Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

11–20 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#11
post #5

If true, then Uber dropped the ball again when it came to PR.

When a company does something immoral, why do people always say "well that's bad because it's bad PR"? How about, that's bad because it's immoral?

Morality is a human standard of behavior, corporations are non-human persons.

I realize this can seem like a cynical take, but if you look at the devestation to our planet, and even human life, I think you can see it's an attempt to be accurate, not cynical.

The people who run a corporation can struggle to maintain a moral direction, but that aim is orthogonal to the goals of the firm and when a conflict arises, it's "logical" for the company to replace whoever diverts it from its goal.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#12
Let me get this straight: there's a company built to exploit the ignorance of people of just how much it costs to drive their own car and the complete disregard of law and you thought while they don't respect their drivers and various governing bodies all over the globe they will respect you ?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#13
Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]:

> duplicate -- a vulnerability that has previously been found either internally or via Hackerone

As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities or b) payout everyone who reports the same vulnerability (make n accounts, report the same thing in each one, get minimum payout * n). I'd say it's off base to say that Hackerone didn't have your back. They were duplicates. No payout. Of course, this does mean taking it on faith from Uber that they WERE aware of these vulnerabilities.

For the final report...that's straight bullshit. Did you ask for mediation from HackerOne on that one? Cause if it's an XSS which triggered them to change the code, that deserves a > minimum payout.

[1] https://hackerone.com/uber

Re: I Got Paid $0 from the Uber Security Bug Bounty

#14
This is why I see these programs in general as foolish. Either you're an employee of the company and you're being paid as such or you've got a proper contract that specifies objectives and compensation. But these bounty programs that leave all the power in the hands of the company just aren't really a great idea. I wonder how many times something like this happened and it went unreported because the hacker just didn't want to sink more time into something that clearly wasn't paying out.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#15
post #5

If true, then Uber dropped the ball again when it came to PR.

When a company does something immoral, why do people always say "well that's bad because it's bad PR"? How about, that's bad because it's immoral?

Because immoral actions don't tend to hurt the bottom line, in fact generally the opposite.

Until, that is, someone shines a light on said immoral behavior for the public to see. Then it tends to have an effect, small as it may usually be.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#16

Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.

I assumed that was in response to the whole ransom thing, not directly related to refusing to publish vulns.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#17
post #12

Let me get this straight: there's a company built to exploit the ignorance of people of just how much it costs to drive their own car and the complete disregard of law and you thought while they don't respect their drivers and various governing bodies all over the globe they will respect you ?

The Social Generation loves to do free work!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#18
post #14

This is why I see these programs in general as foolish. Either you're an employee of the company and you're being paid as such or you've got a proper contract that specifies objectives and compensation. But these bounty programs that leave all the power in the hands of the company just aren't really a great idea. I wonder how many times something like this happened and it went unreported because the hacker just didn'…

Are you basing this opinion on this one account? I would like to point out that Uber has a history of sleaze and would absolutely not use their behavior to judge any such programs. Are there other well described, similar instances of such poor behavior from legitimate companies?

It seems to me that most of the bigger corps offering bug bounties may be paying too little but at least they follow their own rules.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#19

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

If those were vulnerabilities discovered prior, then surely they could cite to the prior report or an internal ticket to that effect. These weren't previously discovered issues, especially the certificate pinning Surface app one. Their own Bug Bounty Treasure Map specifically states that all requests to that mobile endpoint are certificate pinned, but aren't in the Surface app.

But the best part is, when I was reporting various issues to the Bug Bounty, their staff is actively fixing stuff on the backend (I was getting different application responses after the initial report was filed, but only until I gave them more info on the WAF and XSS_Auditor evasion stuff did they finally pull the whole application offline). And then they still didn't pay anything on the bounty.

Yeah I sent HackerOne a bunch of mediation requests, each response was a different excuse why they won't get involved with it. My "Signal" is too low or it's within Uber's discretion to close out the reports etc. Then they disabled completely the Uber Report Issue button. Yawn.

Post reply on HN