Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

181–190 of 562 posts

Re: Instagram's Million Dollar Bug

#181

Earlier quoted context omitted.

What possible motivation did Facebook have for contacting the company with whom this person had a contract employee relationship with, other than to implicitly threaten problems for both? There was no implication that he was doing this other than on his own, and he had cleared it with his employer. Presumably he didn't email Facebook with a corporate email account, and presumably his employer wasn't in a position whe…

> Presumably he didn't email Facebook with a corporate email account "At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes." From Alex Stamos's writeup: https://www.facebook.com/notes/al…

I definitely stand corrected on that point, if it's the case - then calling his employer becomes a reasonable action to take.

Re: Instagram's Million Dollar Bug

#182
post #5

Facebook's calling his employer could be slanderous, possibly even criminal harassment. Between stories like this demonstrating companies' apparent lack of understanding of whitehat infosec, and Weev's incarceration demonstrating the American legal system's apparent lack of understanding of whitehat infosec, it's hard to believe people still participate in such endeavors.

Also remember that the story we have here is a one sided narration from a bug bounty researcher. The story tells us his side of things but what specifically Facebook perceived as threat is still unknown ? Why would a CSO get involved unless they specifically think that the data has been accessed violating the goodwill of the bug bounty research in the first place.

> Why would a CSO get involved unless they specifically think that the data has been accessed...

The most likely reason I can think of is that he was getting some heat from some other C*O.

Edit: Now that Alex's side of the story has been released, his actions don't seem out of line (assuming it's reasonably accurate, and I have no reason to suspect it isn't).

While my explanation is still a valid answer, I agree with the parent. Sounds like he was just doing his job. Though it would be interesting to listen to the audio of the conference call....

Re: Instagram's Million Dollar Bug

#183
post #84

Earlier quoted context omitted.

But that's not going to stop Facebook from publicizing that they will. You're glossing over the details and attributing an aire of "old news" to the bug. Well, yes / no. If he didn't find such an ancient bug but instead someone devious did, they could have dumped all the private user photos. If that happened, what do you think the financial implications might have been?

He got $2500 for that bug. I will venture a guess that that's the most any bug bounty program will pay for that Rails YAML bug in 2015.

How much do you suppose blackhats would pay for instagram's ssl keys, mobile app signing keys, push notification keys, etc?

Yeah, the researcher went deep into the grey area, but I find Alex Stamos's reaction barely short of unbelievable - it's almost as though he's so new to the internet he's never heard of the Streisand Effect... (Either that, or he's just so accustomed to bullying and intimidating people who might embarrass him that he's now got that corrupt politician "Waddaya mean I'm 'abusing my power'? We grant multimillion dollar contracts to old school buddies all the time? What's the problem?" look on his face.)

Re: Instagram's Million Dollar Bug

#184
post #29

Earlier quoted context omitted.

But like he said in the article, he was unable to find a clear policy that gave him the "Stop, no further" point. It may have been a bad assumption to think Facebook was going with the Tumblr stance of "give us a thorough POC," but where should he have drawn the line in his hack and why here instead of where he did?

In the absence of a clear guideline, Researcher101 should kick in; it was clearly the wrong thing to do. An apparent refusal to admit that in the write up is making it hard to put 100% support behind him. There is no excuse: dumping the user table was too far. Facebook went rather far too, of course.

This wasn't the end-users table though, it was the admins table. What if there were a table called "security_keys" - would dumping that be disallowed?

Re: Instagram's Million Dollar Bug

#185

In my opinion, the author is feigning shock... He claims to have downloaded the content listed below. And he is surprised that Facebook responds coldly? Note the string "private keys" in this list... Doesn't the author know how long it will take them to recover from this breech? How much it will cost them? On the other hand, it does sort of re-enforce the idea that he should be paid handsomely, doesn't it? :) * Stati…

>>Doesn't the author know how long it will take them to recover from this breech? How much it will cost them?

Doctor diagnoses, patient has cancer.

Doesn't the doctor know how long the patient will take to recover from this disclosure? How much it will cost the patient?

Re: Instagram's Million Dollar Bug

#186
post #108

Earlier quoted context omitted.

"The Facebook Whitehat TOS explicitly forbid getting sensitive data that is not your own using an exploit." LAUGH.. Where does it say this? https://www.facebook.com/whitehat/ I think instagram should be asking themselves: Would they rather have an honest researcher report this or North Korean hackers not saying anything and just slurping data? Security Researchers are always going to see things they shouldn't. That's…

>If you give us reasonable time to respond to your report before making any information public, AND MAKE A GOOD FAITH EFFORT TO AVOID PRIVACY VIOLATIONS, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you.

Whose privacy did Wes violate? Do webservers have data personal to them?

Re: Instagram's Million Dollar Bug

#188

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

So the bits where you lost the ssl keys, auth cookie keys, app signing keys, push notification keys - and had to ask him (via his employer) about what data he'd accessed are all true? Implying you have no records of who else might have done this and acquired those keys?

Boggle!

Re: Instagram's Million Dollar Bug

#190

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?

> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes.

I feel like that bullet point answers your question pretty well.

Post reply on HN