I wonder if this is the same Gregory V Perry who claimed there'd been an attempt to backdoor OpenBSD IPSec code: https://marc.info/?l=openbsd-security-announce&m=12923753140... Just like this one, his story back then didn't quite add up either.
I Got Paid $0 from the Uber Security Bug Bounty
161–168 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#162Earlier quoted context omitted.
This seems unnecessarily callous. The writer was incredibly insulting to a person in a public forum, but that's ok because "well they worked for Uber"? I don't see this discussion as about whether a corporate PR team is allowed to issue a response. It's about the author childishly lashing out at an individual because he didn't agree with their decision.
I didn't say it's ok. I said Uber doesn't get to complain. Indeed, my belief is that this guy's and Uber's behavior are both not-ok, which is exactly why Uber doesn't get to complain.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#163Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#164Earlier quoted context omitted.
I didn't say it's ok. I said Uber doesn't get to complain. Indeed, my belief is that this guy's and Uber's behavior are both not-ok, which is exactly why Uber doesn't get to complain.
That's not how that works at all.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#165Earlier quoted context omitted.
Genuinely curious about this - why would the price swings in this case be worse than with uber? With enough drivers, I would expect prices to reach an equilibrium that depends on time of day/day of week, with highly rated drivers charging more. And even if the price swings were larger than uber's, wouldn't the prices be more optimal since they would be set by individual actors with more local info about the cost of p…
While Uber and Lyft raise prices in periods of high demand, they also subsidize rides in periods of low demand to keep a consistent quality of service. You'd have a hard time getting a network as reliable as Uber and Lyft without that subsidy.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#166More like you got paid $0 for obvious and shit findings along with a crappy attitude.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#167Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…
Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism. Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submit…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#168"we have contacted the Uber App Sec team and they have confirmed with us that these are not security issues that are in scope on their program."
Contacting the other party and reporting back what they say is not what is meant by mediation. This is underscored by the next sentence:
"I understand that this can be a disappointment but I can assure you that they looked at this report and gave it the proper attention it deserved." [my emphasis.]