Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

561–562 of 562 posts

Re: Instagram's Million Dollar Bug

#561
post #307

Earlier quoted context omitted.

> I assume the AWS resources have been rekeyed by now It doesn't look like the SSL cert on instagram.com has changed recently, and the pentester specifically claims to have obtained its private key.

a private key. It's not uncommon to have multiple simultaneously-valid certificates for the same domain. I'd argue that it's actually sort of irresponsible and therefore surprising for a site at the scale of Instagram not to, for backup purposes.

but using that private key can still grant him access to someone's traffic to their machines. isn't revocation necessary to imply security in that domain ever again?

Re: Instagram's Million Dollar Bug

#562
post #90

Earlier quoted context omitted.

There isn't a parallel universe in which this finding is worth $1,000,000. It it was, every pentester in the country is getting way underpaid, because this is not an uncommon pentest finding.

> It it was, every pentester in the country is getting way underpaid, because this is not an uncommon pentest finding. No wonder there's a flourishing (and well paying) blackmarket for vulnerabilities. I wonder how much this keys-to-the-kingdom vuln would be worth (Mitm Instagram, bootstrap a botnet, steal celebrity pics, ... the possibilities are endless)

This is no market for these kinds of vulnerabilities at all.
Post reply on HN