Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

241–250 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#241
> Most ethical hackers will remember the 2013 case of Robert Kugler, the 17-year old German student who was shafted out of a huge bounty after he discovered a critical bug on PayPal’s site. Kugler notified PayPal of the vulnerability on May 19, but apparently PayPal told him that because he was under 18, he was ineligible for the Bug Bounty Program.

>But according to PayPal, the bug had already been discovered by someone else, but they also admitted that the young hacker was just too young.

Bad PR like this shows that bug bounty programs are probably more trouble than they’re worth.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#242
I have no experience, but it seems to me that a bug bounty program would be ripe for abuse by employees intercepting reports, feeding them to a partner hacker, and then splitting the bounty between themselves. What stops that from happening?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#243

Earlier quoted context omitted.

This feature is not 2FA, and your argument is incoherent even if you fix the terminology, because many anti-ATO systems are heuristic and intriniscally "bypassable" by design, and yet you still want services to have them. ATO is an arms race.

> This feature is not 2FA > anti-ATO ATO [1] is authentication by definition, but again, depending on how it's implemented, not usually the best form. [1] https://csrc.nist.gov/glossary/term/authorization-to-operate

Authorization is not authentication, by definition. Furthermore, your link is talking about an entirely unrelated meaning of ATO. I believe tptacek meant it to stand for "account take-over".

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#244

Earlier quoted context omitted.

i think you might want to take a breath, rethink that position and not let your anger cause you to do something stupid. if you disclose a vulnerability, the company HAS EVERY RIGHT to sue you. every security researcher _thinks_ that they are protected by some unwritten good Samaritan law, when in fact, you are hacking and that carries financial and criminal penalties. this is why these bug bounties and established wa…

> not let your anger cause you to do something stupid Note: I didn't say that I would do this for every company. Just ones that use HackerOne. They have decided to abdicate their responsibility for their security vunerability reporting, and I feel completely justified in dumping info on their vulnerabilities. Releasing the details of a vulnerability is not stupid. The users of the software/service deserve to know the…

i'm not going to argue with you. if your actions and attitude get you in trouble, it won't affect me in the least nor do i care. so if you want to continue to be self-righteous and say and do stupid things, that's on you.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#245

Earlier quoted context omitted.

i think you might want to take a breath, rethink that position and not let your anger cause you to do something stupid. if you disclose a vulnerability, the company HAS EVERY RIGHT to sue you. every security researcher _thinks_ that they are protected by some unwritten good Samaritan law, when in fact, you are hacking and that carries financial and criminal penalties. this is why these bug bounties and established wa…

Insane comment. As a customer of these companies, this attitude is borderline criminal and a big cause of the repeated data breaches. Why should I trust any company that sues security researchers for disclosure?

"Why should I trust any company that sues security researchers for disclosure?"

i didn't say that, i said there are established channels for reporting such things and going outside those channels carries risks.

edit*

my bad... i read your comment wrong.

i could be wrong, but i think you meant to say "Why should I trust any company that sues security researchers for reporting a vulnerability?"

i agree that that would totally suck.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#246

Earlier quoted context omitted.

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

It's not a regulation. It's a contractual obligation between the merchant and the PCI counsel (which is made up by VISA/Mastercard/the backing banks/etc). It was put in place to avoid regulation.

regulation: noun. a rule or directive made and maintained by an authority.

Regulations can be self-imposed on an industry, it does not have to be something the government imposes. Calling PCI-DSS a regulation is still accurate despite many people conflating the term "regulation" solely with government action. In this case, the authority creating the regulations is the PCI Security Standards Council who have their power because the big players in the industry give it to them.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#247

I have not used Paypal since I had to file a dispute over an item I bought on ebay via Paypal. As a response they snail-mailed me a bunch of screenshots of an internal web-app with a bunch of info for someone else, SSN, CC number, address, etc. Everything I would need to do something bad. I called them and they did not seem to care so I called the guy (I had his number of course) but he never answered or responded to…

> Then there was a long pause (I guess they assumed the voicemail was over), and it turned out there were 4-5 people on that call and they then discussed how the call went and whether or not it was sufficient to CYA.

That's hilarious. Please tell me you kept that recording.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#249

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

(remove message) Sorry, on further thought while I still disagree with the analysis above as being overly dismissive, I think the OP may share some blame for not writing higher quality reports with POCs. Also, the OP doesn't explain whether or not they saw the original reports for those marked Duplicate. That's a very critical point. See here - https://docs.hackerone.com/programs/duplicate-reports.html For anyone act…

I don't understand your argument here. "You patch you pay" is not a market term on any bug bounty; people report sev:infos all the time that ultimately get patched, but aren't worth anything (this is why some bounty programs stock sticker and t-shirt SWAG, to placate these submissions).

Meanwhile: I don't care even a little bit how Paypal arrived at their "duplicate" response, because Paypal has no incentive to deny a bounty for a valid bug. Like I said above, they have the opposite incentive. Duplicates happen all the time. If Paypal --- or any other large company --- says it was a duplicate bug, it would take extraordinarily clear evidence for me to believe otherwise.

Some of these things are probably not true for fly-by-night companies that set up bounty programs (a lot of people run bounties that shouldn't). I'm not denying that there are random companies that do ruthlessly screw with bounty submitters; I don't know any of them, but I believe they exist. But the money Paypal spends on bounties, all put together, barely even qualifies as a rounding error. They do not care; nobody serious cares enough to squelch reports to avoid paying bounties.

The fact that this was reported as "six critical vulnerabilities" is enough for me to tilt the credibility scale in the other direction.

Later

I'd appreciate it if you didn't edit your comment out from under my reply; the convention on HN is to update your post to clarify your argument in a PS, not to simply delete the parts you felt didn't hold up to scrutiny.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#250

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

out of curiosity, do you work at PayPal or is the first paragraph all assumptions? One would have thought Wells Fargo had a talented team of people to catch their millions of fake accounts they made, but alas it went on for a decade. I will always assume companies have their backs turned to security, until proven otherwise, regardless of size or perceived risk.

First, I do not work at Paypal, and have never worked at Paypal.

Second, if I did, it would be none of your business.

Third, comments like these are forbidden by the site guidelines, which demand that you not make accusations of astroturfing simply because you disagree with a comment.

Post reply on HN