Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
"I did say that Wes's behavior reflected poorly on him and on Synack, and that it was in our common best interests to focus on the legitimate RCE report and not the unnecessary pivot into S3 and downloading of data." You lost me at this point. Who do you think you are really?
Instagram's Million Dollar Bug
451–460 of 562 posts
Re: Instagram's Million Dollar Bug
#452Earlier quoted context omitted.
This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…
"With the newly obtained AWS key... I queued up several buckets to download, and went to bed for the night." He definitely took data off of Facebook's server. Also you misunderstand his access being denied was a firewall change earlier in his story. This was merely to speculate other systems he could have penetrated--completely separate from the S3 buckets he took data from. From Facebook's perspective it could very…
The question seems to be if he did it in good faith and within the rules of the bug bounty program.
Re: Instagram's Million Dollar Bug
#453The initial bug in Ruby/Rails is striking in its stupidity.[1] You can send something to Ruby/Rails in a session cookie which, when unmarshalled, stores into any named global variable in the namespace of the responding program . It's not a buffer overflow or a bug like that. It's deliberately designed to work that way . It's like doing "eval" on untrusted input. This was on YC years ago.[2] Why was anything so idioti…
Marshalling bugs in other languages and frameworks: - Java: WebSphere, WebLogic, JBoss, Jenkins : http://foxglovesecurity.com/2015/11/06/what-do-weblogic-webs... . Admittedly most of these are through sidechannels and nothing as obvious as sessions, but it's the same mistake. - Python: https://blog.nelhage.com/2011/03/exploiting-pickle/ . Unpickling got at least Cisco Web Security Appliances: http://tools.cisco.com/s…
Re: Instagram's Million Dollar Bug
#454In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
If you're biased, you should do the ethical thing and stay out of it, honestly. There is a ton of asymmetry here, and you and your Facebook CSO friend are being bullies. This is pretty grey, you don't have first hand knowledge, and obviously Alex can do no wrong in your eyes.
Re: Instagram's Million Dollar Bug
#455Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
According to the rules https://www.facebook.com/whitehat/ "We only pay individuals" Wes COULDN'T have been working for Synack to find bugs as your program doesn't even allow for it.
Re: Instagram's Million Dollar Bug
#456In stories like this, try first to remember that Facebook isn't a single entity with a single set of opinions, but rather a huge collection of people who came to the company at different times and different points in their career. Alex Stamos is a good person† who has been doing vulnerability research since the 1990s. He's built a reputation for understanding and defending vulnerability researchers. He hasn't been at…
If you're biased, you should do the ethical thing and stay out of it, honestly. There is a ton of asymmetry here, and you and your Facebook CSO friend are being bullies. This is pretty grey, you don't have first hand knowledge, and obviously Alex can do no wrong in your eyes.
This reminds me of the illusion of objectivity in journalism. If you pretend to be perfectly objective and unbiased, you're lying.
Re: Instagram's Million Dollar Bug
#457Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…
> his account on our portal mentions Synack as his affiliation Can someone clarify exactly what portal is referred to here? Is it something besides https://www.facebook.com/whitehat/report/ ? If not, this is a totally bogus excuse.
Re: Instagram's Million Dollar Bug
#458Earlier quoted context omitted.
Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO. Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.
I like how we're talking about Stamos warning a guy running around with stolen AWS credentials for all of Instagram in the same fashion as we'd talk about a DMCA threat. "Implicit legal threat"? There's nothing "implicit" or subtle about what was happening here.
Given who I'm replying to, I'm assuming that I'm missing some key piece of the puzzle.
(And I totally acknowledge it doesn't change the circumstances of what either side has done, I'm just curious)
Re: Instagram's Million Dollar Bug
#459Earlier quoted context omitted.
Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?
> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. I feel like that bullet point answers your question pretty well.
Re: Instagram's Million Dollar Bug
#460Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...