Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

261–270 of 562 posts

Re: Instagram's Million Dollar Bug

#262

Earlier quoted context omitted.

Does this have anything to do with the SHA1 sunset on 31 December?

Different key, dude. We rotated what was exposed.

Do you believe that after this chain of events anyone still believes your company?

Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits.

EDIT: Clarification, replaced plural you with direct names and better pronouns.

Re: Instagram's Million Dollar Bug

#263
post #242

Earlier quoted context omitted.

Because of the sequence of events that played out...

Yes and he got paid for it.

I'm not quite sure I understand your point? Of course he got paid, that's how bug bounties work... that doesn't detract in any way from the point I made above.

Re: Instagram's Million Dollar Bug

#264
post #29

Earlier quoted context omitted.

In the absence of a clear guideline, Researcher101 should kick in; it was clearly the wrong thing to do. An apparent refusal to admit that in the write up is making it hard to put 100% support behind him. There is no excuse: dumping the user table was too far. Facebook went rather far too, of course.

This wasn't the end-users table though, it was the admins table. What if there were a table called "security_keys" - would dumping that be disallowed?

Yes. As much or more so than an end user table. You can't dump data and use dumped data acquired from a legitimate vulnerability to continue to gain access to additional resources.

Re: Instagram's Million Dollar Bug

#265
When reading the author's article, it would certainly be easy to grab the pitchforks. It is actually a pretty interesting/useful vulnerability that some low-level AWS keys were able to be escalated to some highly privileged keys, and that none of these keys where IP-whitelisted.

However, the biggest issue I see here is that the author (in their own timeline at the bottom of this post) says that they discovered the AWS keys on October 24, yet they did not report this to Facebook until December 1 (in the meantime, they were having various discussions with Facebook about whether their other submissions were valid). That is seriously concerning behavior, if you find come across some live AWS keys this should be reported immediately, you should absolutely not just sit on them for over a month as if they are some sort of bargaining chip.

Re: Instagram's Million Dollar Bug

#266
post #174

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Thank you for the response, Alex, especially the details about the researcher's email address and affiliation. It makes your actions seem reasonable, in my opinion. As a security researcher, I personally would not be dissauded from reporting to the Facebook Whitehat program due to this incident. I'm glad companies can offer transparency like this.

I think his response was too personal. They're both adults, and calling his employing company's CEO to make a point because you can, is to me, way too close for comfort.

There were other personal attacks in his response that I've talked about here: https://news.ycombinator.com/item?id=10755402

Re: Instagram's Million Dollar Bug

#267
post #20

In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…

I think you're right on most points, but after reading the write up and response I do think Alex reached out to the employer first instead of the researcher as an intended act of intimidation. That was a mistake. If it was not done for the purpose of intimidation, then Alex simply would have asked the CEO if the researcher was acting on the company's behalf and after hearing "no" would have ended the call and contact…

Yeah, totally. "I did not threaten legal action against Synack or Wes" Who the f do you think you're kidding, Alex?

Re: Instagram's Million Dollar Bug

#268
post #20

In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…

I think you're right on most points, but after reading the write up and response I do think Alex reached out to the employer first instead of the researcher as an intended act of intimidation. That was a mistake. If it was not done for the purpose of intimidation, then Alex simply would have asked the CEO if the researcher was acting on the company's behalf and after hearing "no" would have ended the call and contact…

[deleted]

Re: Instagram's Million Dollar Bug

#269
post #263

Earlier quoted context omitted.

Yes and he got paid for it.

I'm not quite sure I understand your point? Of course he got paid, that's how bug bounties work... that doesn't detract in any way from the point I made above.

And I don't understand yours. You were concerned about other people other than Wes accessing the same data via the same flaw, Alex said that did not happen.

Re: Instagram's Million Dollar Bug

#270
post #160

Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…

Also note that the second part of this conversation happened over a month after the original report.
Post reply on HN