Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

1–10 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#2
>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported nothing at all.

That seems like a good way to make sure nobody trusts your business. What say you, hackerone? How can anyone trust this business acting against what ostensibly is its core functions.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#4
I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#6

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged:

> When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process.

But Paypal's policy really couldn't be clearer:

> Out-of-Scope Vulnerabilities

> Vulnerabilities involving stolen credentials or physical access to a device

( https://hackerone.com/paypal )

If Paypal says "don't send us this type of report", and you send one anyway, are you really surprised when your account gets a warning attached saying "this person usually files low-value reports"?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#8
post #5

Are hackerone analysts employees of the company? If so the conclusion drawn sounds like complete bs. If the analysts are just other users, then it definitely sounds like there is a problem.

not sure: https://www.hackerone.com/blog/Getting-to-know-the-HackerOne...

"When they aren’t triaging reports on our platform, they are spending time on their own bug bounty hunts."

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#9

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

Sadly you can't feed your children from media drama.

Maybe, in the long run, but it's more likely to get sued.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#10
post #5

Are hackerone analysts employees of the company? If so the conclusion drawn sounds like complete bs. If the analysts are just other users, then it definitely sounds like there is a problem.

Bug triagers may be employees of HackerOne, employees of the company (e.g. Paypal here), or contractors indirectly working for the company (I worked in this role for a year). They're not going to be random other researchers.

The screenshots in this article show a "HackerOne Staff" stamp, so those triagers are employees of H1.

Post reply on HN