Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

1–10 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#3
Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties)

It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest.

I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value? Do you trust their code contributions on OSS to not contain malicious attack vectors?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#7
Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#8
post #5

If true, then Uber dropped the ball again when it came to PR.

When a company does something immoral, why do people always say "well that's bad because it's bad PR"? How about, that's bad because it's immoral?

In my view it's because immorality only really affects a company if it's perceived as immoral (i.e. is a PR issue)
Post reply on HN