Live data from Hacker News

Abusing Amazon‘s Look Inside feature to leak unreleased content

justmaku.org

1–10 of 33 posts

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#2
> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise.

I'm not surprised Amazon would pay with nothing more than a nice email. What's more surprising is that Blizzard would give the author the shaft like that. They're usually pretty good about this sort of thing.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#3
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Perhaps Blizzard was. Activision-Blizzard seems to have abandoned their virtues.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#4
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Perhaps Blizzard was. Activision-Blizzard seems to have abandoned their virtues.

Yeah, I remember interviewing just after the merger when they opened the Cork office. I was 17, flew to Ireland, and the guy who was supposed to interview me face to face had taken a late lunch, so I got interviewed in about 5 minutes by someone who was clearly not interested, and it then took them 6 months to get back to me.

Nice one, good job guys.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#5
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Oh cmon some guy breaking into others system feels entitled to want cash prize.

He should have been sent to prison for this.

Breaking into someone's house is theft regardless wether owner forgot to lock the door.

Same should be the matter with code.

Is this really what the world has come to?

Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bounty for this finding?

This is mad! It seems tech people only care about enriching themselves.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#6
post #4

Earlier quoted context omitted.

Perhaps Blizzard was. Activision-Blizzard seems to have abandoned their virtues.

Yeah, I remember interviewing just after the merger when they opened the Cork office. I was 17, flew to Ireland, and the guy who was supposed to interview me face to face had taken a late lunch, so I got interviewed in about 5 minutes by someone who was clearly not interested, and it then took them 6 months to get back to me. Nice one, good job guys.

I imagine they get thousands of people applying a day. Sad you flew to Ireland, that's messed up that they forgot.

The bad practices for me, are their pivoting toward lootbox pay2win gambling designs.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#7
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Oh cmon some guy breaking into others system feels entitled to want cash prize. He should have been sent to prison for this. Breaking into someone's house is theft regardless wether owner forgot to lock the door. Same should be the matter with code. Is this really what the world has come to? Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bou…

That's how these things typically work. So long as he explored the vulnerability and reported it ethically - and there are both laws and industry norms about that - than typically a small cash bounty is paid if the bug is serious. This is because you want hackers to report vulnerabilities to you so you can fix them. It's more like returning someone's wallet. You give the person a couple of dollars for their trouble. A company like Amazon, you definitely expect them to have an explicit bug bounty program. This system is good for both consumers and businesses and there's no reason, even if purely from a business calculus perspective, not to throw someone a few bucks for the professional reporting of a vulnerability.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#8
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Oh cmon some guy breaking into others system feels entitled to want cash prize. He should have been sent to prison for this. Breaking into someone's house is theft regardless wether owner forgot to lock the door. Same should be the matter with code. Is this really what the world has come to? Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bou…

Idk, to me your mindset seems mad. There are bad actors in the world we all know that. So if you ran a online company and I was your customer I should expect that no one will attack your company because it is illegal? And you would not take steps to protect your company because attacking it would be illegal? Saying out loud sounds crazy. There is no legality when there person stealing my data may be in Russia, or China, or India, who may be an individual, an organized crime ring or state actor. The internet does not care about your legality. So by offering a bug bounty program you are at least showing some interest in the white hat people not working to screw you over when in many circumstances it would probably be much more profitable for the bugs to be exploited or sold. Why would you want to send this type of person to prison?

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#10
post #8

Earlier quoted context omitted.

Oh cmon some guy breaking into others system feels entitled to want cash prize. He should have been sent to prison for this. Breaking into someone's house is theft regardless wether owner forgot to lock the door. Same should be the matter with code. Is this really what the world has come to? Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bou…

Idk, to me your mindset seems mad. There are bad actors in the world we all know that. So if you ran a online company and I was your customer I should expect that no one will attack your company because it is illegal? And you would not take steps to protect your company because attacking it would be illegal? Saying out loud sounds crazy. There is no legality when there person stealing my data may be in Russia, or Chi…

You are completely missing the point.

He can't monetize the bug because that would be illegal!

This is granted by the law.

So why pay? Paying for bug is useless here.

Sending him to prison and making an example out of him so that others do not break into your system and make a joke of your engineering team/security team is better for their morale.

Post reply on HN