Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

191–200 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#191
post #16

Earlier quoted context omitted.

Oh so an N/A dupe? That sounds plausable.

The policy of the company I worked for was only to dupe to closed issues if those issues were Resolved -- if the duplicate issue was already closed Informational or N/A, we just closed the new one with the same status. This has advantages in avoiding researcher confusion, as illustrated here. But that was a company policy, not an H1 policy. It's perfectly possible to dupe to a closed issue. (And of course, it's also…

Could you could state that the newly reported issue is both duplicate and that the original report was closed as N/A?

Not applicable typically means the reporter is free to try to argue that is in fact applicable, but by stating it's both duplicate and N/A neither the second reporter nor the company will spend further time arguing back and forth, as even if the issue was applicable the credit would go to the original reporter.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#192

Earlier quoted context omitted.

The point of being a branded platform is that you take responsibility for the activity on your platform. Otherwise you are just an email gateway.

It is possible to escalate your dispute with a company to H1 itself. They'll review the report and the company's policy, and they may contact the triager or the company to try to resolve any questions. I wouldn't do that as a regular thing; you're pretty well guaranteed to piss off everyone on the company's side of things. I should note that I've personally seen probably in excess of $100,000 paid out through H1; the…

That sounds like it's a payout lottery. H1 can't force its customers to pay. It's acting as a go-between on behalf of its customer, the company offering the bounty, not as an neuteal arbiter when there is a dispute.

Perhaps I would take them seriously if there was an escrow account companies paid into and was released to the reporting party when a plurality of multiple, disinterested parties agreed that the report was valid.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#193
post #9

Earlier quoted context omitted.

> I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne. Sadly you can't feed your children from media drama. Maybe, in the long run, but it's more likely to get sued.

> Sadly you can't feed your children from media drama. So it seems like the real answer in these cases is selling the exploit on the "dark web". I mean why not? The vendor doesn't seem to care about security anyway.

"Dark web" for things that are not relevant to Five Eyes and NSA when they are relevant. At least in those cases, with good opsec for the "dark web", you can be reasonably sure the company who made the product can't retaliate against you.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#195

Earlier quoted context omitted.

I'm sure that'll be a great comfort to the victims of whoever those flaws are sold to.

Who would you like to be upset with in a case where the black market is more efficient than HackerOne? If the legitimate channels are not working then the system is broken and you should blame PayPal and HackerOne. Be pissed at PayPal for not making it easier to report real issues. Be pissed at PayPal for not finding the issues themselves.

Or, and I know this might be hard to grasp if you're the kind of unscrupulous individual who would sell exploits to criminals, I could also blame the unscrupulous individual who sold exploits to criminals. Are they deserving of a pass for some reason? Fuck them.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#196
post #102

Earlier quoted context omitted.

Full disclosure isn't a crime in the United States, at least.

Hacking PayPal is a crime tho'. Except for when you play their game, which means: submit bugs via h1 and only disclose if they allow.

Legitimately interested in your explanation as to how this specific research would be a crime absent contact with HackerOne. Please cite statute. I'm not saying you're wrong - simply asking you to back up your claim with evidence.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#197

PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. According to this image [2], they did not respond…

How is this the top comment on the thread? Do people really believe that failing to respond to a self-XSS report on HackerOne to the satisfaction of the reporter would cause someone to lose their PCI certification?

> failing to respond to a self-XSS report

This really downplays the report or shows a complete lack of understanding.

Getting access to someone's Paypal account which could potentially mean all their credit cards and banks is definitely an issue that needs to be addressed. This in itself should not be reason to lose PCI certification.

However, as the article further indicates [1], failure to respond (or even closing the issue without resolving) is a completely different story.

[1] https://cybernews.com/security/we-found-6-critical-paypal-vu...

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#198
People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for strong findings.

Here are the vulnerabilities in their report:

1. They can suppress a new-computer login challenge (they call this "2FA", but this is a risk-based login or anti-ATO feature, not 2FA).

2. They can register accounts for one phone, then change it to another phone, to "bypass" phone number confirmation.

3. There are risk-based controls in Paypal that prevent transactions when anomalies are detected, and some of them can apparently be defeated with brute force.

4. They can change names on accounts they control.

5. They found what appears to be self-XSS in a support chat system.

6. They found what appears to be self-XSS in the security questions challenge inputs.

None of these are sev:hi vulnerabilities, let alone "critical". 2 of them --- #4 and #6 --- are duplicates of other people's issues. Self-XSS vulnerabilities are often excluded entirely from bounty programs.

For the last 3 hours, the top comment on this thread has been an analysis saying that, because Paypal is PCI-encumbered, and HackerOne reports can function as "assessments" for PCI attestations, Paypal is in danger of losing its PCI status (and the fact that it won't is evidence that they are "too big to fail"). To put it gently: that is not how any of this stuff works. In reality, formal bug bounty programs are a firehose of reports suggesting that DKIM configuration quirks are critical vulnerabilities, and nobody in the world would expect any kind of regulatory outcome simply from the way a bounty report does or doesn't get handled. It should, I hope, go without saying that nobody is required to run a bounty in the first place, and most companies probably shouldn't.

The login challenge bypass finding was actually interesting (it would be more interesting if they fully disclosed what it was and what Paypal's response was). But these reporters have crudded up their story with standard bug-bounty-reporter hype, and made it very difficult to judge what they found. I'm inclined not to believe their claim that Paypal acted abusively here (and I am not a fan of Paypal).

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#199

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

What does "broken" mean here? If the development team is unresponsive, what do you expect H1's response to be?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#200

Earlier quoted context omitted.

How is this the top comment on the thread? Do people really believe that failing to respond to a self-XSS report on HackerOne to the satisfaction of the reporter would cause someone to lose their PCI certification?

> failing to respond to a self-XSS report This really downplays the report or shows a complete lack of understanding. Getting access to someone's Paypal account which could potentially mean all their credit cards and banks is definitely an issue that needs to be addressed. This in itself should not be reason to lose PCI certification. However, as the article further indicates [1], failure to respond (or even closing…

It's not at all clear to me what you're saying here. Are you making a case that the whole report all put together is impactful? Or are you actually trying to argue that self-XSS is a critical security vulnerability?
Post reply on HN