Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…
I Got Paid $0 from the Uber Security Bug Bounty
131–140 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#132Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…
Even your username tells us that you are absolutely biased toward hackerone. May be you are even a staff/co-founder of hackerone.
Hopefully this clears it to you.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#133Earlier quoted context omitted.
Even your username tells us that you are absolutely biased toward hackerone. May be you are even a staff/co-founder of hackerone.
My username has nothing to do with anything. I simply chose it to hide my identity. I said what I said because I hack multiple programs throughout multiple platforms. These kind of blogs usually give a sense to companies that all hackers are like these. This leaves a bad impression about what we actually do. I don't think simply having hackerone in my name will make me bias. If you check my comment, you will see I ha…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#134Earlier quoted context omitted.
Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…
biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?
Re: I Got Paid $0 from the Uber Security Bug Bounty
#135I'm gonna need a response from HackerOne on this one. It's a very bad look for both Uber (yet again) but also HackerOne.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#136Earlier quoted context omitted.
Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…
biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?
Re: I Got Paid $0 from the Uber Security Bug Bounty
#137Uber's response is a joke, but I'm more surprised by how HockerOne is not helpful here. Sure their revenues come from corporations but if they don't maintain healthy community (where hackers get rewarded appropriately) the platform will lose any attraction.
My firing-from-the-hip response is that HackerOne is possibly making more bank from Uber and other big corporate clients in the short term than they would from building an established userbase, and they are going to cash out and dump the project soon. Corporations get what they wanted (effectively free quality pentesting), and HackerOne can run the narrative that it was a "foolish venture" all the way to the bank. Bu…
All his bugs were trash P5 bugs
Re: I Got Paid $0 from the Uber Security Bug Bounty
#138Just like this one, his story back then didn't quite add up either.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#139What is the end game here? There is black market for this stuff and payouts are orders of magnitude higher than the bounty programs, why would they skew things even more in favor of that route by behaving like this is a mystery.
> payouts are orders of magnitude higher than the bounty programs This is mostly false except for a narrow class of products and bug classes. You could get more on the black market for an iOS jailbreak than Apple would pay you, yes. You could not get more on the black market for any of the bugs the author submitted - most likely you wouldn't find a buyer at all.