Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

341–350 of 562 posts

Re: Instagram's Million Dollar Bug

#341

Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…

> I never contacted Facebook or Alex using my work email account. It was only after Alex contacted my employer via email that I sent a reply from my work account. Alex indirectly contacted me at work, not the other way around.

From Wes's blog post.

I don't know anything about security or about the people involved. But I read your quote, and I read the one above.

Unless Stamos explicitly disagrees with Wes's timeline of events, my interpretation of 'he has interacted with us using a synack.com email address' does not explicitly state that Wes used it in relation to the attack before the phone call to the CEO.

Happy for more evidence to be presented to show the contrary.

Re: Instagram's Million Dollar Bug

#342
post #320
post #277

Earlier quoted context omitted.

I'm not sure you understand how the law works

I'm not sure anyone really understands how the law works when it comes to bug bounty programs and legal retaliation by companies. Is there any case law precedent yet?

Especially when Facebook expressly authorizes this type of activity (to some degree). The relevant passage is cited in the original article.

Re: Instagram's Million Dollar Bug

#343
post #172
post #126

Earlier quoted context omitted.

As someone outside the infosec industry, I think the dissonance I feel reading this comes from this line: "[Alex] then explained that the vulnerability I found was trivial and of little value" coupled with the fact that he seemed to be very worried about the problems that could be caused by the author in exploiting it. Something seems amiss.

I feel he meant the original RCE Ruby bug which then allowed all this extra access. It was not some huge, architecture-changing security problem, just a simple upgrade to fix.

Nothing in here is exactly wrong, but we do have to acknowledge that this whole back and forth has essentially informed everyone that:

Facebook considers the keys to their kingdom to be worth $2,500. OR Facebook doesn't know what the keys to it's kingdom look like.

Facebook will not update keys/credentials even if they are known to be compromised.

If you have the keys to the kingdom, you can use them and Facebook won't find out about it unless you tell them.

Re: Instagram's Million Dollar Bug

#344
post #235

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

I think the root cause of the problem is the unclear policy by FB. Privilege escalation can be hard to catch, and can be a separate bug in and of itself, even if it requires a separate exploit to get the initial privileges. The published policy didn't say anything about not doing what he did. I'm not going to argue that what he did should or shouldn't be ok, but FB has no control over what other people do. Yeah, mayb…

I would have come here to say this if you had not said it already.

A major root cause is that the published guidelines say nothing directly about exfiltrating sensitive data. This leads to legitimate confusion for exactly the reasons given. The actual policies make sense given what the published guidelines say, but that's not good enough.

The policy needs to be changed. Not by much, but it needs changing. Here is a Responsible Disclosure Policy that might work better than your current one:

We expect to have a reasonable time to respond to your report before making any information public, and not to be put at any unnecessary risk from your actions. Specifically you should avoid invading privacy, destroying data, interrupting or degrading services, and saving our operational data outside of our network. We will not involve law enforcement or bring any lawsuits against people who have followed these common sense rules.

Re: Instagram's Million Dollar Bug

#345

Earlier quoted context omitted.

You're perfectly right, but his employer didn't need to hear it. And that's the whole crux of the matter.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO.

Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.

Re: Instagram's Million Dollar Bug

#347

Sort of an interesting conflict these bug bounties create. You have someone who wants to hack as deeply as possible to have a bigger bug bounty based on stated rules, but at the same time they will invalidate your bounty if they arbitrarily determine it as too much? I imagine the initial report by his friend that the server was accessibly would not be a very high paying bounty compared to one accessing the server. Bu…

Exactly how I see it. People want a higher bounty, and are also curious of any more bugs deeper. But companies want them to stop at the first layer. It seems too difficult to define how deep is too deep, especially since at least he reported him doing it. He didn't decide to go that deep and then just report the RCE and collect $10 million from people far more interested in this.

Not only that, but dangling the $1 million bounty means they are encouraging the bounty hunters to try to make it larger. And ultimately it also leaves them in a position to find out how big it is (for whatever negotiations) and prove it to the company (in order to make an argument to its magnitude).

Re: Instagram's Million Dollar Bug

#348
post #160

Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…

   Oh by the way, when I looked in your open front door, I noticed all your 
   computer terminals had their passwords written on post-it notes by their 
   monitors, and the big safe in the back room had its key hanging right 
   next to it on a chain.

Re: Instagram's Million Dollar Bug

#349
post #276

Earlier quoted context omitted.

Do you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.

> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.

I don't see that as uncivil or a personal attack. It's either a reasonable direct question or a rhetorical one. And as a rhetorical question, it's not a personal attack, but rather makes the point that other posts seem to damage his credibility.

Re: Instagram's Million Dollar Bug

#350

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

At this point, it was reasonable to believe that Wes was operating on behalf of Synack. Huh? how did you make this connection? Why would he then report his findings to you? From my point of view, contacting his employer was clearly meant as a gut punch.

This section was 100% written by a lawyer, and is intended to sound obvious without in fact being obvious at all.
Post reply on HN