Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

131–140 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#131

Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…

As a researcher on Uber's program, I can assure you that OP has no clue what he's talking about. I've made a bunch of money from their program by submitting valid security issues, not this garbage he's complaining about. It's blowing my mind how everyone on HN is just eating this up, so much misinformation.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#132

Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…

Even your username tells us that you are absolutely biased toward hackerone. May be you are even a staff/co-founder of hackerone.

My username has nothing to do with anything. I simply chose it to hide my identity. I said what I said because I hack multiple programs throughout multiple platforms. These kind of blogs usually give a sense to companies that all hackers are like these. This leaves a bad impression about what we actually do. I don't think simply having hackerone in my name will make me bias. If you check my comment, you will see I have not said that HackerOne is right and the hacker is wrong. I have simply pointed the right facts that I felt was important for everyone to see. His blog leaves out a lot of points and also misguides readers.

Hopefully this clears it to you.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#133

Earlier quoted context omitted.

Even your username tells us that you are absolutely biased toward hackerone. May be you are even a staff/co-founder of hackerone.

My username has nothing to do with anything. I simply chose it to hide my identity. I said what I said because I hack multiple programs throughout multiple platforms. These kind of blogs usually give a sense to companies that all hackers are like these. This leaves a bad impression about what we actually do. I don't think simply having hackerone in my name will make me bias. If you check my comment, you will see I ha…

Also, I wish I am an hackerone employee or work in any of these platforms as an employee. I am simply a hacker and also employee of a company that runs a bbp so I have in both sides and I understand frustration of both side. Being frustrated does not provide excuses to the hacker's behavior of harassing an employeee based on their degree. This community is diverse and that is what we should learn to appreciate.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#134

Earlier quoted context omitted.

Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…

biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?

Simply putting my name as HackerOne user does not mean I am bias. Also no, hackerone or Uber none of them paid me to say the comments. If simply putting my points and pointing out the wrong facts will make me look bias then so be it.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#135
post #30

I'm gonna need a response from HackerOne on this one. It's a very bad look for both Uber (yet again) but also HackerOne.

How? These were terrible P5 reports that would get closed as informative in ANY PROGRAM. He has no evidence behind the claims of the "xss" and the "OneLogin bypass" which they would have indeed paid out if it was valid. I'm highly disappointed in people here, geez.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#136

Earlier quoted context omitted.

Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…

biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?

Great argument end sarcasm, you yourself are also obviously biased

Re: I Got Paid $0 from the Uber Security Bug Bounty

#137
post #40

Uber's response is a joke, but I'm more surprised by how HockerOne is not helpful here. Sure their revenues come from corporations but if they don't maintain healthy community (where hackers get rewarded appropriately) the platform will lose any attraction.

My firing-from-the-hip response is that HackerOne is possibly making more bank from Uber and other big corporate clients in the short term than they would from building an established userbase, and they are going to cash out and dump the project soon. Corporations get what they wanted (effectively free quality pentesting), and HackerOne can run the narrative that it was a "foolish venture" all the way to the bank. Bu…

No no no no no. What is it that you guys are not understanding about the severity of these reports??? Everyone PLEASE do yourself a favor and familiarize yourself with this: https://bugcrowd.com/vulnerability-rating-taxonomy

All his bugs were trash P5 bugs

Re: I Got Paid $0 from the Uber Security Bug Bounty

#139
post #36

What is the end game here? There is black market for this stuff and payouts are orders of magnitude higher than the bounty programs, why would they skew things even more in favor of that route by behaving like this is a mystery.

> payouts are orders of magnitude higher than the bounty programs This is mostly false except for a narrow class of products and bug classes. You could get more on the black market for an iOS jailbreak than Apple would pay you, yes. You could not get more on the black market for any of the bugs the author submitted - most likely you wouldn't find a buyer at all.

For reflection attack you sure would find a buyer at a rate far beyond $500
Post reply on HN