Live data from Hacker News

Abusing Amazon‘s Look Inside feature to leak unreleased content

justmaku.org

21–30 of 33 posts

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#21
post #16
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

[deleted]

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#22
post #16

Earlier quoted context omitted.

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…

Your analogy has cause and effect reversed. The correct analogy is that if I know there is a reward for telling people their car doors are open, I will go around town specifically looking for open car doors. With no reward, I'm just going to go about my life not even looking at car doors.

Your service may be too small for this, but a company like Amazon typically saves money overall by running a bug bounty program because uncaught bugs can be extremely expensive.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#23

The use of that feature to extract significant amounts of content was noticed over a decade ago by Fravia and his followers: http://search.lores.eu/books.htm (near bottom of page) Of course, back then it was the norm to publish this information in a place for those seeking information or otherwise "keep it tight", and not instead let them tighten the nooses around our necks by instantly snitching to the company for t…

I think you should consider that some people need money more than a goofy clandestine comradery with other “information seekers” on the internet and also that bug bounties frequently exceed “paltry.”

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#24
post #16
post #2

> Disclaimer: Amazon doesn't have a bug bounty program and didn't offer anything other than thanks and gratefulness for bringing the vulnerability to their attention. Blizzard Entertainment (as the copyright holder for the book I was testing with) has also been notified of this vulnerability and has offered a small gift but never fulfilled that promise. I'm not surprised Amazon would pay with nothing more than a nice…

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

Sorry, that's ridiculous and borderline extortion. Sounds like protection money for the mob.

If there's any entitlement, it's within the small but vocal subset of security researchers that feel that unsolicited bug finding should be compensated under threat of public disclosure.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#25
post #22

Earlier quoted context omitted.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…

Your analogy has cause and effect reversed. The correct analogy is that if I know there is a reward for telling people their car doors are open, I will go around town specifically looking for open car doors. With no reward, I'm just going to go about my life not even looking at car doors. Your service may be too small for this, but a company like Amazon typically saves money overall by running a bug bounty program be…

The GP said "the next time someone finds a bug", ie the assumption is that a bug has been found. They didn't talk about whether bugs would be found or not.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#26

Earlier quoted context omitted.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…

You can't afford aa bug bounty program. Amazon can.

Does that make it moral for someone to disclose the bug? "This parking lot leaves cars unlocked, but since they seem busy and aren't paying me not to, it's okay if I tell thieves about it".

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#27

Earlier quoted context omitted.

I imagine they get thousands of people applying a day. Sad you flew to Ireland, that's messed up that they forgot. The bad practices for me, are their pivoting toward lootbox pay2win gambling designs.

Are you sure? In their latest COD loot boxes do not contain anything pay to win. Same with Overwatch which falsely gets blamed for the whole lootbox thing we have going on atm - https://youtu.be/PTLFNlu2N_M Destiny2 had some issue with theirs but didn’t they listen to the community and fix those. I’m not a fan of loot boxes but their are not as bad as others in the industry.

I was thinking hearthstone card packs as loot boxes, and they sort of popularized skinner boxes in games with the epic drops in wow

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#28
post #16

Earlier quoted context omitted.

Then next time someone finds an Amazon bug, they should release it 0-day on their blog for the lulz^H^H^H^H credit. Or sell it to someone who can make use of it. It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.

If you find that someone forgot their car door open, do you deserve money for not telling thieves where you can find a car with an open door? Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing? I run a service that has a few users and makes about $200/mo. Someone once email…

Selling zero day exploits is an amoral act.

That being said, your analogy is broken and doesn't fit here at all. First, parking lots are passive and have no intelligence. Amazon is neither of those things. Also, there are no such people who dedicate their career to lawfully testing the security of parking lots in exchange for money.

In the real world of mega corporation technology (which is almost as different from a parking lot as you can get) there are countless black hats motivated by money to steal from Amazon, and countless grey hats who would help combat or mitigate the issues if properly compensated. White hats are the rare exception and report issues even without compensation.

There are numerous grey hats who: 1) If there is a bug bounty program, would report the issue to be fixed 2) else, would ignore the issue entirely.

You know this is true because you experienced it yourself. The difference is you can't afford the service of a grey hat.

So forget the morality of these hackers.

Amazon refusing to pay out a bug bounty program is amoral. Because what you're seeing is Amazon trading the security of their customers, and for what? Greed and hubris it seems.

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#29

Earlier quoted context omitted.

Are you sure? In their latest COD loot boxes do not contain anything pay to win. Same with Overwatch which falsely gets blamed for the whole lootbox thing we have going on atm - https://youtu.be/PTLFNlu2N_M Destiny2 had some issue with theirs but didn’t they listen to the community and fix those. I’m not a fan of loot boxes but their are not as bad as others in the industry.

I was thinking hearthstone card packs as loot boxes, and they sort of popularized skinner boxes in games with the epic drops in wow

> epic drops in wow

Which was a feature in games before WoW but isn't a pay to win mechanic as you can not pay for "drops". WoW for the longest time refused to have a real money gold shop as was more that people were buying in game gold from 3rd parties anyway so might as well make a safe way to do it (which isn't a direct cash for gold transaction, more that another player has to buy your game time token, but that will usually happen within 30 mins).

As for hearthstone I would lay the blame more at Magic: The Gathering Online personally (though not the first), but I see you point that the game has very popular and became the "cardboard crack" that IRL Magic was (Atleast with Magic: The Gathering Online you could trade / sell your online cards with others until you piss off WotC and they nuke your account).

Re: Abusing Amazon‘s Look Inside feature to leak unreleased content

#30

Earlier quoted context omitted.

I was thinking hearthstone card packs as loot boxes, and they sort of popularized skinner boxes in games with the epic drops in wow

> epic drops in wow Which was a feature in games before WoW but isn't a pay to win mechanic as you can not pay for "drops". WoW for the longest time refused to have a real money gold shop as was more that people were buying in game gold from 3rd parties anyway so might as well make a safe way to do it (which isn't a direct cash for gold transaction, more that another player has to buy your game time token, but that w…

another similar recent move was the widespread disdane mobile Diablo got at blizzcon, fun YouTube clips of that.

My point about the drops is that skinner boxes are dangerous. My RA flunked out due to wow. Some small group of people really struggle with casino stuff

Post reply on HN