Instagram's Million Dollar Bug
261–270 of 562 posts
Re: Instagram's Million Dollar Bug
#262Earlier quoted context omitted.
Does this have anything to do with the SHA1 sunset on 31 December?
Different key, dude. We rotated what was exposed.
Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits.
EDIT: Clarification, replaced plural you with direct names and better pronouns.
Re: Instagram's Million Dollar Bug
#263Re: Instagram's Million Dollar Bug
#264Earlier quoted context omitted.
In the absence of a clear guideline, Researcher101 should kick in; it was clearly the wrong thing to do. An apparent refusal to admit that in the write up is making it hard to put 100% support behind him. There is no excuse: dumping the user table was too far. Facebook went rather far too, of course.
This wasn't the end-users table though, it was the admins table. What if there were a table called "security_keys" - would dumping that be disallowed?
Re: Instagram's Million Dollar Bug
#265However, the biggest issue I see here is that the author (in their own timeline at the bottom of this post) says that they discovered the AWS keys on October 24, yet they did not report this to Facebook until December 1 (in the meantime, they were having various discussions with Facebook about whether their other submissions were valid). That is seriously concerning behavior, if you find come across some live AWS keys this should be reported immediately, you should absolutely not just sit on them for over a month as if they are some sort of bargaining chip.
Re: Instagram's Million Dollar Bug
#266Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Thank you for the response, Alex, especially the details about the researcher's email address and affiliation. It makes your actions seem reasonable, in my opinion. As a security researcher, I personally would not be dissauded from reporting to the Facebook Whitehat program due to this incident. I'm glad companies can offer transparency like this.
There were other personal attacks in his response that I've talked about here: https://news.ycombinator.com/item?id=10755402
Re: Instagram's Million Dollar Bug
#267In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
I think you're right on most points, but after reading the write up and response I do think Alex reached out to the employer first instead of the researcher as an intended act of intimidation. That was a mistake. If it was not done for the purpose of intimidation, then Alex simply would have asked the CEO if the researcher was acting on the company's behalf and after hearing "no" would have ended the call and contact…
Re: Instagram's Million Dollar Bug
#268In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
I think you're right on most points, but after reading the write up and response I do think Alex reached out to the employer first instead of the researcher as an intended act of intimidation. That was a mistake. If it was not done for the purpose of intimidation, then Alex simply would have asked the CEO if the researcher was acting on the company's behalf and after hearing "no" would have ended the call and contact…
Re: Instagram's Million Dollar Bug
#269Earlier quoted context omitted.
Yes and he got paid for it.
I'm not quite sure I understand your point? Of course he got paid, that's how bug bounties work... that doesn't detract in any way from the point I made above.
Re: Instagram's Million Dollar Bug
#270Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…