Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

141–150 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#141

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities Hackerone could require them to publish a list of hashes of unambiguous descriptions of known bugs. That way they could prove beyond doubt which issues were already known - much like astronomers published anagrams to prove their discoveries' priority in the 1500s. It wouldn't solve the problem of people wasting their tim…

I think it would go a long way just stating when they became duplicates. It would be hard to be mad at Uber if another person reported the same bug two days earlier.

It would be easy to be mad at Uber if this had been sitting in an internal bug tracker for three years just getting "closed, duplicate" everytime someone made a Hacker One report.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#142

Earlier quoted context omitted.

biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?

Simply putting my name as HackerOne user does not mean I am bias. Also no, hackerone or Uber none of them paid me to say the comments. If simply putting my points and pointing out the wrong facts will make me look bias then so be it.

> simply putting my points and pointing out the wrong facts

An argument should be judged purely on its content. No matter who says it or what their motive is.

However it is reasonable for someone to be suspicious given that you had to create a new account to do that, and you are so vocal in this story.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#143
post #14

This is why I see these programs in general as foolish. Either you're an employee of the company and you're being paid as such or you've got a proper contract that specifies objectives and compensation. But these bounty programs that leave all the power in the hands of the company just aren't really a great idea. I wonder how many times something like this happened and it went unreported because the hacker just didn'…

I work with HackerOne as an employee of a company with a bug bounty program. We're pretty sensitive about pissing off submitters. We're pretty strict about honoring our scope. Even if we know about a vulnerability, if we haven't specifically excluded it then we usually pay out (except duplicates where we have already paid out for it). I've seen many submitters respond with something along the lines of "thanks for the quick payout, I'm going to spend more time on your product".

We want submitters to spend time finding issues for us. Thats why we set up the program. It's important to our brand that we don't have security issues and we recognize that a few thousand dollar payout to HackerOne is much cheaper than the potential legal bill if we were compromised.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#144
post #71

Earlier quoted context omitted.

This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.

Amen! As a former drug addict, I can tell you that I would have given you amazing service. Reason being, that next $10 would have meant the world to me, and I wouldn't jeopardize it for anything. Stealing is hard and I was terrible at it. It's pretty common to assume that addicts are just pieces of inferior shit. Hell, I felt that way before I was one. That was a rather rude awakening.

I think its that real world experience with someone who had an addiction in your life that will change your worldview - my father is an opioid addict, and an alcoholic - and frankly, he managed to have both of these habits for 50 years and hold down a job, make a living, and (sort of) raise a child. He wasn't there when I was a kid - but I know he did the best job he knew how - even if it wasn't enough - and I can't fault him for it. Same with my mother, who was left emotionally kinda broken by her own childhood.

I've know many current and former addicts in my life - and I don't look at it as a character failing at all - its just an unfortunate luck of the draw when it comes to biology, genetics, and life experience.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#145

Earlier quoted context omitted.

Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism. Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submit…

AMEN. I totally agree with this, Uber was 100% right on these decisions. My response is here: https://medium.com/@cdll/im-also-able-to-bypass-the-uber-one...

No, they where not 100% right, your blog post reads full of quickfire/offbrand outrage. Especially when you resort to personal attacks whilst chastising him for personal attacks.

All of your other points are "I don't believe him" and "here is some unrelated technical information about uuids that while correct is not really the point". Cool, good for you. Didn't need to put that in a blog post though.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#146
post #30

I'm gonna need a response from HackerOne on this one. It's a very bad look for both Uber (yet again) but also HackerOne.

How? These were terrible P5 reports that would get closed as informative in ANY PROGRAM. He has no evidence behind the claims of the "xss" and the "OneLogin bypass" which they would have indeed paid out if it was valid. I'm highly disappointed in people here, geez.

I'm pretty disappointed too, now that I've seen the actual reports and his awful behavior. :-(

No, I was too eager to jump on Uber, here.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#147

Earlier quoted context omitted.

> So please, learn about the platform and a program works before you make any form of assumption. Welcome to Hacker News, I see it’s your first time visiting.

lool he has valid points though.

Welcome to you too!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#148
post #97

Earlier quoted context omitted.

It looks like a "reap what you sow" situation. No one is looking good now.

Uber is the last company in the world that gets to complain that somebody isn't being nice to them.

This seems unnecessarily callous. The writer was incredibly insulting to a person in a public forum, but that's ok because "well they worked for Uber"?

I don't see this discussion as about whether a corporate PR team is allowed to issue a response. It's about the author childishly lashing out at an individual because he didn't agree with their decision.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#149

Earlier quoted context omitted.

not to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.

Are you familiar with the freelancers' concept of "fuck you, pay me"? I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.

The freelancers „fuck you, pay me“ is based on very clear contracts and respectful communication, even when things go bad. This is not what’s happening here AFAICS.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#150
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

In Ukraine we have a taxi app where user selects price he's willing to pay and waits for drivers. He can increase the price if no drivers take an offer.
Post reply on HN