Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

201–210 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#201

Earlier quoted context omitted.

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

They "clearly aren't up to the responsibility"? Paypal has one of the larger application security teams in SFBA. You've decided they're not qualified because someone reported a self-XSS and Paypal didn't freak out? Did you read downthread about the actual "2FA" feature this team "bypassed"?

> Paypal has one of the larger application security teams in SFBA.

It's not the size that matters, but how you use it that counts.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#202

Earlier quoted context omitted.

reading both, looks to me like this is pretty much 2fa. isn't 2fa defined as a "second factor" beyond user:pass? isn't that what this bypass is about?

There is genuine disagreement about whether email qualifies as a second factor. As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor. I will say, that if cybernews have done what they say that they've done, and PayPal are claiming that it's not a concern, then PayPal are clearly in the wrong, an…

> As it is often just protected by a username and password the argument is that it's the same "something you know" factor as a password, or just an obfuscation of the same factor.

All factors are just varying obfuscations of "something you know" when you get down to it though.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#203

Earlier quoted context omitted.

Who would you like to be upset with in a case where the black market is more efficient than HackerOne? If the legitimate channels are not working then the system is broken and you should blame PayPal and HackerOne. Be pissed at PayPal for not making it easier to report real issues. Be pissed at PayPal for not finding the issues themselves.

Or, and I know this might be hard to grasp if you're the kind of unscrupulous individual who would sell exploits to criminals, I could also blame the unscrupulous individual who sold exploits to criminals. Are they deserving of a pass for some reason? Fuck them.

Bad Guys exist and we can't ignore them, like it or not. A head-in-the-sand approach is not good for security either. Yes, fuck the bad guys but seriously fuck those that refuse to acknowledge and fix real issues.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#204

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> 1. They can suppress a new-computer login challenge (they call this "2FA", but this is a risk-based login or anti-ATO feature, not 2FA).

2FA means 2 Factor Authentication. This works by forcing one to use two different forms of identification to authenticate, such as login/password and, in this case, identification of the computer used.

So, with all respect sir, what I'm saying is while this isn't the best 2FA, it absolutely IS 2FA by definition.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#205

I've had plenty of problems with bug bounty platforms and have completely stopped doing them. But most/all of these "critical" reports aren't critical and some of the behavior of their "researchers" is unprofessional at best. There's maybe one legit report here, and that's #2. #1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy." So you need to be MITM'd…

Although I rejected many similar MITM reports myself, in this case I think this is valid threat. It's not some random comments or forum site where there's almost no value for attackers, we're talking on pseudo-banking system, where users have usually at even few credit cards hooked and/or some account balance, and indeed there are many places you can buy leaked/stolen stolen credentials. Ability to bypass automatic 2FA by hackers is little alarming for service where users may lost $1000+. This simply should be fixed and some bounty should be paid for it (of course probably not maximum bounty, but still).

#5 and #6 are indeed exaggerated, especially that even if hacker has stolen credentials, and bypassed automatic 2FA, security question won't be displayed on same page users use to confirm payment (to replace e-mail address), or keylog credit card information.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#206

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> 1. They can suppress a new-computer login challenge (they call this "2FA", but this is a risk-based login or anti-ATO feature, not 2FA). 2FA means 2 Factor Authentication. This works by forcing one to use two different forms of identification to authenticate, such as login/password and, in this case, identification of the computer used. So, with all respect sir, what I'm saying is while this isn't the best 2FA, it…

No.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#207

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

What does "broken" mean here? If the development team is unresponsive, what do you expect H1's response to be?

H1 used to have a mechanism where researchers could push to make raised issues public if a ticket was ignored or marked as wontfix.

That was a good way to keep companies honest, an implementation of responsible disclosure.

So H1 could implement that again. It doesn't get them a bounty but it does stop companies pretending reports don't exist, if that's what has happened here.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#208

Earlier quoted context omitted.

> HackerOne states they are a PCI-DSS auditor approved organization Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne. ---- EDIT: I guess you are referring to this: > Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certif…

> Not anywhere on the page you linked. Read the page carefully - it specifically states they are an auditor approved org. Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].” Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they c…

Even if HackerOne were a company that is licensed to do PCI DSS scans, they were not contracted by PayPal to do it. A PCI DSS scanning company cannot just do independent audits for PCI compliance unless solicited by the target. The auditing process you are referencing is not related at all to reports by unsolicited scanners.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#209

Earlier quoted context omitted.

What does "broken" mean here? If the development team is unresponsive, what do you expect H1's response to be?

H1 used to have a mechanism where researchers could push to make raised issues public if a ticket was ignored or marked as wontfix. That was a good way to keep companies honest, an implementation of responsible disclosure. So H1 could implement that again. It doesn't get them a bounty but it does stop companies pretending reports don't exist, if that's what has happened here.

If you have a Squid RCE, what prevents you from getting a CVE for it, writing a blog post, and announcing on Twitter?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#210
HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report.

What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to PortSwigger (and Uber was running some promotional for a free three month license for Burp Proxy).

HackerOne completely sided with Uber on everything, gave the Portswigger kid $25K and that was that.

So, in summary: HackerOne is trash, and Burp Proxy may contain backdoor functionality which is relayed directly back to Portswigger whenever a high value critical vulnerability is discovered with it.

Post reply on HN