Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

471–480 of 562 posts

Re: Instagram's Million Dollar Bug

#471

Earlier quoted context omitted.

I never claimed that AWS bucket creds were the same thing as SSL certs.

Then rotating their SSL keys shouldn't be relevant.

Unless I'm misunderstanding, it's relevant because this researcher was able to access (from the blog): -- SSL certificates and private keys, including both instagram.com and *.instagram.com

If this researcher was able to access it via not much more than a hole that was _already reported multiple times_, then I think it's not a stretch to think that [many?] other less honest parties could (and in my opinion most likely do) already have it.

If it was me, even if it's definitely only a single researcher who got access (and it doesn't sound to me like they know for sure - but regardless), something _that_ sensitive would have to be rotated anyways. If it was someone outside the teams that strictly require access to it operationaly, I'd rotate it, let alone outside the company.

Re: Instagram's Million Dollar Bug

#472

Earlier quoted context omitted.

This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…

This whole thing is silly. Facebook (or any other tech company) have a lot of flexibility and hardly any accountability in defining what a "million dollar bug" is. You really can't believe they are going to just hand you over 1m because you think it is a 1m bug. It very well may be but in the end facebook will be the one deciding the value of said bug and you will have nothing to do with their decision so assume they…

I don't think he is claiming 1 million for the bugs, he mostly wanted to share the whole story (that title was just to get some eyeballs instead of using maybe "facebook cheated me")

Re: Instagram's Million Dollar Bug

#473
post #160

Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…

Sorry, but being a multi-billion company, pledging $1M bounty and giving only $2500 for a serious bug which could lead to taking control of the whole Instagram is greedy. I can understand why the researcher didn't stop there.

Re: Instagram's Million Dollar Bug

#474
The lessons i learned here are: 1) any RCE vulnerability of Instagram leads to unrestricted access to user data. Facebook knows it, does nothing about it. 2) facebook will not pay you your bug bounty reward, but will complain to your employer.

Re: Instagram's Million Dollar Bug

#475
post #319

Earlier quoted context omitted.

Yes, exactly this. Without escalating an RCE, how would he have been able to expose this absolutely huge flaw? The initial report was inconsequential, but this seems like at the very least a much more than $2500 bug. If things like this are considered "unethical" it kind of makes finding million dollar bugs in a bug bounty close to impossible.

He only got $2500 because the bug had already been reported by others. Most programs pay nothing in that case.

Then the first one to report it should have been paid a lot more than the $2500. The fact is that FB didn't understand the impact of the bug, and it needed Wes to show them how severe the bug was.

And once they knew how severe it was, they ought to have acknowledged the severity and paid him a lot more.

Re: Instagram's Million Dollar Bug

#476

Earlier quoted context omitted.

This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…

This whole thing is silly. Facebook (or any other tech company) have a lot of flexibility and hardly any accountability in defining what a "million dollar bug" is. You really can't believe they are going to just hand you over 1m because you think it is a 1m bug. It very well may be but in the end facebook will be the one deciding the value of said bug and you will have nothing to do with their decision so assume they…

Sure, they'll be the one deciding. Except, that other bounty hunters are watching their reaction and their fairness in paying out people for their work.

The next $1M bug that gets discovered will probably go out onto the black market because of Mr. Alex's actions here.

Re: Instagram's Million Dollar Bug

#477
post #392

Earlier quoted context omitted.

This isn't all that complicated, as far as I can tell. Guy discloses a vulnerability. He knows it potentially has wide reaching security concerns, and downloads enough data to prove that if necessary. Guy gets shortchanged on the bounty, indicating that either a) facebook is trying to shortchange him, or b) facebook doesn't realize how big of a vulnerability this truly is Everything about Facebook's response indicate…

Guy discloses vulnerability. Facebook is not as impressed as guy would have hoped. Maybe it's because he's one of several people to disclose the same vulnerability. Maybe there are just a lot of vulnerabilities (they've paid out 4.3m in bounties). Guy's reaction to rejection: take hostages and threaten Facebook. Facebook moves to defense and cuts guy off. You are not a good neighbor for kidnapping someone's family to…

"Maybe it's because he's one of several people to disclose the same vulnerability"

The thing that gets me about this whole situation is that Facebook either didn't understand the extent of the vulnerability (which seems to be the case to me, and in which case I think Wes Wineberg should have been rewarded far greater than they did for showing them how serious it was, though I wouldn't say this is literally a "million dollar" bug) or they were grossly negligent for not patching it up a lot sooner than they did. They can't have it both ways.

Are they bad at managing their bug bounty program, or just bad at responding to serious security issues? It has to be one or the other.

Re: Instagram's Million Dollar Bug

#478
It's not the main point of the post, which is Facebook's response to the researcher, but I'm really surprised that they're storing unencrypted secret keys and source code on S3. They trust Amazon a lot and have no fear that somebody could eavesdrop Amazon servers (if I were a black hat I'd go for the accounts of the big guys, not for the one of a random guy)

http://www.exfiltrated.com/research-Instagram-RCE.php#One_Ke...

I wonder what any claim of protecting user's privacy is worth when they leave their credentials unprotected in that way.

https://www.instagram.com/about/legal/privacy/

"We use commercially reasonable safeguards to help keep the information collected through the Service secure [...]"

Ops.

I can imagine why they didn't appreciate the efforts of the researcher. Hopefully they'll change their current practices.

Re: Instagram's Million Dollar Bug

#479
post #431

Earlier quoted context omitted.

This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…

"With the newly obtained AWS key... I queued up several buckets to download, and went to bed for the night." He definitely took data off of Facebook's server. Also you misunderstand his access being denied was a firewall change earlier in his story. This was merely to speculate other systems he could have penetrated--completely separate from the S3 buckets he took data from. From Facebook's perspective it could very…

No. The question is whether FB understood the severity of the bug and paid in proportion to its severity. When you run a bounty program, that's what you do.

Re: Instagram's Million Dollar Bug

#480
post #348
post #160

Summarizing what I've seen here in analogy form: Researcher: "I found a way to unlock your door" Facebook: "Thanks, here's $2500. We've now fixed the problem." Researcher: "Oh, BTW when I unlocked your door I rifled through your stuff and found your passport, your banking details, and a lot of personal information. I've kept copies of these. I also found the keys to your car and looked inside, where I found a box in…

Oh by the way, when I looked in your open front door, I noticed all your computer terminals had their passwords written on post-it notes by their monitors, and the big safe in the back room had its key hanging right next to it on a chain.

[deleted]
Post reply on HN