Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

161–170 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#161
post #156

Earlier quoted context omitted.

> I guess my confusion now is why PayPal even purports to offer bug bounties if they're going to craft an "out of scope" list that allows them to reject every submitted report. They're not; you're just choosing to assume bad things about them. Their out-of-scope list is fairly standard. If you asked a guy on the street "what would hacking PayPal look like?", the answer they imagined would probably be in scope. For ex…

> automatically sends $500 to my PayPal account, that’s in scope. Nope. From the out of scope list: > Attacks involving payment fraud, theft, or malicious merchant accounts

You're misinterpreting it.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#162

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

This is what I was thinking. The only stories I ever see about HackerOne are how horrible they are. As a non-sec dev, I only ever get the feeling that bounty hunting for profitability is the same as trying to sell something on eBay. You're eventually going to get scammed and you have to eat the loss.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#163

I've had plenty of problems with bug bounty platforms and have completely stopped doing them. But most/all of these "critical" reports aren't critical and some of the behavior of their "researchers" is unprofessional at best. There's maybe one legit report here, and that's #2. #1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy." So you need to be MITM'd…

[deleted]

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#164

I've had plenty of problems with bug bounty platforms and have completely stopped doing them. But most/all of these "critical" reports aren't critical and some of the behavior of their "researchers" is unprofessional at best. There's maybe one legit report here, and that's #2. #1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy." So you need to be MITM'd…

I agree that none of these reports could be considered "critical." I also agree that the tone is a bit unprofessional. I'd add that I generally find these publicity pushes using fairly bland findings to be distasteful. All that being said, I'd like to clarify a bit based on my read of #1.

> #1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy."

> So you need to be MITM'd and have a malicious cert installed? Yeah... not "critical" and out-of-scope for most places.

In generally, using a proxy to perform a 2FA bypass wouldn't decrease the risk. In this case, the attacker already has compromised credentials, and they are trying to bypass the secondary control. As they are the one authenticating, the need for MiTM isn't a huge deal.

That being said, another point that was made is that the "2FA" they are bypassing isn't actually Paypal's 2FA. Instead, it is a secondary, risk-based validation. A bit of a semantic difference, but important to note that if a user was leveraging 2FA this bypass wouldn't actually get an attack who had compromised credentials access.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#166

Earlier quoted context omitted.

As someone who deals with PCI-DSS compliance in fintech land on a daily basis this thread is showing me there are a lot of people who like to crow on about stuff they don't know a thing about.

Indeed. However, it's refreshing to see a HN thread that's defending vendor snakeoil instead of assuming all infosec is vendor snakeoil.

[deleted]

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#167

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

There is no doubt that the PCI-DSS is a farce.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#168
post #148

Earlier quoted context omitted.

Yet paypal's policy explictly says authentication bypasses, like the 2FA bypass they showed, are in scope >Authentication or authorization flaws, including insecure direct object references and authentication bypass Reading with the context of the other out-of-scope issues. I think they meant that the ability to buy or steal someones credentials is not a vulnerability in and of itself. >Vulnerabilities involving stol…

They apparently have fake / security theater 2FA, where things are as inconvenient as 2FA, but pay pal explicitly doesn’t care that it’s easily bypassed, and full of security bypasses. They also have opt-in 2FA. It’s unclear which one the author bypassed. Perhaps the confusion is by design on paypal’s side? Presumably giving people a false sense of security helps them close disputes without paying out?

I think the confusion results from attempting to encode "use good judgement" in formal language. I suspect the reason they talk about stolen accounts being out of scope is because someone bought a bunch of stolen accounts and then demanded a bounty.

Completeness or consistency (choose one)

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#169
post #120

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

> HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Completely disagree with this. I launched a HackerOne program for my company last month (for free, not using their “managed” service). Of the many reports people submitted, we triaged 30-40 valid reports (most very minor, one or two moderate). We paid out a few thousand dollars in rewards. At the same time, we also did a more tradition…

You are not disagreeing. The grandparent is saying that H1 isn't great for researchers.

For companies, it might as well be very good, both for honest ones, and ones just looking to "cover their ass".

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#170
post #94
post #73

Earlier quoted context omitted.

I worked as a contractor for a company that's a household name in the US. I am now convinced that HackerOne only exists for CISOs to say "look, I'm doing something" during the 2-3 years they stay at a company. The cybersecurity team had a backlog of roughly 30 critical issues discovered internally before starting HackerOne. We were unable to fix those issues, or the ones reported to us, because we had no visibility i…

Ohh your very right. The sales team is very focused on "selling" to the CISO (rightly so I suppose). I was part of a team that got the big sales pitch. Little technical details, high on "let us handle this for you, we know hackers / Well throw a big Defcon party for anyone you want."

[deleted]
Post reply on HN