Only the XSS one was a real vulnerability, they should have paid $500 at least for that though.
Client side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.
I Got Paid $0 from the Uber Security Bug Bounty
41–50 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#42I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#43I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#44Earlier quoted context omitted.
Are you basing this opinion on this one account? I would like to point out that Uber has a history of sleaze and would absolutely not use their behavior to judge any such programs. Are there other well described, similar instances of such poor behavior from legitimate companies? It seems to me that most of the bigger corps offering bug bounties may be paying too little but at least they follow their own rules.
Khaos Tian published a writeup a few days ago about how he discovered a wide-open HomeKit vulnerability [0]. He reported it properly months prior, but Apple ignored his followups and was unresponsive. After this extended radio silence, Tian reached out to a media contact. Within hours of being contacted by the website, Apple finally pushed a hotfix for the vulnerability. Apple subsequently denied Tian access to their…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#45I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#46Earlier quoted context omitted.
I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…
That sounds like a great idea, the only point I'd make is that a one time purchase model wouldn't work because you'd have ongoing costs (transaction fees for payments, records you legally have to keep, etc.).
Re: I Got Paid $0 from the Uber Security Bug Bounty
#47Re: I Got Paid $0 from the Uber Security Bug Bounty
#48Earlier quoted context omitted.
Client side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.
Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.
I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#49https://hackerone.com/reports/293358
Re: I Got Paid $0 from the Uber Security Bug Bounty
#50I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.
I thought of an app to facilitate this based off of a review system of past customers. Take a dollar off of the ride to encourage reviews. Leave a tip option to give the dollar back if the passenger liked the ride. Baltimore could benefit from this. Cheaper transportation that connects people that is.