Earlier quoted context omitted.
How is this unprofessional behaviour ? They are trying to condone the behaviour of data access which in all honesty falls on borderline unethical behaviour. Any professional who participates in any company's bug bounty should respect their rights as well. Whether the keys were accessible and it is a technical blunder is secondary but the action the researcher took a) accessing the data he did not need to b) making th…
I am not saying that the sec researcher is right here. I don't care about him, he is just some random guy who wants publicity. Talking about FB is more interesting because it is a huge public corporation which should behave smartly. But if you want talk ethical/not ethical -- he found a serious problem in their infrastructure. Had he not looked at the data ("respected their privacy") he wouldn't have found it. You ca…
Instagram's Million Dollar Bug
321–330 of 562 posts
Re: Instagram's Million Dollar Bug
#322In general, if you have a green handle, you shouldn't be commenting on things like this. Otherwise we'll have sock puppets galore muddying the waters.
Re: Instagram's Million Dollar Bug
#323Re: Instagram's Million Dollar Bug
#324Re: Instagram's Million Dollar Bug
#325Earlier quoted context omitted.
Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?
> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. I feel like that bullet point answers your question pretty well.
I don't know, if the guy was just shaking them down then maybe trying to get him fired is indeed a reasonable thing to do, but I don't buy that anyone would have just assumed under the circumstances that he was doing all of this on the clock.
Re: Instagram's Million Dollar Bug
#326Earlier quoted context omitted.
Please don't do this here.
Can you please define "this"?
https://news.ycombinator.com/newsguidelines.html
https://news.ycombinator.com/newswelcome.html
We've detached this subthread from https://news.ycombinator.com/item?id=10755067 and marked it off-topic.
Re: Instagram's Million Dollar Bug
#327Wow, arrogance much? "Look at me, I'm the f*cking CSO!!!"
Re: Instagram's Million Dollar Bug
#328Earlier quoted context omitted.
Thanks for the writeup. Based on what you've written, it sounds like you would have been surprised if Facebook had paid $1 million for the original report (and no further nefarious behavior by OP) since it was probably due to a simple oversight, even though it was a RCE that obviously could have been turned into total ownage of instagram. Is that accurate? If so, what class of vulnerability would make you say "Yep th…
There isn't a parallel universe in which this finding is worth $1,000,000. It it was, every pentester in the country is getting way underpaid, because this is not an uncommon pentest finding.
Re: Instagram's Million Dollar Bug
#329Earlier quoted context omitted.
Surely they would have to revoke all the keys anyway as they would have no idea if a blackhat got their first and took the keys before the vulnerability was reported?
According to the timeline, Instagram have known about the ssl keys since 1 Dec. My browser is currently showing an ssl cert for instagram.com that was issued in April and expires on Dec 31. Doesn't look like they're in any hurry to revoke that one. (I guess like Alex Stamos told his employer - it's "trivial and of little value"...)
Re: Instagram's Million Dollar Bug
#330Earlier quoted context omitted.
According to the timeline, Instagram have known about the ssl keys since 1 Dec. My browser is currently showing an ssl cert for instagram.com that was issued in April and expires on Dec 31. Doesn't look like they're in any hurry to revoke that one. (I guess like Alex Stamos told his employer - it's "trivial and of little value"...)
Or, like almost any company that's reasonably competent, they have multiple certificates with different private keys.
Seems … contradictory.