Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

121–130 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#121

Earlier quoted context omitted.

> ...or drug addicts looking for money for their fix. What a catastrophically bad idea..

Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.

I’m more worried about their ability to drive safely. I am not against drugs (I in fact believe legalizing them would be best) however, one should not drive a car when they are either high or on withdrawal because it prevents them from being able to drive safely. I would not want to be the passenger of someone who does drugs regularly because regular usage can have negative affects even after you are no longer high.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#123

Earlier quoted context omitted.

Sounds great until you realize 1. riders would only use the app if they could sort by 'price,' 2. drivers would therefore have to constantly change their rates to reflect what those in the area are charging at a given time/supply/demand level, so.. 3. in order to do this effectively without creating massive unexpected price swings for both drivers & riders, you'd end up automating this 'bidding' system and hey whaddy…

Genuinely curious about this - why would the price swings in this case be worse than with uber? With enough drivers, I would expect prices to reach an equilibrium that depends on time of day/day of week, with highly rated drivers charging more. And even if the price swings were larger than uber's, wouldn't the prices be more optimal since they would be set by individual actors with more local info about the cost of p…

While Uber and Lyft raise prices in periods of high demand, they also subsidize rides in periods of low demand to keep a consistent quality of service. You'd have a hard time getting a network as reliable as Uber and Lyft without that subsidy.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#124
post #49

3 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359

These are low severity reports. The first two require difficult prerequisites for an attacker to exploit, and the last one was not proven to be a security flaw.

#293358: it's not ideal that the certificate isn't pinned, but to exploit this an attacker needs to either install their own root certificate on the victim's device, somehow obtain a private key for a certificate already installed, or have a certificate authority misissue a certificate to them for an Uber domain used by the app.

#293363: an attacker still needs to acquire the victim's X-Uber-Token somehow for this to be useful. It's also somewhat mitigated by the token being invalidated when the victim changes their password.

#293359: as pointed out by Uber, no weaknesses in the token generation algorithm were actually demonstrated, and brute forcing the 2^128 keyspace is infeasible.

Also, the rudeness he displayed was petty and unhelpful:

> given the fact that at least one of your system architects were apparently high when they designed and implemented your bearer token assignment process

> Not completely unexpected though, given the caliber of talent utilized by Uber such as the “security” group that you hail from. You would do well in government security consulting, for sure.

> Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ

All in all, rather a poor result for this vulnerability researcher.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#126

Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…

Even your username tells us that you are absolutely biased toward hackerone. May be you are even a staff/co-founder of hackerone.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#127

Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.

Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…

biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#128
post #116
post #99

Earlier quoted context omitted.

I challenge you to explore addiction more fully - it is simplistic to assume that all addicts are opioid-linked and that maintenance dosages would remove harm (methadone programs are basically performing this function, so it is not as though this doesn’t happen). Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Becaus…

I'm the child of an addict. It really depends on how you measure cost - the current regime of punishing it, or treating it as a character weakness is clearly not working - plus moving sustained addiction outside of a care network to the black market, also clearly isn't working either. Everything we do has a cost to the community, the question is, since we know we can't eliminate the cost, how can we reduce it?

I agree, services to support are very important and models that reduce harm should be encouraged and adopted

Re: I Got Paid $0 from the Uber Security Bug Bounty

#129
Posted this as a response on Medium but got blocked cause I guess he just wants yes men around lol:

“I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system.”

Where’s the proof? I don’t see any whatsoever. I highly doubt that you were actually able to bypass the OneLogin because if you did, they’d definitely pay out and it’d be an actual issue rather than some crappy bugs.

    Lack of certificate pinning IS NOT a critical issue. Critical issues are code execution, file read, etc.
    The odds of you actually guessing UUIDs are super low and pretty difficult, they did the right thing in closing as informative. You’d have to try “~ 10²⁹ values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second.” You claimed their PRNG was broken but had no evidence or support to back it.
    “Are you seriously the Program Manager for Uber’s Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting?” — you’re a complete moron, glad you know how to personally attack people, Uber definitely had the right to ban you from their program.
    Programs CANNOT delete comments from HackerOne Reports (as you claim in https://hackerone.com/reports/293359)
Uber DEFINITELY made the right choices in closing your reports as informative, but go ahead, fool yourself
Post reply on HN