Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

461–470 of 562 posts

Re: Instagram's Million Dollar Bug

#461
post #276

Earlier quoted context omitted.

Do you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.

> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.

Seems like a reasonable, if rhetorical, question. Hope Alex doesn't complain to his employer about it though ;-P

Re: Instagram's Million Dollar Bug

#463

Earlier quoted context omitted.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO. Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.

I am not sure what part of

"he has interacted with us using a synack.com email address,"

invalidates my reading that he was using his company's email?

Re: Instagram's Million Dollar Bug

#464
post #431

Earlier quoted context omitted.

This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…

"With the newly obtained AWS key... I queued up several buckets to download, and went to bed for the night." He definitely took data off of Facebook's server. Also you misunderstand his access being denied was a firewall change earlier in his story. This was merely to speculate other systems he could have penetrated--completely separate from the S3 buckets he took data from. From Facebook's perspective it could very…

Honestly, I think he did go too far downloading the S3 data, but nothing in their policy stated or implied that was against the rules. He did not violate their written guidelines. And so, Facebook should have paid him (and then changed their policy), even if begrudgingly.

Re: Instagram's Million Dollar Bug

#465

Earlier quoted context omitted.

The "bug" here is that they aren't really keeping track of their AWS buckets and keys at all. Least privilege, access logging, remote IP flagging, etc. These operational failures are ostensibly the responsibility of the CSO. I'm not saying this researcher was 100% in the right, but this is the CSO ass covering. "Don't pay attention to the obvious operational deficits, the problem is the researcher overreaching." A si…

Alex has in the last few months built one of the best teams in application security at Facebook (Facebook security is now seemingly most of O.G. iSEC Partners). I get it, everyone hates big companies and especially Facebook evil Facebook but, come on. They know what they're doing. If you understand how security works inside of big companies, this is a really silly theory to run with. CSOs are happy when shit like thi…

In any case, there is one question remains. How do facebook defines a "million dollar" bug if the security team is not aware of the damage it can do. Since this is not the first time this bug was reported, did they actually give a big bounty to the first person who did the initial report(Given that it can lead to this much damage)? Or just another small bounty saying that it's not a very important security flaw.

Re: Instagram's Million Dollar Bug

#466
post #457
post #438

Earlier quoted context omitted.

> his account on our portal mentions Synack as his affiliation Can someone clarify exactly what portal is referred to here? Is it something besides https://www.facebook.com/whitehat/report/ ? If not, this is a totally bogus excuse.

My gathering from the researcher's post is that facebook requires you to use a personal account. I'm guessing he just had his employer listed on his fb account.

Seems that way, but I wanted to invite anyone who knows more to comment.

Alex's response uses extremely misleading language to justify the employer contact:

  - "account on our portal mentions Synack as his affiliation" amounts to nothing more than "he lists his job on his facebook profile"
  - "he has interacted with us using a synack.com email address" -- OP claims otherwise. Taking OP's word, the use of "has" perhaps prevents this from being an outright lie: yes, as of *right now* he "has" used a synack.com email. But did he before you reached out?
  - "he has written blog posts that are used by Synack for marketing purposes" -- ... and? What does that have to do with anything?
"He listed an employer on his fb profile" is literally their top justification for the supposed belief he was acting on their behalf. Yikes.

Re: Instagram's Million Dollar Bug

#467
post #383

Earlier quoted context omitted.

Correct, the policy isn't clear and needs improvement. The bug bounty's policy definitely falls under the CSO's purview. So even if you approve of Alex's handling of the matter, you can't forgive him for running a sloppy bug bounty program. It's one thing if he claims mea culpa and says we could do better. But there's not one iota of regret, remorse, or apology on not making things more clear in Alex's response. If y…

The policy reads clear enough to me to warrant a huge reward. Adding additional conditions after the fact is dealing in bad faith.

most RCE bugs can be compounded into major data dumps. That doesn't make each individual RCE a million dollar bug.

Re: Instagram's Million Dollar Bug

#468

Earlier quoted context omitted.

No, Alex just assumed. Why didn't he just ask Wes if he was doing this for Synack?

He "assumed" because the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook. He wasn't guessing. He didn't look the guy up on LinkedIn.

> He didn't look the guy up on LinkedIn.

I don't really see how else you can interpret the defense "he has written blog posts that are used by Synack for marketing purposes".

And it's pointed out all over the thread, but no part of "the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook" is uncontested, nor is it supported by the text of Alex Stamos' response. You've just read in what you want to see.

Re: Instagram's Million Dollar Bug

#469

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Sorry Alex, you're in the wrong here. Your threats to go to law enforcement completely undermine the credibility of your bug bounty program. Your publicly calling another professional "unethical" is a serious charge for what is a grey area at best, and the facts and history of issues reported by this person would not lead a reasonable person to conclude malice. And ignoring him but going to his boss, that's just pett…

CXOs do not talk directly to anyone other than CXOs right?

Re: Instagram's Million Dollar Bug

#470

Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…

I agree with what another guy said -- you should do the ethical thing and stay out of it. You're his buddy and have already rallied enough about how he's a Good Guy and was just confused. We get it.
Post reply on HN