Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

21–30 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#21

Earlier quoted context omitted.

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

but this is it: "This happened even when the issue was eventually patched..." which, based on that, I understand their gripe here

That would be a valid complaint if their report had been closed Not Applicable on the grounds that the behavior didn't present a significant security risk. But it wasn't; it was closed Not Applicable on the grounds that it was ineligible for the program regardless of whether it was a security risk.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#22

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Their "In-Scope Vulnerabilities" explicitly includes XSS exploits, though, which they also closed as Not Applicable (after patching the issue).

Tangentially, as a (former?) PayPal user, it's wild to see that they consider vulnerabilities involving stolen credentials as a non-issue. Why do they offer 2FA at all, then?

e: After taking another look at that massive Out-of-Scope list, I'm having a hard time imagining a bug that couldn't be closed as "Not Applicable." What a sham.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#23

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

All the more reason to not submit bugs like this to HackerOne. If you can bypass 2FA by having only one factor then I wouldn't consider that 'stolen credentials' and more a singular stolen credential. Their system is designed to defend against this and it does so ineffectively. That is, by definiton, a security issue.

I wish I could define what is and isn't a bug in my code at work. My defect rate would be incredible.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#24
post #9

Earlier quoted context omitted.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne. Sadly you can't feed your children from media drama. Maybe, in the long run, but it's more likely to get sued.

The market for a freelance security researcher out there is hard, no doubt, but disclosing bugs publically is an addition to your resume, akin to any other professional development you do. It demonstrates you can do the work and it shows the skills you have. Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.

> but disclosing bugs publically is an addition to your resume

Request disclosure on hackerone then. Idk, breaking the law to get a job doesn't seem ok to me.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#25

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

Yet paypal's policy explictly says authentication bypasses, like the 2FA bypass they showed, are in scope

>Authentication or authorization flaws, including insecure direct object references and authentication bypass

Reading with the context of the other out-of-scope issues. I think they meant that the ability to buy or steal someones credentials is not a vulnerability in and of itself.

>Vulnerabilities involving stolen credentials or physical access to a device

It is a poorly worded and confusing policy. Yet, if I found a 2FA bypass and I read that policy I would conclude that it is in scope and submit the issue.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#26

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

Are there other cases where PCI-DSS compliance requirements are selectively enforced?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#27

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

HackerOne, itself, is pretty generous about reported bugs. (As in, you reported an issue in the website hackerone.com.) They have to be, because their existence depends on everyone thinking bug bounty platforms are a good idea -- it's part of their way of encouraging people to hunt for bug bounties in general.

Payouts for bugs in other products are determined by those companies, not by H1.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#29

>When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level. This happened even when the issue was eventually patched, although we received no bounty, credit, or even a thanks. Instead, we got our Reputation scores (which start out at 100) negatively impacted, leaving us worse off than if we’d reported not…

They had out-of-scope issues closed as being out-of-scope, which automatically lowers their reputation on the platform. The researchers are outraged: > When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process. But Paypal's policy really couldn't be c…

The vulnerabilities they found allow bypassing the two factor auth so works with only part of the credentials

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#30

Earlier quoted context omitted.

but this is it: "This happened even when the issue was eventually patched..." which, based on that, I understand their gripe here

That would be a valid complaint if their report had been closed Not Applicable on the grounds that the behavior didn't present a significant security risk . But it wasn't; it was closed Not Applicable on the grounds that it was ineligible for the program regardless of whether it was a security risk.

hmm yes, I see your point
Post reply on HN