Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

61–70 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#62
post #12

Let me get this straight: there's a company built to exploit the ignorance of people of just how much it costs to drive their own car and the complete disregard of law and you thought while they don't respect their drivers and various governing bodies all over the globe they will respect you ?

I think you will realize, once you have cooled down a bit, that it is exactly people's awareness of how much it costs to own and drive a car in terms of money and mental peace that drives them to use services like Uber. And yes, I know you were referring to people who drive for Uber. For many people, the process of owning and driving a car doesn't make overall sense, which is why they pay others to do it for them. I…

> it is exactly people's awareness of how much it costs to own and drive a car in terms of money and mental peace that drives them to use services like Uber.

The point is that its far less profitable than it seems, is very stressful, and has variable (unstable) income which further adds to the stress. See for example Uber The Game [1] based on real life examples.

> I don't see anyone complaining about how maids have to, oh my gosh, clean houses.

Well, of course they don't complain about that here. That'd be offtopic.

Part of the problem with issues like these is that if they don't affect you, why bother caring? Reading about it? Investigating the issue? You're not a maid, so why would you bother? You not enough on your plate as it is making your own deadlines and taking care of your family and and... which creates apathy.

I happen to know that regarding maids, and I won't speak for all hotels, but I happen to know from a series called RamBam [2] that at least in 2016 the Bastion and Ibis hotels in Amsterdam, cleaning service profession ("hotel maid") was 1) very stressful 2) paid by amount of rooms being cleared 3) a very low amount of minutes per room is being accounted 4) if you don't make it (setback of any kind), tough luck, you get paid less or you gotta work longer. Its a job you would only get if you can't get any other, and you desperately need the money. The company who hire know that, so the employees get exploited.

If that's still the case, if its more widespread, I don't know...

Cause what happens all too often in situations like these is when companies have shady, illegal, immoral behavior they resort to ostrich politics until they get exposed and it causes public uproar (in US, as a foreigner, I could think about say, Consumer Reports, or a John Oliver broadcast, or news about X in regular media). Then they start with damage control, but not necessarily with real steps to solve the issue. Just the symptom that the public perceives. Examples of damage control could be empty promises, solving the issue of the specific complaint of that one user, more empty promises, a bunch of excuses, some technicalities or pseudo-intelligent speech, yet more empty promises and excuses, shifting the blame, and all kind of other fallacies. It precisely describes what Uber did until a big change occurred (they got a new CEO). Heck, I've seen Uber employees exercise damage control on HN! Another good example is the #metoo debacles where people deny the allegations until the proof stacked up too high.

[1] https://ig.ft.com/uber-game/

[2] https://nl.wikipedia.org/wiki/RamBam#Seizoen_5 (see 5.2)

Re: I Got Paid $0 from the Uber Security Bug Bounty

#63
Here is my personal take on this:

I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts.

There are couple of things I want to point out to the author here:

1) You said that if these were Duplicate reports, they have to have a report number assigned. If you use HackerOne application frequently (which it does not look like you do), a report number is only assigned if it was submitted by another hacker. There are situations when internal findings are also on process on being fixed.

Uber treasure map is simply a guide. If you find something that is bypass of what they said they have, does not mean its an original finding. I work at a company where we have our own security team breaking applications every day. Sometimes hacker submit similar findings that our security team found before. In such cases, if it is a low priority issue, it will take time for us to fix because we do not prioritize it. In that case, a hacker will get a report marked as Duplicate with no report number assigned.

For the first three report that is exactly what happened.

2) Personal attack against a employee of a company will not help you anyways. You went after an employee just based on your degree. If you look closely in the industry, it is the matter of experience not degrees. I have worked with colleagues who are way smarter than me in the field and have way more experience. I never judge them based on their degree.

3) I am still not sure about your reflected XSS bug. Were you able to get a XSS actually execute? Seeing reply from Rob makes me thing you probably found a valid xss that works on an old browser. In addition, you also said you gained access to internal uChat: "I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system." but you did not prove that anywhere in your blog so I don't know if that is legit.

To conclude, considering the recent media attention at Uber due to security mishaps that occurred before, it seems to me that you are just looking for a media attention. Your title first is clickbait because 3 of your reports are duplicate so I am not sure why you expected any bounty.

To make this clear: I am a hacker in the community and an active participant in Uber's bug bounty and also in HackerOne. I have never seen Uber be unfair to hackers in the platform. Hell, to even encourage hackers, they started to pay 500 on triage.

That said, I am looking forward to your comment on this and would love to see your discussion on my points listed above.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#64

Earlier quoted context omitted.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

Sounds great until you realize 1. riders would only use the app if they could sort by 'price,' 2. drivers would therefore have to constantly change their rates to reflect what those in the area are charging at a given time/supply/demand level, so.. 3. in order to do this effectively without creating massive unexpected price swings for both drivers & riders, you'd end up automating this 'bidding' system and hey whaddy…

Genuinely curious about this - why would the price swings in this case be worse than with uber? With enough drivers, I would expect prices to reach an equilibrium that depends on time of day/day of week, with highly rated drivers charging more. And even if the price swings were larger than uber's, wouldn't the prices be more optimal since they would be set by individual actors with more local info about the cost of providing the service?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#65
post #52
post #49

3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359

How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ ( https://hackerone.com/reports/293359#activity-2203160 ) > Cute. Big surprise. ( https://hac…

Clearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#66

Earlier quoted context omitted.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

> ...or drug addicts looking for money for their fix. What a catastrophically bad idea..

You underestimate the sense of poor people who just need a quick ride up the street or are desperate to get to a job that's on the verge of firing them for their lateness because the public transportation has failed them time and time again.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#67
post #60

Earlier quoted context omitted.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

IIRC taxi permits are usually called hacking permits.

The old British term for a cab is a Hackney Carriage

Re: I Got Paid $0 from the Uber Security Bug Bounty

#68
From the comments and the article. it seems HackerOne cares for security researcher and white hat hackers insofar as they attract companies to their platform.

I guess their apathy makes sense from a short-term, bottom-line perspective, but it still seems a little unseemly.

Is there a better alternative to HackerOne for the security community?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#69

Earlier quoted context omitted.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

> ...or drug addicts looking for money for their fix. What a catastrophically bad idea..

Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.
Post reply on HN