Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

151–160 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#151

Earlier quoted context omitted.

Are you familiar with the freelancers' concept of "fuck you, pay me"? I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.

The freelancers „fuck you, pay me“ is based on very clear contracts and respectful communication, even when things go bad. This is not what’s happening here AFAICS.

"Minimum payout of $500" sounds like a very clear contract.

Once they have shadowbanned the author, IMO, any attempt at respectfulness is violated by bug bounty organizers.

Maybe there are things more rude than shadowban, but I'm not aware of such.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#152
post #97

Earlier quoted context omitted.

Uber is the last company in the world that gets to complain that somebody isn't being nice to them.

This seems unnecessarily callous. The writer was incredibly insulting to a person in a public forum, but that's ok because "well they worked for Uber"? I don't see this discussion as about whether a corporate PR team is allowed to issue a response. It's about the author childishly lashing out at an individual because he didn't agree with their decision.

I didn't say it's ok. I said Uber doesn't get to complain.

Indeed, my belief is that this guy's and Uber's behavior are both not-ok, which is exactly why Uber doesn't get to complain.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#153
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

That’s basically what SideCar was, as drivers could set their own rates, and passengers could choose from a number of offers based on total price, quality, driver rating, and time until pickup.

SideCar closed in late 2014 though :-/ (And there was a recurring cut paid to SC.)

Re: I Got Paid $0 from the Uber Security Bug Bounty

#154

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism. Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submit…

Are you seriously suggesting that it is OK to open a bug bounty for e.g. a webpage that you know has XSS flaws, and then refuse to pay out when someone exposes them because "yeah, we sort of knew that there were XSS, and we're hoping to move past our legacy framework. Closed informative"?

Don't open a bug bounty if you have unresolved known issues unless you are prepared to pay out, thats bogus.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#155

Earlier quoted context omitted.

Irrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!

But that's my point. Of course he deserved a payout if he reported a previously unknown vulnerability. What I'm saying is that he (appears to have) behaved in such toxic way (sow) that someone denied something he deserved (reap). All parties in this are squishy humans with emotions. No one looks good - he doesn't look good for how he behaved/communicationed, Uber doesn't look good for denying the payout on a valid re…

Just because you violate social mores does not entitle someone to violate the terms of their engagement with you.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#156

Earlier quoted context omitted.

biased persons like you should not comment here. Did hackerone paid you so you publish your biased comments about hackerone everywhere?

Great argument end sarcasm , you yourself are also obviously biased

Would you please not post unsubstantive or uncivil comments to HN? You're welcome here if (but only if) you want thoughtful conversation.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#157

Earlier quoted context omitted.

The freelancers „fuck you, pay me“ is based on very clear contracts and respectful communication, even when things go bad. This is not what’s happening here AFAICS.

"Minimum payout of $500" sounds like a very clear contract. Once they have shadowbanned the author, IMO, any attempt at respectfulness is violated by bug bounty organizers. Maybe there are things more rude than shadowban, but I'm not aware of such.

The minimum payout is subject to various conditions — for example, not being a duplicate. The author did not meet those conditions, and resorted to personal attacks instead of keeping things professional.

Uber has many, many problems as a company, but on this matter I can't say they're in the wrong.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#158
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

I've often thought it would be cool to build a fairer ride hailing app that gives drivers more autonomy. The driver buys the app as a one time purchase, they get to set their own prices, and there is more transparency between buyer and seller. There could be a simple bidding process where users request a ride, drivers make an offer, and the user accepts one based on price, how far away the driver is, and their review…

Semi-related: there's a startup in Denmark [0] trying to do this for parcel/freight transportation. I'm not sure how well they're doing, though.

[0] https://www.badabring.com/ (link in Danish)

Re: I Got Paid $0 from the Uber Security Bug Bounty

#160
post #157

Earlier quoted context omitted.

"Minimum payout of $500" sounds like a very clear contract. Once they have shadowbanned the author, IMO, any attempt at respectfulness is violated by bug bounty organizers. Maybe there are things more rude than shadowban, but I'm not aware of such.

The minimum payout is subject to various conditions — for example, not being a duplicate. The author did not meet those conditions, and resorted to personal attacks instead of keeping things professional. Uber has many, many problems as a company, but on this matter I can't say they're in the wrong.

Well, it doesn't seem like the last report was a duplicate.

The one they failed to recognize as XSS. If they paid for that one there would be no blog post and no name calling.

Post reply on HN