Earlier quoted context omitted.
As someone outside the infosec industry, I think the dissonance I feel reading this comes from this line: "[Alex] then explained that the vulnerability I found was trivial and of little value" coupled with the fact that he seemed to be very worried about the problems that could be caused by the author in exploiting it. Something seems amiss.
I feel he meant the original RCE Ruby bug which then allowed all this extra access. It was not some huge, architecture-changing security problem, just a simple upgrade to fix.
Instagram's Million Dollar Bug
201–210 of 562 posts
Re: Instagram's Million Dollar Bug
#202Re: Instagram's Million Dollar Bug
#203Earlier quoted context omitted.
I certainly wouldn't consider dumping credentials to test for reuse/continued use a privacy violation. If FB wants people not to dump data, they need to make that explicit and specific.
Really? The article states: "To say that I had gained access to basically all of Instagram's secret key material would probably be a fair statement". How on earth would holding on to that data not be a privacy violation?
Re: Instagram's Million Dollar Bug
#204Earlier quoted context omitted.
I'll rephrase the question. Is the broader vulnerability apparent based on the first discovery OR does it only become clear the further down the rabbit hole you get?
I don't know. If we're going to speculate, I'll say: the Facebook security team didn't know this system existed (it's a 3rd party admin console on a public IP address!), and their immediate reaction to it was "nuke it from orbit, pay out the bounty for finding it, and forget about it". My guess is that they discovered the AWS credential thing on December 1.
Re: Instagram's Million Dollar Bug
#205Earlier quoted context omitted.
Holding credentials is not violating privacy. It would be possible to use those credentials to violate privacy, but merely having them is not that act.
Holding sensitive credentials is absolutely a violation of privacy. This is like saying that having a user's password is not a privacy violation unless you use it to gain access to their account.
Re: Instagram's Million Dollar Bug
#206Earlier quoted context omitted.
I would tend to agree. Facebook's point is that he found a vulnerability, and exploited it instead of stopping there. I kind of understand their point of view though. "See you have a vulnerability there, and then I can get access to this, and then this, and see now I have the password of your user, and then I'm just one click away from accessing all the instagram pictures I want." Although Facebook's handling of the…
Exploiting the bug would have been downloading the actual contents of the S3 bucket (the instagram source and other things). He specifically says he did not do that.
> [...] I queued up several buckets to download, and went to bed for the night.
> The next day, I began to go through some of what I'd downloaded, [...]
Re: Instagram's Million Dollar Bug
#207Earlier quoted context omitted.
Holding credentials is not violating privacy. It would be possible to use those credentials to violate privacy, but merely having them is not that act.
Holding sensitive credentials is absolutely a violation of privacy. This is like saying that having a user's password is not a privacy violation unless you use it to gain access to their account.
Re: Instagram's Million Dollar Bug
#208Earlier quoted context omitted.
Yea I did and I realize he got paid out a little, but it was short of the $1 million. I realize a million is a bit unrealistic, but if you're going to make a public statement, at least back it up or prove to the guy why his findings don't constitute a "million-dollar bug". It's not right to just cold-shoulder the guy and hide behind vague rules that were never clearly outlined. In fact, you might even conclude Facebo…
Nobody is going to pay you a million dollars in 2015 for the 2013 Rails YAML bug in a stale server. Nobody is going to pay you a million dollars for a reliable Firefox RCE, and those take months to prove out and develop, and there's a liquid market for them.
Re: Instagram's Million Dollar Bug
#209Earlier quoted context omitted.
Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?
> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. I feel like that bullet point answers your question pretty well.
Re: Instagram's Million Dollar Bug
#210Earlier quoted context omitted.
Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?
> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. I feel like that bullet point answers your question pretty well.