Earlier quoted context omitted.
Do you believe that after this chain of events anyone still believes your company? Additionally, I hope that the EU data privacy official is going to take a look at this, as it shows that Facebook improperly secured their systems, and not even properly handled the disclosure of exploits. EDIT: Clarification, replaced plural you with direct names and better pronouns.
> Do you believe that after this chain of events anyone still believes you? Personal attacks, which this crosses into, are not allowed on Hacker News. Please comment civilly or not at all.
Instagram's Million Dollar Bug
461–470 of 562 posts
Re: Instagram's Million Dollar Bug
#462Re: Instagram's Million Dollar Bug
#463Earlier quoted context omitted.
If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…
Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO. Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.
"he has interacted with us using a synack.com email address,"
invalidates my reading that he was using his company's email?
Re: Instagram's Million Dollar Bug
#464Earlier quoted context omitted.
This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…
"With the newly obtained AWS key... I queued up several buckets to download, and went to bed for the night." He definitely took data off of Facebook's server. Also you misunderstand his access being denied was a firewall change earlier in his story. This was merely to speculate other systems he could have penetrated--completely separate from the S3 buckets he took data from. From Facebook's perspective it could very…
Re: Instagram's Million Dollar Bug
#465Earlier quoted context omitted.
The "bug" here is that they aren't really keeping track of their AWS buckets and keys at all. Least privilege, access logging, remote IP flagging, etc. These operational failures are ostensibly the responsibility of the CSO. I'm not saying this researcher was 100% in the right, but this is the CSO ass covering. "Don't pay attention to the obvious operational deficits, the problem is the researcher overreaching." A si…
Alex has in the last few months built one of the best teams in application security at Facebook (Facebook security is now seemingly most of O.G. iSEC Partners). I get it, everyone hates big companies and especially Facebook evil Facebook but, come on. They know what they're doing. If you understand how security works inside of big companies, this is a really silly theory to run with. CSOs are happy when shit like thi…
Re: Instagram's Million Dollar Bug
#466Earlier quoted context omitted.
> his account on our portal mentions Synack as his affiliation Can someone clarify exactly what portal is referred to here? Is it something besides https://www.facebook.com/whitehat/report/ ? If not, this is a totally bogus excuse.
My gathering from the researcher's post is that facebook requires you to use a personal account. I'm guessing he just had his employer listed on his fb account.
Alex's response uses extremely misleading language to justify the employer contact:
- "account on our portal mentions Synack as his affiliation" amounts to nothing more than "he lists his job on his facebook profile"
- "he has interacted with us using a synack.com email address" -- OP claims otherwise. Taking OP's word, the use of "has" perhaps prevents this from being an outright lie: yes, as of *right now* he "has" used a synack.com email. But did he before you reached out?
- "he has written blog posts that are used by Synack for marketing purposes" -- ... and? What does that have to do with anything?
"He listed an employer on his fb profile" is literally their top justification for the supposed belief he was acting on their behalf. Yikes.Re: Instagram's Million Dollar Bug
#467Earlier quoted context omitted.
Correct, the policy isn't clear and needs improvement. The bug bounty's policy definitely falls under the CSO's purview. So even if you approve of Alex's handling of the matter, you can't forgive him for running a sloppy bug bounty program. It's one thing if he claims mea culpa and says we could do better. But there's not one iota of regret, remorse, or apology on not making things more clear in Alex's response. If y…
The policy reads clear enough to me to warrant a huge reward. Adding additional conditions after the fact is dealing in bad faith.
Re: Instagram's Million Dollar Bug
#468Earlier quoted context omitted.
No, Alex just assumed. Why didn't he just ask Wes if he was doing this for Synack?
He "assumed" because the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook. He wasn't guessing. He didn't look the guy up on LinkedIn.
I don't really see how else you can interpret the defense "he has written blog posts that are used by Synack for marketing purposes".
And it's pointed out all over the thread, but no part of "the researcher signed up for the Facebook bounty program as an employee of Synack and used his Synack email to communicate with Facebook" is uncontested, nor is it supported by the text of Alex Stamos' response. You've just read in what you want to see.
Re: Instagram's Million Dollar Bug
#469Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Sorry Alex, you're in the wrong here. Your threats to go to law enforcement completely undermine the credibility of your bug bounty program. Your publicly calling another professional "unethical" is a serious charge for what is a grey area at best, and the facts and history of issues reported by this person would not lead a reasonable person to conclude malice. And ignoring him but going to his boss, that's just pett…
Re: Instagram's Million Dollar Bug
#470Alex responds: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics... Critically: At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. Alex's timeline seems like it matches wha…