Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

521–530 of 562 posts

Re: Instagram's Million Dollar Bug

#521

Earlier quoted context omitted.

How is that a "no true scotsman"? Most people in this thread commenting have not indicated they work in the infosec industry. (For the record, I do, though I'm not sure I'd flatter myself by saying I'm "experienced" exactly.)

The problems I have with your absolute statement: * You are stating that all (not some) experienced security folks are agreeing unanimously. The implication is that those show disagree are not "experienced security guys" (as you called them: "everyone else") - they are the ones who aren't true scotsman * you assume those who don't explicitly indicate that they work in infosec industry do not work in the infosec indus…

I wasn't the one who made the comment you're referring to. I'm just saying there is no evidence of a "no true Scotsman" here, as far as I can tell.

Re: Instagram's Million Dollar Bug

#523
post #422
post #129

Posting this write-up might be the last thing the researcher should have done--from a criminal liability perspective. First, the negative press might serve to piss off Facebook (who could have some perspective we are not privy to here). From Facebook's angle, the criminal aspect here may be a much closer issue, and this write-up could serve as the tipping point. Second, as a party admission, this post is could very w…

I can't see Facebook ever pursuing the criminal angle in this situation. I actually wonder if Alex's boss isn't a little unhappy with his response because it will make people think twice about their bug bounty (just look at the backlash here). The bug bounty was put out there so that people don't use or sell exploits as blackhats.

Facebook doesn't have to "pursue" criminal charges, however. It's the Government that brings criminal charges. In this case, Alex would just be a witness (willing or otherwise) the Government used to produce evidence of the researcher's crime. There is a mistaken understanding that if the "victim" of a crime doesn't "press charges", then there is no criminal liability. However, the "victim" is really only a witness to the actual crime in the eyes of the law. Here, the researcher has arguably confessed to a number of computer crimes, and if a DA/USAO or the DOJ were interested in making a statement, they might have enough evidence to indict the researcher on the strength of this post alone. Facebook, while perhaps not interested in "pressing charges", would have to comply with a criminal investigation here.

Re: Instagram's Million Dollar Bug

#524

Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Couldn't it be argued that instagram's choice to store private keys in a third party system (amazon) is a million(s?) dollar bug?

Re: Instagram's Million Dollar Bug

#525

Earlier quoted context omitted.

Facebook's terms say they will not prosecute /report whitehats to law-enforcement. Facebook could prosecute, at the price of some goodwill from the security industry (or part of it). I'm sure a competent lawyer to mount a robust defence for the security researcher (beyond reasonable doubt, IMO).

You're missing my point and talking about something entirely different from what I'm talking about. I'm not talking about whether Facebook will prosecute and what the consequences of that will be (whether they'll win or lose whatever). I'm just pointing out that taking AWS keys is a big deal , because it's legally a big deal.

Facebook's disclosure policy reads:

>If you give us reasonable time to respond to your report before making any information public, and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you.

IANAL: but it could be argued (in court) that he had Facebook's permission to getting the AWS keys. In his opinion (and mine) he made good faith efforts to avoid privacy violations.

Facebook's official disclosure policy has legal weight. There is legal concept (whose name is escaping me) that could apply that in laymen's terms say the official disclosure policy gives him Facebook's tacit approval - I first heard about it in the Oracle v Google where Google argued a blog post congratulating Google provided tacit approval.

Re: Instagram's Million Dollar Bug

#526

Earlier quoted context omitted.

The problems I have with your absolute statement: * You are stating that all (not some) experienced security folks are agreeing unanimously. The implication is that those show disagree are not "experienced security guys" (as you called them: "everyone else") - they are the ones who aren't true scotsman * you assume those who don't explicitly indicate that they work in infosec industry do not work in the infosec indus…

I wasn't the one who made the comment you're referring to. I'm just saying there is no evidence of a "no true Scotsman" here, as far as I can tell.

apologies - didn't notice you weren't OP. IMO, the "no true Scotsman" is implied (might be unintentional)

Re: Instagram's Million Dollar Bug

#528

Earlier quoted context omitted.

The policy reads clear enough to me to warrant a huge reward. Adding additional conditions after the fact is dealing in bad faith.

most RCE bugs can be compounded into major data dumps. That doesn't make each individual RCE a million dollar bug.

Think about this guy being a Russian hacker and selling the ability to access restricted accounts, pose as Instagram administrator and I assume access user's data freely

Re: Instagram's Million Dollar Bug

#529
post #392

Earlier quoted context omitted.

Guy discloses vulnerability. Facebook is not as impressed as guy would have hoped. Maybe it's because he's one of several people to disclose the same vulnerability. Maybe there are just a lot of vulnerabilities (they've paid out 4.3m in bounties). Guy's reaction to rejection: take hostages and threaten Facebook. Facebook moves to defense and cuts guy off. You are not a good neighbor for kidnapping someone's family to…

This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…

Yeah, Wes looks more credible. FB contacting Synack makes me lose my trust in them for this case

Re: Instagram's Million Dollar Bug

#530

Earlier quoted context omitted.

You're missing my point and talking about something entirely different from what I'm talking about. I'm not talking about whether Facebook will prosecute and what the consequences of that will be (whether they'll win or lose whatever). I'm just pointing out that taking AWS keys is a big deal , because it's legally a big deal.

Facebook's disclosure policy reads: >If you give us reasonable time to respond to your report before making any information public, and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you. IANAL: but it could be argued (in court) that he had Fa…

The part you emphasized is dependent on the first part of that sentence, however. In this hypothetical lawsuit Facebook's lawyers would easily be able argue that they would not have done anything for the initial exploit or even demonstrating that he had recovered valid AWS keys but that attempting to hoover up data from S3, etc. violated the “good faith effort to avoid privacy violations” part.
Post reply on HN