I Got Paid $0 from the Uber Security Bug Bounty
81–90 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#82Earlier quoted context omitted.
Clearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?
It looks like a "reap what you sow" situation. No one is looking good now.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#83Re: I Got Paid $0 from the Uber Security Bug Bounty
#84Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.
1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure page with no valuable information for new hackers.
2) I haven't seen reports getting locked unless reporter goes "Can i haz update" every 2 days. Then in such cases, Locking a report is more than fair.
3) You might be confusing this with Limited Disclosure. That is allowed in both sense by companies and hackers. Most of my reports are limited disclosure because sometimes, I have to share personal details or personal information that I don't want other hackers to see.
I support transparency that is why, till this day, all of my resolved reports for public programs are publicly disclosed. Even in Uber's case, I have disclosed bug but they were limited disclosure because it had my personal information. But if you check, Uber has allowed me to write public blogs on my reports.
So please, learn about the platform and a program works before you make any form of assumption.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#85I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.
>Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders. I already benefit from it massively. Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where an…
I'm not familiar with he US, but taxis in most European countries have an app these days. Even >20 years ago you could just call their phone number and they would pick you up from (or drop you) anywhere, even in remote villages, even at 4am. Never had a problem. I find it hard to believe the same isn't true for the US.
Sure public transport isn't as flexible route/time wise but I don't see how Uber is different from regular taxi service - apart from the price.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#86Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#87Earlier quoted context omitted.
Client side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.
I recall that either OAuth or SAML doesn't have capabilities for logout.
SAML has an actual logout endpoint
Re: I Got Paid $0 from the Uber Security Bug Bounty
#88Earlier quoted context omitted.
Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.
Not the parent commenter and I get what you mean, but if they state that it's a duplicate issue (and assuming on good faith that it is), doesn't it make sense that they don't pay you out for that? I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.
Also: this is Uber. At this point, they’ve used up all their good faith. I definitely wouldn’t be taking anything they say in good faith - I still haven’t forgotten them threatening a journalist or publicly tracking the ride of a CEO for an entire room of people!
Re: I Got Paid $0 from the Uber Security Bug Bounty
#89Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#90Earlier quoted context omitted.
Are you basing this opinion on this one account? I would like to point out that Uber has a history of sleaze and would absolutely not use their behavior to judge any such programs. Are there other well described, similar instances of such poor behavior from legitimate companies? It seems to me that most of the bigger corps offering bug bounties may be paying too little but at least they follow their own rules.
Khaos Tian published a writeup a few days ago about how he discovered a wide-open HomeKit vulnerability [0]. He reported it properly months prior, but Apple ignored his followups and was unresponsive. After this extended radio silence, Tian reached out to a media contact. Within hours of being contacted by the website, Apple finally pushed a hotfix for the vulnerability. Apple subsequently denied Tian access to their…
I'm certainly not justifying a poor communication and response to the report, but, it seems like a very different kind of problem, and not one reflective of the kind of corporate sleaze often seen from Uber.