Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

161–168 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#161

I wonder if this is the same Gregory V Perry who claimed there'd been an attempt to backdoor OpenBSD IPSec code: https://marc.info/?l=openbsd-security-announce&m=12923753140... Just like this one, his story back then didn't quite add up either.

Hm, both profiles have one thing in common: VMware training/instruction. You might be on to something.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#162

Earlier quoted context omitted.

This seems unnecessarily callous. The writer was incredibly insulting to a person in a public forum, but that's ok because "well they worked for Uber"? I don't see this discussion as about whether a corporate PR team is allowed to issue a response. It's about the author childishly lashing out at an individual because he didn't agree with their decision.

I didn't say it's ok. I said Uber doesn't get to complain. Indeed, my belief is that this guy's and Uber's behavior are both not-ok, which is exactly why Uber doesn't get to complain.

That's not how that works at all.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#163

Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.

Acting like there's a conspiracy against you is not helping your case at all, it's just making you look paranoid and unreasonable.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#164

Earlier quoted context omitted.

I didn't say it's ok. I said Uber doesn't get to complain. Indeed, my belief is that this guy's and Uber's behavior are both not-ok, which is exactly why Uber doesn't get to complain.

That's not how that works at all.

Sorry, Ashton. I believe it is, and an internet random boldly asserting otherwise is not likely to do much to persuade me to the contrary.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#165

Earlier quoted context omitted.

Genuinely curious about this - why would the price swings in this case be worse than with uber? With enough drivers, I would expect prices to reach an equilibrium that depends on time of day/day of week, with highly rated drivers charging more. And even if the price swings were larger than uber's, wouldn't the prices be more optimal since they would be set by individual actors with more local info about the cost of p…

While Uber and Lyft raise prices in periods of high demand, they also subsidize rides in periods of low demand to keep a consistent quality of service. You'd have a hard time getting a network as reliable as Uber and Lyft without that subsidy.

It's not uncommon to see Uber retain 75% of the fee collected these days. The subsidies are much lower and less frequent than you are probably expecting. In Los Angeles, you are talking about 1.1-2.0 subsidy on base rates in the same areas with base rates for the driver being .72/mi and .11/min.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#167

Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…

Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism. Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submit…

The reporter's lack of maturity or social skills is not grounds for denying a valid bounty, and the fact that Uber responded by modifying its system in response to the reports of the final problem is strong evidence that they were both original and valid concerns.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#168
This is not just about Uber; it also indicates problems at HackerOne, if this is its response to a mediation request:

"we have contacted the Uber App Sec team and they have confirmed with us that these are not security issues that are in scope on their program."

Contacting the other party and reporting back what they say is not what is meant by mediation. This is underscored by the next sentence:

"I understand that this can be a disappointment but I can assure you that they looked at this report and gave it the proper attention it deserved." [my emphasis.]

Post reply on HN