Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
The lesson here is when you find Operations issues (particularly Security Operations) at Facebook don't report them. Those make the CSO look bad directly.
Instagram's Million Dollar Bug
301–310 of 562 posts
Re: Instagram's Million Dollar Bug
#302Earlier quoted context omitted.
Do you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.
> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.
And I am sorry, but after these acts the company has taken, the little bit of trust that was left in the company is gone.
I am sorry if it sounded like a personal attack, that was not intended.
Re: Instagram's Million Dollar Bug
#303Re: Instagram's Million Dollar Bug
#304Earlier quoted context omitted.
There isn't a parallel universe in which this finding is worth $1,000,000. It it was, every pentester in the country is getting way underpaid, because this is not an uncommon pentest finding.
Makes sense, I'm just trying to get a sense of what sort of thing would be worth that much. Obviously only Facebook can answer that for sure. Heartbleed?
I don't believe any company would pay $1M for a bounty on their own systems. Only people who intend to use the vuln, or to fix it as they are the vendor.
Fr a vuln to go for $1M requires "discovering SQL injection"-levels of vuln. MS paid $100K for an entire vuln class for ASLR/DEP bypass discovery, and promptly patched the shit out of it. For a remote vuln class, I could see them paying $1M quite happily to not have all of their products re-owned.
Re: Instagram's Million Dollar Bug
#305Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
OK, so lets look at this - your response showed us one extremaly important issue. No clear rules in your system. Wes actually by exploiting your system, exploited your lack of rules regarding the handling of white hat hackers.
Listen, hacker should exploit ALL possible issues. He exploited your weakest one - the rules behind the system. Close the case - reward him XX,XXX for exploiting weakness in your policy for dealing with white hat hackers, spend another as much to bulletproof your policy. Do not reward him for hacks, that are unethical, as it would be wrong, but do it for the other exposure - small dent on your white hat hacker system.
Re: Instagram's Million Dollar Bug
#306Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Re: Instagram's Million Dollar Bug
#307In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
> I assume the AWS resources have been rekeyed by now It doesn't look like the SSL cert on instagram.com has changed recently, and the pentester specifically claims to have obtained its private key.
Re: Instagram's Million Dollar Bug
#308In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
I think you're right on most points, but after reading the write up and response I do think Alex reached out to the employer first instead of the researcher as an intended act of intimidation. That was a mistake. If it was not done for the purpose of intimidation, then Alex simply would have asked the CEO if the researcher was acting on the company's behalf and after hearing "no" would have ended the call and contact…
Then the CEO is going to contact the researcher and he's screwed either way. God knows what the CEO would have say to the researcher privately. Having a middle man to translate is a bad idea in an emergency.
Let's face it, when you used your work email and made another company paranoid, you are putting people on the spot. Employer needs to know (they have legal responsibility), and given the prior research they did and the researcher's claim, I think the reach out is absolutely correct.
Instgram's infrastructure has flaw. That's bad but everyone's infrastructure has flaw. Shit has to be fixed. Doing more than what was needed is bad. If I am told to stop dumping data, I would stop.
Re: Instagram's Million Dollar Bug
#309Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Sounds like FB acted pretty unprofessionally both in the infrastructure department and in handling of the situation. You had some embarrassing mistakes and instead of acknowledging them you tried to scare the reporter into shutting up and leaving you alone. That part is pretty clear. Whether he violated your rules and how much you pay him I don't care.
Re: Instagram's Million Dollar Bug
#310Earlier quoted context omitted.
Do you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.
> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.