Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

51–60 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#51
post #38

Earlier quoted context omitted.

how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.

^^^ What he said. How about "eBay for car rides"

It's not even eBay, since Uber sets the prices.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#52
post #49

3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359

How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this)

> Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ (https://hackerone.com/reports/293359#activity-2203160)

> Cute. Big surprise. (https://hackerone.com/reports/293358#activity-2214673)

Re: I Got Paid $0 from the Uber Security Bug Bounty

#53
post #40

Uber's response is a joke, but I'm more surprised by how HockerOne is not helpful here. Sure their revenues come from corporations but if they don't maintain healthy community (where hackers get rewarded appropriately) the platform will lose any attraction.

My firing-from-the-hip response is that HackerOne is possibly making more bank from Uber and other big corporate clients in the short term than they would from building an established userbase, and they are going to cash out and dump the project soon. Corporations get what they wanted (effectively free quality pentesting), and HackerOne can run the narrative that it was a "foolish venture" all the way to the bank.

But, I'm probably wrong; the company seems to be well financed and has attracted a ton of clients that would be pissed if their investments were to disappear like that. Maybe it's just growing pains combined with fear of pissing off bad actors like Uber. They supposedly have nearly 100,000 active pentesters contracted, so they can stand to lose a little face to keep Uber happy.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#54
post #52
post #49

3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359

How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ ( https://hackerone.com/reports/293359#activity-2203160 ) > Cute. Big surprise. ( https://hac…

not to mention linking someone's social profile in a blog post about a company:

> So these tickets get assigned to Rob Fletcher with Uber’s security team.

Unfortunately, at least for me, this comes off as public shaming.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#55
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

Sounds great until you realize 1. riders would only use the app if they could sort by 'price,' 2. drivers would therefore have to constantly change their rates to reflect what those in the area are charging at a given time/supply/demand level, so.. 3. in order to do this effectively without creating massive unexpected price swings for both drivers & riders, you'd end up automating this 'bidding' system and hey whaddya know, you just built Uber again!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#56
post #38

Earlier quoted context omitted.

how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

> ...or drug addicts looking for money for their fix.

What a catastrophically bad idea..

Re: I Got Paid $0 from the Uber Security Bug Bounty

#57
This Uber company makes me so angry. I go to the Hacker News and I always see bad things about them. I just want to scream! What are they even doing for society—aside from employing hundreds of thousands of people and reducing drunk driving deaths. Doesn’t this stupid company realize that there are 500 angry journalists and technologists who don’t care about those two things.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#58

Only the XSS one was a real vulnerability, they should have paid $500 at least for that though.

> Only the XSS one was a real vulnerability, they should have paid $500 at least for that though.

That's false. Non-expired authentication tokens is a serious issue.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#59
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

Reminds me of a similar project that popped up on HN a while ago.

https://arcade.city/

Re: I Got Paid $0 from the Uber Security Bug Bounty

#60
post #38

Earlier quoted context omitted.

how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

IIRC taxi permits are usually called hacking permits.
Post reply on HN