Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

111–120 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#112

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

My suspicion is that Paypal is now "too big to fail" and will suffer very little consequences if none at all.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#113
post #83

Earlier quoted context omitted.

Sorry, but you don't understand what you are looking at. All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. And the "scans" the PCI-DSS standards refers to are standard pen-test and external vulnerability scans, usually conducted by an accounting company who will ce…

> All of HackerOne's information that you cite is about them being PCI-DSS-compliant or having undergone a SOC2 Type 2 audit. Nothing you link to identifies them as a PCI-DSS auditing company. They are not. Please read the page again. They specifically say you can achieve compliance certification with HackerOne.

You achieve that compliance by paying HackerOne, as a company, to perform a compliance scan. This does not mean any swinging dick that reports a vulnerability through HackerOne is causing PayPal to fall out of compliance. These scans are planned well in advance and are part of a normal audit cycle. (edit: typo)

On top of that, there's not really any legal issues for being non-compliant, as has been pointed out elsewhere in this thread.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#114
post #5

Are hackerone analysts employees of the company? If so the conclusion drawn sounds like complete bs. If the analysts are just other users, then it definitely sounds like there is a problem.

Bug triagers may be employees of HackerOne, employees of the company (e.g. Paypal here), or contractors indirectly working for the company (I worked in this role for a year). They're not going to be random other researchers. The screenshots in this article show a "HackerOne Staff" stamp, so those triagers are employees of H1.

So it’s pretty far fetched that they would be purposely delaying reports so they could steal the rewards.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#115

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

How is this the top comment on the thread? Do people really believe that failing to respond to a self-XSS report on HackerOne to the satisfaction of the reporter would cause someone to lose their PCI certification?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#116

Earlier quoted context omitted.

GDPR max fine is (iirc) 4% of revenue. So if you are a small fish you will be paying less then the big fish. Also the fines are for wilful failure to comply, if you accidentally broke GDPR then your first offence is going to be more a slap on the wrist then an instant 4%.

Except it says "whichever" is higher, so if they decided to fine you 10 million or 2% of revenue, and your 2% is much lower than 10 million, guess which one you're paying... > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher See: https://www.gdpreu.org/compliance/fines-and-penalties/

They key part there is "if they decide to fine you...".

The max(€10m, 2%) and max(€20m, 4%) are the most that supervisory authorities may issue as fines.

But supervisory authorities have a legal duty to issue fines that are proportional which means than unless you breach the GDPR in a wilful and egregious manner you're unlikely to be fined that much (and if you are you can appeal the fine to a court who would reduce it to a proportional amount).

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#117
post #107

Earlier quoted context omitted.

What is their certificate number?

> If PayPal’s PCI-DSS compliance certification isn’t revoked then PCI-DSS is a farce. This comment chain has convinced me that PCI-DSS is a farce.

Pretty much. All it really proves is that an org meets a bare minimum of security standards. As noted elsewhere in the thread, it's used more for marketing and to serve as a "hey look at us we're self-regulating within industry!" than anything else.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#118
I know of a really nice vulnerability but I know when to shut up. I almost scammed a legitimate business by mistake. Made sure to pay them with a normal bank transfer instead. Don't want to complain in case their account gets closed down or something. Not touching PayPal again.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#119

Earlier quoted context omitted.

We read the page, and even if your claim holds, it is still irrelevant because whatever you quoted is not the same as being a PCI-DSS approved scanning vendor. And even if it was, HackerOne did not perform any scans. HackerOne offering PCI-DSS approved auditor approved challenges gets you nowhere towards the claims you made in your first comment. To review: 1. HackerOne would have to be a PCI DSS Approved Scanning Ve…

“SATISFY COMPLIANCE CERTIFICATION REQUIREMENTS Meet pentest requirements for PCI DSS, SOC2 Type II, and HITRUST compliance certifications.” [1] [1] https://www.hackerone.com/product/pentest

Can you remind me again why hackerone is relevant here? Who claimed where that they performed a PCI DSS external scan that failed?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#120

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

> HackerOne appears to be completely broken and I wouldn't recommend it to anyone.

Completely disagree with this.

I launched a HackerOne program for my company last month (for free, not using their “managed” service).

Of the many reports people submitted, we triaged 30-40 valid reports (most very minor, one or two moderate). We paid out a few thousand dollars in rewards.

At the same time, we also did a more traditional 2-week penetration test with Cobalt (https://cobalt.io/) that cost over $10,000, and HackerOne was the clear winner when it came to the number of high quality security reports worth fixing. And H1 was 2-3x cheaper after paying out the bounties.

I’m sure HackerOne isn’t great for all companies, but just posting this to refute the blanket statement that HackerOne is “completely broken” across the board.

Post reply on HN