug. If getting the keys to the kingdom is easy as exploiting a trivial bug than Instagram is really really screwed.

As I'm sure it's not the only trivial bug!

Instagram should be thanking Wes for the wakeup call instead of making him the enemy.

Re: Instagram's Million Dollar Bug

#180
post #149

Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…

Assuming that's true (and I personally don't believe Stamos would flagrantly fabricate a detailed story like this publicly), this is a game changer. It's fully reasonable to escalate to an employer if they seem to be affiliated with the security researcher's report. Also worth noting that this is frequently done in the security industry - folks will often credit not only themselves but also the companies they work wi…

Why not ask directly Wes if he is working on the behalf of his company? Seems shady at least to resort immediately to his employer.
Post reply on HN