Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…
Assuming that's true (and I personally don't believe Stamos would flagrantly fabricate a detailed story like this publicly), this is a game changer. It's fully reasonable to escalate to an employer if they seem to be affiliated with the security researcher's report. Also worth noting that this is frequently done in the security industry - folks will often credit not only themselves but also the companies they work wi…
Instagram's Million Dollar Bug
171–180 of 562 posts
Re: Instagram's Million Dollar Bug
#172As a security researcher and engineer, I'd like to point out the following, without taking sides: 1. Facebook is not going ballistic because this is a RCE report. They have received high and critical severity reports many times before and acted peaceably, up to and including a prior RCE reported in 2013 by Reginaldo Silva (who now works there!). 2. The researcher used the vulnerability to dump data. This is well know…
As someone outside the infosec industry, I think the dissonance I feel reading this comes from this line: "[Alex] then explained that the vulnerability I found was trivial and of little value" coupled with the fact that he seemed to be very worried about the problems that could be caused by the author in exploiting it. Something seems amiss.
Re: Instagram's Million Dollar Bug
#173Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?
Re: Instagram's Million Dollar Bug
#174Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
I'm glad companies can offer transparency like this.
Re: Instagram's Million Dollar Bug
#175Earlier quoted context omitted.
Alex has been a vulnerability research since the 1990s, and co-ran iSEC Partners, one of the best-known software security firms in the world, through the 2000s. I'm pretty sure they're on top of the key situation.
A lot of things has changed since 1990...
Re: Instagram's Million Dollar Bug
#176Earlier quoted context omitted.
Is this not the point of a Whitehat bounty program? To entice someone to discover and disclose a bug in a trustworthy manner? If they react this way, and can't trust people to attempt to find exploitable security holes on their system (even those that yield private keys), then what is the point at all? The only people that find them then, are not going to be as cooperative about it. > Doesn't the author know how long…
No, this is not the point of bug bounties. The point of a bug bounty is to find and fix bugs. That's why they're called "bug bounties". This person took a bug bounty and ran it as a penetration test. Facebook fixed the one bug he found and paid him for it.
Re: Instagram's Million Dollar Bug
#177Earlier quoted context omitted.
Severity on a vulnerability assessment is based on the bug itself; it's the severity of the RCE.
Yeah - but it's 100% clear from this that FB wanted to brush the RCE under the carpet with a "not at all severe $2500" classification - without ever admitting to losing their private ssl keys or auth token seeds. He clearly _did_ have a "security vulnerability" that gave him the keys to the kingdom. He knew it, and Facebook know it - and they wanted to pretend it was no big deal. Any bets on how many months till ther…
Re: Instagram's Million Dollar Bug
#178Earlier quoted context omitted.
Running a bug bounty is not a suicide pact. A team had to convince a finance group that it was valuable to give money away to people who might be assholes. Bounty hunters are not a community- but if you are a bounty hunter, you should understand that many of your peers are total assholes. The company that wants to pay you a reward has to figure out if you are going to make them regret offering you a reward. There are…
Are you saying that if Wes hadn't pointed it out, than Alex wouldn't have to refresh all those keys? That if Wes hadn't dumped the keys than they were 100% secure?
I am saying explicitly- Wes went past the point at which he should have stopped.
He also should have known better, and the fact that he didn't is a problem in itself.
Re: Instagram's Million Dollar Bug
#179Earlier quoted context omitted.
Is this not the point of a Whitehat bounty program? To entice someone to discover and disclose a bug in a trustworthy manner? If they react this way, and can't trust people to attempt to find exploitable security holes on their system (even those that yield private keys), then what is the point at all? The only people that find them then, are not going to be as cooperative about it. > Doesn't the author know how long…
No, this is not the point of bug bounties. The point of a bug bounty is to find and fix bugs. That's why they're called "bug bounties". This person took a bug bounty and ran it as a penetration test. Facebook fixed the one bug he found and paid him for it.
As I'm sure it's not the only trivial bug!
Instagram should be thanking Wes for the wakeup call instead of making him the enemy.
Re: Instagram's Million Dollar Bug
#180Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…
Assuming that's true (and I personally don't believe Stamos would flagrantly fabricate a detailed story like this publicly), this is a game changer. It's fully reasonable to escalate to an employer if they seem to be affiliated with the security researcher's report. Also worth noting that this is frequently done in the security industry - folks will often credit not only themselves but also the companies they work wi…