Live data from Hacker News

Abusing Amazon‘s Look Inside feature to leak unreleased content

justmaku.org

11–20 of 33 posts

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#11
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Oh cmon some guy breaking into others system feels entitled to want cash prize. He should have been sent to prison for this. Breaking into someone's house is theft regardless wether owner forgot to lock the door. Same should be the matter with code. Is this really what the world has come to? Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bou…

> Oh cmon some guy breaking into others system feels entitled to want cash prize.

I don't think he was specifically seeking a cash prize; he reported it to Amazon despite them not having a standing offer for such prizes. Also, aggregating the results of searches that Amazon specifically allows is hardly "breaking in"

> He should have been sent to prison for this.

That seems like a recipe for Amazon having a lot more security holes (which is probably why Amazon won't seek damages here).

> Breaking into someone's house is theft regardless wether owner forgot to lock the door.

No, taking someone's property is theft. Nothing was stolen here.

> Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bounty for this finding?

This leaves the door damaged. Nothing of Amazon's was damaged here. Also the door is (probably) not expected to be robust against plasma cutters. Amazon thanked the author of the post for bringing this to their attention.

This is more like "Your neighbor has a early 2000s Kryptonite bike lock and you show them it can be opened with a Bic pen[1]. They thank you and get a different bike lock"

1: https://www.wired.com/2004/09/twist-a-pen-open-a-lock/

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#12
post #9

This is sort of tangential, but: it doesn't make any sense that there's OCR going on in that process. Surely Amazon could just ask for the digital version of the book as a requirement for SearchInside participation?

Not sure how the specifics of this works on amazon but when I read it initially I assumed the results were returned as images which seems to make a little bit more sense, although possibly not that much.

Although reading it again it does seem to be quite unclear...

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#13
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Oh cmon some guy breaking into others system feels entitled to want cash prize. He should have been sent to prison for this. Breaking into someone's house is theft regardless wether owner forgot to lock the door. Same should be the matter with code. Is this really what the world has come to? Let's just break into neighbors house and tell them that their door failed against the latest gen plasma cutter. Now pay us bou…

Bug bounties are a) professional courtesy to say "thanks for telling us" and b) a way to incentivise someone to write up the bug report.

Otherwise, if I as a white hat discovered this bug, I might just not bother reporting it. I wouldn't exploit it, but the next guy might. Hence, bug bounty programs.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#14
Interesting, the "stitch together a bunch of substrings of a large string" task also comes up in DNA sequencing: the physical process basically randomly samples a bunch of snippets that are each a few hundred bases long, and you need to use software to detect overlaps combine them into one long sequence. It's a pretty heavily-researched computational problem, I believe. The author's simple algorithm seems to have worked, but I guess the DNA case is harder because you don't really have the "page number", you have a lot more snippets to combine, and snippets may have errors, with more errors occurring toward the ends.

Some information on the topic: https://en.wikibooks.org/wiki/Next_Generation_Sequencing_(NG...

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#15
The use of that feature to extract significant amounts of content was noticed over a decade ago by Fravia and his followers:

http://search.lores.eu/books.htm (near bottom of page)

Of course, back then it was the norm to publish this information in a place for those seeking information or otherwise "keep it tight", and not instead let them tighten the nooses around our necks by instantly snitching to the company for the hope of a paltry monetary reward...

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#16
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit.

Or sell it to someone who can make use of it.

It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#18
post #16
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door?

Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing?

I run a service that has a few users and makes about $200/mo. Someone once emailed me that they found a bug and whether I run a bug bounty program. I told them I couldn't really afford one and they never replied. Are they now morally justified to publicize the flaw?

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#19
post #4

Earlier quoted context omitted.

Yeah, I remember interviewing just after the merger when they opened the Cork office. I was 17, flew to Ireland, and the guy who was supposed to interview me face to face had taken a late lunch, so I got interviewed in about 5 minutes by someone who was clearly not interested, and it then took them 6 months to get back to me. Nice one, good job guys.

I imagine they get thousands of people applying a day. Sad you flew to Ireland, that's messed up that they forgot. The bad practices for me, are their pivoting toward lootbox pay2win gambling designs.

Are you sure? In their latest COD loot boxes do not contain anything pay to win. Same with Overwatch which falsely gets blamed for the whole lootbox thing we have going on atm - https://youtu.be/PTLFNlu2N_M

Destiny2 had some issue with theirs but didn’t they listen to the community and fix those.

I’m not a fan of loot boxes but their are not as bad as others in the industry.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#20
post #16

Earlier quoted context omitted.

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…

You can't afford aa bug bounty program. Amazon can.
Post reply on HN