Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

491–500 of 562 posts

Re: Instagram's Million Dollar Bug

#491

Earlier quoted context omitted.

If you read the article, his company does security research and found a vulnerability in Hotmail. Plus he was using his company's email address. > At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marke…

The Facebook reply does not state that he was using his company email address to report issues or to communicate prior to them reaching out. The researcher says that he only used the email after Facebook got his employer involved. The Facebook post does not, in any way, contest that.

Technically it doesn't contest that but he uses multiple weak points in bullet prior to the one about contacting the employer's CEO. The intent was clearly to establish that his decision to contact the researcher's employer had merit. It was clearly carefully written so it remained factual while implying things that aren't.

I'm not disagreeing with you, only making it clear that yeukhon was played by Alex exactly as intended so he'd be out there defending him on sites like HN.

Re: Instagram's Million Dollar Bug

#492

Earlier quoted context omitted.

Actually his write up makes pretty clear that he didn't use his company email until after Alex went over his head to the CEO. Second, everything else being equal, Alex going to the CEO without calling or mailing the researcher first was a mistake. Going to someone's boss and saying "please do something, I don't want to get the lawyers involved" IS an implicit legal threat, both to synack and the researcher.

I am not sure what part of "he has interacted with us using a synack.com email address," invalidates my reading that he was using his company's email?

It says nothing about who initiated contact using his company email address. It could have said, "he contacted us using" or "his facebook account was associated with" but instead it says "he has interacted with us using". Sometimes what's not said tells us as much if not more.

Re: Instagram's Million Dollar Bug

#493

The fact that Alex Stamos from Facebook contacted this researchers employer talking about potential lawsuits to threaten the employee via a proxy is probably the single most damning thing in the entire article. That to me is entirely unacceptable, if you want to threaten someone then have your legal team send them a cease and desist. Don't go after their livelihood.

I'm gutted cause of that, i can not believe the FB CSO contacted his employer , it's such a disrespectful thing to do. Another reason to hate facebook.

Re: Instagram's Million Dollar Bug

#495

Earlier quoted context omitted.

If he had told Facebook that at the same time as he reported the credentials he harvested from the database --- which his timeline suggests he could have --- I'd agree with you. But he didn't. He put the credentials in his back pocket so he could pull them out when they suggested he hadn't found his "million dollar bug". And so for a month after they fixed the bug, some fucking rando is walking around with credential…

I think the point is that, after the first bug report those credentials SHOULD NOT WORK because their job should have included revoking ANYTHING that system have access to. How did they know Wes was the first person to find that bug and the linked credentials? So, the fact that those credentials still worked a month later is a HUGE FUCKING DEAL! Alex, the consummate professional, didn't do his job and instead had a k…

Exactly.

Notwithstanding the fact that AWS credentials should be very narrow in scope.

Re: Instagram's Million Dollar Bug

#496

Earlier quoted context omitted.

Honestly, I think he did go too far downloading the S3 data, but nothing in their policy stated or implied that was against the rules. He did not violate their written guidelines. And so, Facebook should have paid him (and then changed their policy), even if begrudgingly.

Here is what's happening right now: FB: He's an experienced bug bounty hunter and should know where reasonable borders are. All the experienced security guys itt: He's an experienced bug bounty hunter and should know where reasonable borders are or at least not pivot/escalate without asking. Also never dump and hold data. Everyone else: What he did isn't technically against the rules FB wrote, so they are screwing hi…

> All the experienced security guys itt...

Ah, so those who disagree are inexperienced? No true scottsman indeed!

Re: Instagram's Million Dollar Bug

#497

Earlier quoted context omitted.

Alex has in the last few months built one of the best teams in application security at Facebook (Facebook security is now seemingly most of O.G. iSEC Partners). I get it, everyone hates big companies and especially Facebook evil Facebook but, come on. They know what they're doing. If you understand how security works inside of big companies, this is a really silly theory to run with. CSOs are happy when shit like thi…

>> Delete the keys or I have to tell legal what's happening. >> The researcher NEEDED TO HEAR THAT. I'm not in security, but from the outside looking in, how things worked out just doesn't smell right. If "the researcher NEEDED TO HEAR THAT" is the priority, then why waste time looking up who the guy works for and calling them instead? The simplest and most obvious way to tell the researcher is to tell him directly i…

My reading of tptacek's subtext is that Facebook wanted to show the researcher that they were really, ALL-CAPS serious, as in "get you fired and ruin-your-livelihood if you don't stop" serious. These mafia tactics are fine because the Facebook CSO "built a good team and knows what he is doing"

Re: Instagram's Million Dollar Bug

#498

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Sorry Alex, you're in the wrong here. Your threats to go to law enforcement completely undermine the credibility of your bug bounty program. Your publicly calling another professional "unethical" is a serious charge for what is a grey area at best, and the facts and history of issues reported by this person would not lead a reasonable person to conclude malice. And ignoring him but going to his boss, that's just pett…

Agreed. You've have quite a list of arguments defending the researcher when only his track record should have been enough to prove his good will. Despite the landslide of evidence of good will, Facebook decided to act in bad faith. Unacceptable, I hope other researchers read and remember this story.

Re: Instagram's Million Dollar Bug

#499

Earlier quoted context omitted.

I get your point in these threads, but unless I'm misunderstanding, who cares about stolen, potentially undeleted Amazon creds? Revoke the key in the portal and be done with it? Given who I'm replying to, I'm assuming that I'm missing some key piece of the puzzle. (And I totally acknowledge it doesn't change the circumstances of what either side has done, I'm just curious)

The point is, having those is a prosecute-able offense, if Facebook chose to prosecute. So it's a big threshold to cross legally, even if not meaningful from a programmer's perspective.

Facebook's terms say they will not prosecute /report whitehats to law-enforcement. Facebook could prosecute, at the price of some goodwill from the security industry (or part of it). I'm sure a competent lawyer to mount a robust defence for the security researcher (beyond reasonable doubt, IMO).

Re: Instagram's Million Dollar Bug

#500
post #398

Earlier quoted context omitted.

Alex has in the last few months built one of the best teams in application security at Facebook (Facebook security is now seemingly most of O.G. iSEC Partners). I get it, everyone hates big companies and especially Facebook evil Facebook but, come on. They know what they're doing. If you understand how security works inside of big companies, this is a really silly theory to run with. CSOs are happy when shit like thi…

> The researcher NEEDED TO HEAR THAT. I don't disagree. But why go through his employer, when they already had a direct line to the researcher himself?

Intimidation.
Post reply on HN