Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

111–120 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#111
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

they have not brought any innovation. They are just a company with a very reliable and robust service. For all the bad news its just social moral crying, its nothing about their tech.

As a service they are great, reliable. Thats all you need to be a successful business you dont need to innovate. Let google and Microsoft think about AI. All Uber needs to do is make sure I get to my destination on time.

When you think about impact, you might say Uber has topped all tech companies. Sure Google AI can be the best chess player, but Uber give mobility to me and many others in an easy to use application which is much more effective in my day to day life.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#112

Earlier quoted context omitted.

>Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders. I already benefit from it massively. Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where an…

Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where and how to hail a taxi or having to figure out the bus routes. I'm not familiar with he US, but taxis in most European countries have an app these days. Even >20 years ago you could just call their phone number a…

You should listen to all the Americans insisting the taxi experience was nowhere near that easy or good. Because outside NYC, it was utter shit. And good luck even in NYC if you're black, or going to the airport, or the outer Burroughs, or ...

Re: I Got Paid $0 from the Uber Security Bug Bounty

#113
post #38

Earlier quoted context omitted.

how we can fix this sharing economy Start by ditching the term “sharing economy” because there is no “sharing”, person A pays and person B provides some service, so it’s just “economy”.

^^^ What he said. How about "eBay for car rides"

yea make it dude see if its successful , no one is stopping you

Re: I Got Paid $0 from the Uber Security Bug Bounty

#114

Earlier quoted context omitted.

It looks like a "reap what you sow" situation. No one is looking good now.

Irrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!

A bunch of P5's that were rightly closed as informative. I completely agree w/ Uber's decisions here...

Re: I Got Paid $0 from the Uber Security Bug Bounty

#115

Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…

> Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) They've paid out more than $1,300,000 in bounties, you can view all their payouts here: https://hackerone.com/uber/hacktivity?sort_type=latest_discl... > Do you trust their code contributions on OSS to not contain malicious attack vectors? This has nothing to do with anything.

Good to know they aren't actually deadbeats on bugbounties and can chalk up this example to honest disagreement.

As for the rest, it has to do with everything. Would you trust your application's security to code libraries written by a company with the the allegations hanging over Uber? If there's a chance your customer data might be a strategic asset for Uber?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#116
post #99
post #71

Earlier quoted context omitted.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

I challenge you to explore addiction more fully - it is simplistic to assume that all addicts are opioid-linked and that maintenance dosages would remove harm (methadone programs are basically performing this function, so it is not as though this doesn’t happen). Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Becaus…

I'm the child of an addict.

It really depends on how you measure cost - the current regime of punishing it, or treating it as a character weakness is clearly not working - plus moving sustained addiction outside of a care network to the black market, also clearly isn't working either.

Everything we do has a cost to the community, the question is, since we know we can't eliminate the cost, how can we reduce it?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#117
post #71

Earlier quoted context omitted.

Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

Amen! As a former drug addict, I can tell you that I would have given you amazing service. Reason being, that next $10 would have meant the world to me, and I wouldn't jeopardize it for anything. Stealing is hard and I was terrible at it.

It's pretty common to assume that addicts are just pieces of inferior shit. Hell, I felt that way before I was one. That was a rather rude awakening.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#119
post #102

Earlier quoted context omitted.

it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities Hackerone could require them to publish a list of hashes of unambiguous descriptions of known bugs. That way they could prove beyond doubt which issues were already known - much like astronomers published anagrams to prove their discoveries' priority in the 1500s. It wouldn't solve the problem of people wasting their tim…

I was going to suggest hackerone should be responsible for both storing and arbitrating known bugs but this is even better. It's really hard to not think Uber is simply playing hackerone to get free penetration testing here by responding to everything as "already discovered" or "out of scope"... A dangerous game though if people catch on and get pissed off enough and just publish it like this, I can't really blame th…

This would appear to be consistent with what I've personally observed of Uber's approach to, well, pretty much everything.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#120
post #99
post #71

Earlier quoted context omitted.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

I challenge you to explore addiction more fully - it is simplistic to assume that all addicts are opioid-linked and that maintenance dosages would remove harm (methadone programs are basically performing this function, so it is not as though this doesn’t happen). Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Becaus…

[deleted]
Post reply on HN