Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

231–240 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#231

Earlier quoted context omitted.

> No. Please explain which parts of my comment are false? Thank you.

This feature is not 2FA, and your argument is incoherent even if you fix the terminology, because many anti-ATO systems are heuristic and intriniscally "bypassable" by design, and yet you still want services to have them. ATO is an arms race.

> This feature is not 2FA

> anti-ATO

ATO [1] is authentication by definition, but again, depending on how it's implemented, not usually the best form.

[1] https://csrc.nist.gov/glossary/term/authorization-to-operate

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#232

I've had plenty of problems with bug bounty platforms and have completely stopped doing them. But most/all of these "critical" reports aren't critical and some of the behavior of their "researchers" is unprofessional at best. There's maybe one legit report here, and that's #2. #1 "In order to bypass PayPal’s 2FA, our researcher used the PayPal mobile app and a MITM proxy, like Charles proxy." So you need to be MITM'd…

> So you need to be MITM'd and have a malicious cert installed? No. The attacker is the man in the middle to himself , because why are you trusting the client . > A "security" flaw that requires stolen creds and brute forcing isn't going to get much traction anywhere. The feature is meant to stop people from using stolen creds. It does not work. Given that stolen creds exist, that sounds like a security flaw to me.

As far as I can tell, "it's impossible to use stolen credentials" is not part of Paypal's security model or a promise that Paypal has actually made. It's important to distinguish flaws in a company's security model from additional security controls we think they ought to add.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#233

Earlier quoted context omitted.

I'm sure that'll be a great comfort to the victims of whoever those flaws are sold to.

Who would you like to be upset with in a case where the black market is more efficient than HackerOne? If the legitimate channels are not working then the system is broken and you should blame PayPal and HackerOne. Be pissed at PayPal for not making it easier to report real issues. Be pissed at PayPal for not finding the issues themselves.

The failure of the legitimate market causally explains the emergence of a black market.

It doesn’t morally vindicate people who sell exploits on the black market.

This is, I don’t know, kindergarten-level ethics? I’m flabbergasted at the self-serving rationalizations here.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#235

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies:

> Anyone can write malicious code into the chatbox and PayPal’s system would execute it. Using the right payload, a scammer can capture customer support agent session cookies and access their account.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#236

Earlier quoted context omitted.

> HackerOne states they are a PCI-DSS auditor approved organization Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne. ---- EDIT: I guess you are referring to this: > Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certif…

> Not anywhere on the page you linked. Read the page carefully - it specifically states they are an auditor approved org. Quote from page: “Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.[1].” Secondly, PayPal works with HackerOne officially [2] and within the CVSS standards as they c…

> Read the page carefully

Emphasis mine.

"...satisfy the requirements for external penetration testing for audited PCI DSS and SOC2 Type II certifications."

"Final Report Delivered. Ready for Auditors."

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#237

Earlier quoted context omitted.

Who would you like to be upset with in a case where the black market is more efficient than HackerOne? If the legitimate channels are not working then the system is broken and you should blame PayPal and HackerOne. Be pissed at PayPal for not making it easier to report real issues. Be pissed at PayPal for not finding the issues themselves.

The failure of the legitimate market causally explains the emergence of a black market. It doesn’t morally vindicate people who sell exploits on the black market. This is, I don’t know, kindergarten-level ethics? I’m flabbergasted at the self-serving rationalizations here.

To be clear, I am not personally advocating the use of the black market to sell exploits. I'm saying that the black market may be more attractive in cases like this and that anger at the black market in this case is misguided. The failure is with PayPal and/or HackerOne in this case. When the black market is more efficient that is a failure of the legitimate marketplace and you should place your anger with the legitimate marketplace that failed.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#238

Earlier quoted context omitted.

> Or they simply don't want their stuff stolen? Equating credit card fraud to physical theft is silly. The intermediaries of the credit card industry earn revenue by charging fees to process transactions. When fraud occurs, they're only liable if they were some how responsible. PCI allows the network to shift liability to the periphery and to allow the central network to deny taking responsibility for systemic proble…

"Equating credit card fraud to physical theft is silly. " In both cases someone is out money. It isn't a difficult step. Fraud costs the credit card industry. It costs issuers (they shoulder 60% of the direct cost), merchants, and it costs the future of the industry because it is a nuisance for end-users. They make a standard of best practices to reduce fraud. Following those best practices is good for every single p…

No one is denying fraud has a cost or that there's benefit to mitigating it. Mitigation comes at a cost and so there is a cost/benefit analysis performed by stake holders to determine the scope of mitigation employed.

PCI identifies recommended mitigations and imposes penalties for failures, but it doesn't ensure or validate compliance. It simply shifts liability from one stakeholder to another.

No one is spinning this as nefarious, but rather information that should be taken into consideration.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#239
post #159

My two last reports were closed as duplicate. I got some rep for one, and zero rep for the other. Both were real vulnerabilities. It is strange the reputation reward is not consistent.

According to HackerOne help page on reputation, it depends on the status of the vulnerability: yet undisclosed, not applicable, publicly known...

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#240

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

For #5 I believe it's not just a self-XSS, but also executes on the support agents browser, allowing you to potentially exfiltrate their cookies: > Anyone can write malicious code into the chatbox and PayPal’s system would execute it. Using the right payload, a scammer can capture customer support agent session cookies and access their account.

Yeah, they probably should have included a POC of the attack on initial submit. That one got patched after the N/A. That's pretty sad.

For example, under example quality reports, POCs are provided

https://hackerone.com/reports/32825

https://docs.hackerone.com/programs/quality-reports.html

Post reply on HN