Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

71–80 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#71

Earlier quoted context omitted.

> ...or drug addicts looking for money for their fix. What a catastrophically bad idea..

Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#72
post #38

Earlier quoted context omitted.

how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.

In Baltimore we already do this. In Baltimore it's called hacking. http://afro.com/the-anatomy-of-a-hack/ It could be half the cost of a uber or lyft depending on where you're going. A $23-$30 ride could be $9-$15 via a hack. Most of these people are retired older dudes or drug addicts looking for money for their fix. I thought of an app to facilitate this based off of a review system of past customers. Take a dollar…

And people wonder why America used to have Unions, and regulations. And didn't cheap out everything.

This Sharing Economy is a nice way to say, here's a chit part time job. A race to the bottom is not what I want. Uber has always been in my crosshairs. "You need to have a late model four door vechicle before applying!" Ugh.

I used to think the poor will eventually rebel. I don't think that will happen. Technology will keep them in line.

I do see a day where a person will be judged on exactly how they made the wad, or maybe not?

I miss some of that hippy dippy it's not cute to be a filthy looker mentality, or at least sharing.

Merry Christmas!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#73

Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…

If you check reports that are actually valid, you can see that Uber actually pays for valid issues. Excluding the 100,000, Uber has already paid 1million+ in bug bounty. Please check their hackerone platform :)

Re: I Got Paid $0 from the Uber Security Bug Bounty

#74
post #52

Earlier quoted context omitted.

How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ ( https://hackerone.com/reports/293359#activity-2203160 ) > Cute. Big surprise. ( https://hac…

Clearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?

It looks like a "reap what you sow" situation. No one is looking good now.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#75
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

Fixing sharing economy - develop proper distributed system that runs akin to bittorrent/bitcoin model with guaranteed feedback mechanisms that mitigates against systemic abuse. Super hard job. But it would, if solved, truly revolutionize/create the shared economy space.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#76

Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…

> Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties)

They've paid out more than $1,300,000 in bounties, you can view all their payouts here: https://hackerone.com/uber/hacktivity?sort_type=latest_discl...

> Do you trust their code contributions on OSS to not contain malicious attack vectors?

This has nothing to do with anything.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#77
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

>Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I already benefit from it massively. Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where and how to hail a taxi or having to figure out the bus routes. Now as long as I have my phone and I'm in a somewhat populated area, I have no fear.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#78

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

  it doesn't make sense for
  Uber to a) publish a list 
  of current unpatched 
  security vulnerabilities
Hackerone could require them to publish a list of hashes of unambiguous descriptions of known bugs. That way they could prove beyond doubt which issues were already known - much like astronomers published anagrams to prove their discoveries' priority in the 1500s.

It wouldn't solve the problem of people wasting their time rediscovering bugs that don't pay out, of course.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#79

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

[deleted]

Re: I Got Paid $0 from the Uber Security Bug Bounty

#80
post #36

What is the end game here? There is black market for this stuff and payouts are orders of magnitude higher than the bounty programs, why would they skew things even more in favor of that route by behaving like this is a mystery.

> payouts are orders of magnitude higher than the bounty programs

This is mostly false except for a narrow class of products and bug classes. You could get more on the black market for an iOS jailbreak than Apple would pay you, yes. You could not get more on the black market for any of the bugs the author submitted - most likely you wouldn't find a buyer at all.

Post reply on HN