> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…
Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
Abusing Amazon‘s Look Inside feature to leak unreleased content
21–30 of 33 posts
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#22Earlier quoted context omitted.
Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…
Your service may be too small for this, but a company like Amazon typically saves money overall by running a bug bounty program because uncaught bugs can be extremely expensive.
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#23The use of that feature to extract significant amounts of content was noticed over a decade ago by Fravia and his followers: http://search.lores.eu/books.htm (near bottom of page) Of course, back then it was the norm to publish this information in a place for those seeking information or otherwise "keep it tight", and not instead let them tighten the nooses around our necks by instantly snitching to the company for t…
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#24> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…
Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
If there's any entitlement, it's within the small but vocal subset of security researchers that feel that unsolicited bug finding should be compensated under threat of public disclosure.
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#25Earlier quoted context omitted.
If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…
Your analogy has cause and effect reversed. The correct analogy is that if I know there is a reward for telling people their car doors are open, I will go around town specifically looking for open car doors. With no reward, I'm just going to go about my life not even looking at car doors. Your service may be too small for this, but a company like Amazon typically saves money overall by running a bug bounty program be…
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#26Earlier quoted context omitted.
If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…
You can't afford aa bug bounty program. Amazon can.
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#27Earlier quoted context omitted.
I imagine they get thousands of people applying a day. Sad you flew to Ireland, that's messed up that they forgot. The bad practices for me, are their pivoting toward lootbox pay2win gambling designs.
Are you sure? In their latest COD loot boxes do not contain anything pay to win. Same with Overwatch which falsely gets blamed for the whole lootbox thing we have going on atm - https://youtu.be/PTLFNlu2N_M Destiny2 had some issue with theirs but didn’t they listen to the community and fix those. I’m not a fan of loot boxes but their are not as bad as others in the industry.
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#28Earlier quoted context omitted.
Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…
That being said, your analogy is broken and doesn't fit here at all. First, parking lots are passive and have no intelligence. Amazon is neither of those things. Also, there are no such people who dedicate their career to lawfully testing the security of parking lots in exchange for money.
In the real world of mega corporation technology (which is almost as different from a parking lot as you can get) there are countless black hats motivated by money to steal from Amazon, and countless grey hats who would help combat or mitigate the issues if properly compensated. White hats are the rare exception and report issues even without compensation.
There are numerous grey hats who: 1) If there is a bug bounty program, would report the issue to be fixed 2) else, would ignore the issue entirely.
You know this is true because you experienced it yourself. The difference is you can't afford the service of a grey hat.
So forget the morality of these hackers.
Amazon refusing to pay out a bug bounty program is amoral. Because what you're seeing is Amazon trading the security of their customers, and for what? Greed and hubris it seems.
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#29Earlier quoted context omitted.
Are you sure? In their latest COD loot boxes do not contain anything pay to win. Same with Overwatch which falsely gets blamed for the whole lootbox thing we have going on atm - https://youtu.be/PTLFNlu2N_M Destiny2 had some issue with theirs but didn’t they listen to the community and fix those. I’m not a fan of loot boxes but their are not as bad as others in the industry.
I was thinking hearthstone card packs as loot boxes, and they sort of popularized skinner boxes in games with the epic drops in wow
Which was a feature in games before WoW but isn't a pay to win mechanic as you can not pay for "drops". WoW for the longest time refused to have a real money gold shop as was more that people were buying in game gold from 3rd parties anyway so might as well make a safe way to do it (which isn't a direct cash for gold transaction, more that another player has to buy your game time token, but that will usually happen within 30 mins).
As for hearthstone I would lay the blame more at Magic: The Gathering Online personally (though not the first), but I see you point that the game has very popular and became the "cardboard crack" that IRL Magic was (Atleast with Magic: The Gathering Online you could trade / sell your online cards with others until you piss off WotC and they nuke your account).
Re: Abusing Amazon‘s Look Inside feature to leak unreleased content
#30Earlier quoted context omitted.
I was thinking hearthstone card packs as loot boxes, and they sort of popularized skinner boxes in games with the epic drops in wow
> epic drops in wow Which was a feature in games before WoW but isn't a pay to win mechanic as you can not pay for "drops". WoW for the longest time refused to have a real money gold shop as was more that people were buying in game gold from 3rd parties anyway so might as well make a safe way to do it (which isn't a direct cash for gold transaction, more that another player has to buy your game time token, but that w…
My point about the drops is that skinner boxes are dangerous. My RA flunked out due to wow. Some small group of people really struggle with casino stuff