Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

101–110 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#101
With all the horror stories I've been reading since the 90's I'd never help any company like this (again). Discover a vulnerability and get sued or punished. Fix their bugs for them, get nothing for doing their job for them.

I remember contributing to BigCommerce's crappy software just because I needed it to actually do it's job (despite the fact that my boss was paying their enterprise rate). I got shitty responses from their devs and nothing got fixed when I forked and submitted patches. I kept and then hid my working fork and never looked back.

Yeah, a company can fix it's own problems. Open source, perhaps... Helping a profitable business for nothing? Never again.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#102

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities Hackerone could require them to publish a list of hashes of unambiguous descriptions of known bugs. That way they could prove beyond doubt which issues were already known - much like astronomers published anagrams to prove their discoveries' priority in the 1500s. It wouldn't solve the problem of people wasting their tim…

I was going to suggest hackerone should be responsible for both storing and arbitrating known bugs but this is even better.

It's really hard to not think Uber is simply playing hackerone to get free penetration testing here by responding to everything as "already discovered" or "out of scope"... A dangerous game though if people catch on and get pissed off enough and just publish it like this, I can't really blame the author, the whole process sounds like bullshit.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#103
post #52

Earlier quoted context omitted.

How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ ( https://hackerone.com/reports/293359#activity-2203160 ) > Cute. Big surprise. ( https://hac…

not to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.

[deleted]

Re: I Got Paid $0 from the Uber Security Bug Bounty

#104
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

Something like what Project Wonderful does with web advertising would really have big potential

Re: I Got Paid $0 from the Uber Security Bug Bounty

#105

Earlier quoted context omitted.

Client side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.

Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.

[deleted]

Re: I Got Paid $0 from the Uber Security Bug Bounty

#107

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism. Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submit…

AMEN. I totally agree with this, Uber was 100% right on these decisions. My response is here: https://medium.com/@cdll/im-also-able-to-bypass-the-uber-one...

Re: I Got Paid $0 from the Uber Security Bug Bounty

#108

Earlier quoted context omitted.

It looks like a "reap what you sow" situation. No one is looking good now.

Irrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!

But that's my point. Of course he deserved a payout if he reported a previously unknown vulnerability. What I'm saying is that he (appears to have) behaved in such toxic way (sow) that someone denied something he deserved (reap). All parties in this are squishy humans with emotions.

No one looks good - he doesn't look good for how he behaved/communicationed, Uber doesn't look good for denying the payout on a valid report, and Hackerone doesn't look good for not enforcing a minimum payout on a valid report.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#109

Earlier quoted context omitted.

Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…

> So please, learn about the platform and a program works before you make any form of assumption. Welcome to Hacker News, I see it’s your first time visiting.

lool he has valid points though.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#110
post #99
post #71

Earlier quoted context omitted.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

I challenge you to explore addiction more fully - it is simplistic to assume that all addicts are opioid-linked and that maintenance dosages would remove harm (methadone programs are basically performing this function, so it is not as though this doesn’t happen). Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Becaus…

[deleted]
Post reply on HN