Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

351–360 of 562 posts

Re: Instagram's Million Dollar Bug

#351

Earlier quoted context omitted.

You're perfectly right, but his employer didn't need to hear it. And that's the whole crux of the matter.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

The Facebook reply does not state that he was using his company email address to report issues or to communicate prior to them reaching out. The researcher says that he only used the email after Facebook got his employer involved.

The Facebook post does not, in any way, contest that.

Re: Instagram's Million Dollar Bug

#352
post #160

Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…

I saw it more like:

  Researcher: "I found a way to unlock your door"

  Facebook: "Thanks, here's $2500. We've now fixed the problem."

  Researcher: "Ohh hey about that bug. Turns out that
 door, if the guys from the Ashley Madison breach found
 first, your entire company would lose billions in market
 cap, you and all your friends would no longer have jobs,
 and the trust placed in your company by the public would
 be so eroded that there's a good chance it would no longer
 exist."

  Facebook: "Well this is embarrassing. Our boss found out
 and talked to your boss, the subject of lawyers and law
 enforcement may have been mentioned in an effort to keep
 this info getting to the public, and when this failed, he
 made a highly visible blog post discrediting your
 professional conduct"

  Researcher: 
You can make the case for misconduct on both sides but I'm more inclined to side with the researcher. If you define bugs and the associated bounty by the amount of possible damage it could cause, this one would definitely be 'catastrophic'. And Facebook would still be none the wiser if he hadn't dug deeper.

Re: Instagram's Million Dollar Bug

#353

Earlier quoted context omitted.

judging by this exploit and the fact that they didn't rotate keys and other folks probably got this data, I would say this wasn't one of their finest moments, wouldn't you agree?

Take the top 10 tech companies on the west coast. Select the most senior security person at those companies. Roll 1d10 and substitute that person for Alex in this exact situation. Now bet your life that you won't have your life wrecked by a prosecutor based on the outcome of that die roll. I don't love Stamos calling the guy's boss, but if it's between "call his boss" and "tell legal that a bounty participant has FUC…

That just sounds like ass covering to me. The fact of the matter is that Alex had no idea and no one at Facebook had any idea if this researcher indeed went rogue with their credentials, because of the lack of security that the hack exposed. No logs on S3 buckets? No separation of access between user data and operations buckets? Give me a break. Calling the guy's boss or the guy himself wouldn't give any authoritative answers as to what's on the researcher's laptop, so I really don't see how calling the researcher's boss was a way out of "telling legal that a bounty participant had THE KEY TO THE KINGDOM BECAUSE CAPS ARE REALLLLLY AWESOME!" If you think that simply calling the guy's boss was the right call and not acknowledging the massive security holes that this guy exposed, then I hope you work for a company that has a more clear bounty program and deal with equally ethical researchers who will tell you about a full systems exploit without violating any user privacy and hope he's happy with your $2500. That will happen..

Re: Instagram's Million Dollar Bug

#354

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

just pay the man, you guys got billions of dollars.

honestly, I've lost all respect I had for you.

Re: Instagram's Million Dollar Bug

#355

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

> The fact that AWS keys can be used to access S3 is expected behavior and would not be considered a security flaw in itself.

A security "mistake" then? :)

Re: Instagram's Million Dollar Bug

#356

Earlier quoted context omitted.

You're perfectly right, but his employer didn't need to hear it. And that's the whole crux of the matter.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

He didn't use his company address until he was contacted through his company.

Re: Instagram's Million Dollar Bug

#357
post #299

Earlier quoted context omitted.

"This bug has been fixed, the affected keys have been rotated, and we have no evidence that Wes or anybody else accessed any user data."

> and we have no evidence that Wes or anybody else accessed any user data This raises way more questions than it answers. Most notably: why aren't you recording who accesses user data?

Reads to me that they are recording the access and no-one did access it.

Re: Instagram's Million Dollar Bug

#358

Earlier quoted context omitted.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO. Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.

I like how we're talking about Stamos warning a guy running around with stolen AWS credentials for all of Instagram in the same fashion as we'd talk about a DMCA threat. "Implicit legal threat"? There's nothing "implicit" or subtle about what was happening here.

Re: Instagram's Million Dollar Bug

#359
post #349
post #276

Earlier quoted context omitted.

> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.

I don't see that as uncivil or a personal attack. It's either a reasonable direct question or a rhetorical one. And as a rhetorical question, it's not a personal attack, but rather makes the point that other posts seem to damage his credibility.

It's obviously not a direct question (there are people defending him in this thread, so of course he "believes" that), and as a rhetorical one it implies that he is lying. That's not a civil debate tactic—there's a reason why parliamentary systems expel people for using it.

Everyone needs to err in favor of respect when addressing someone on the other side of an argument, especially when one's passions are agitated, because the default is to forget all that.

Re: Instagram's Million Dollar Bug

#360

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Yea, wouldn't want to "set a precedent" that infosec researchers will be rewarded for doing the right thing.

Next time someone uncovers your private keys at least they'll know upfront that there is no money in doing the right thing which might just make selling them to the highest bidder seem like a more compelling option.

Post reply on HN