Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

251–260 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#251

Earlier quoted context omitted.

> This feature is not 2FA > anti-ATO ATO [1] is authentication by definition, but again, depending on how it's implemented, not usually the best form. [1] https://csrc.nist.gov/glossary/term/authorization-to-operate

Authorization is not authentication, by definition. Furthermore, your link is talking about an entirely unrelated meaning of ATO. I believe tptacek meant it to stand for "account take-over".

You're right; that's what ATO means here.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#252
post #120

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

> HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Completely disagree with this. I launched a HackerOne program for my company last month (for free, not using their “managed” service). Of the many reports people submitted, we triaged 30-40 valid reports (most very minor, one or two moderate). We paid out a few thousand dollars in rewards. At the same time, we also did a more tradition…

This is not funny, many of us live in countries where we need that money. We're underpaid but we try. I'm glad that we have high quality researchers in this platforms but punishing us goes too far.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#253
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

I've been bitten before by the fact that if you don't use PayPal, eBay's interest in helping you with a refund dispute is exactly zero. And now I learn this. I guess PayPal + credit card is the way to go if you want any chance of a successful refund.

Unless you're getting boned with pseudo credit cards which are debit cards in disguise.

Direct banks such as ING or DKB in Germany are offering those cards but dear god if you have a dispute. Money is gone from your checking account right away and you don't get the convenient fraud protection of actual CCs.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#254

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I submitted a vulnerability to a vendor on H1 along with a typical “I plan on publicly disclosing this vulnerability on X date” note, and started getting emails directly from H1 telling me that this undermined vendors’ confidence in the platform and that doing what I was doing might make it…

>HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices.

I would say to step back and even question the concept of 'responsible' disclosure. For starters, even the very name seems to be manipulative by setting the tone of the conversation in a way that, in most other settings, doesn't pass the smell test.

It seems like a short term optimization with longer term costs. While at the moment release the vulnerability into the wild will likely be followed by bad actors exploiting it, by sitting on it until the company fixes it we create an environment where companies are given a grace period if vulnerabilities are found. This is in turn factored into their decisions making when it comes to how prioritized security is.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#255

Earlier quoted context omitted.

out of curiosity, do you work at PayPal or is the first paragraph all assumptions? One would have thought Wells Fargo had a talented team of people to catch their millions of fake accounts they made, but alas it went on for a decade. I will always assume companies have their backs turned to security, until proven otherwise, regardless of size or perceived risk.

First, I do not work at Paypal, and have never worked at Paypal. Second, if I did, it would be none of your business. Third, comments like these are forbidden by the site guidelines, which demand that you not make accusations of astroturfing simply because you disagree with a comment.

Charitably interpreted, it's 'just' an accusation you can't possibly know the quality of PayPal's security team since you don't work there and lack the necessary insider knowledge. Calling you a naïf, not a shill!

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#256

HackerOne is complete garbage. I spent close to a month digging into Uber and compromised their m.uber.com mobile endpoint; they hemmed and hawed and then awarded the $25K to another HackerOne top performer stating that he had discovered the exact same vulnerability the day before I had submitted the report. What's weird about it is that I was using Burp Proxy for everything, and this guy was directly connected to Po…

What would you expect HackerOne to do in the situation you describe? You filed a duplicate report. All of the malfeasance you allege is coming from Portswigger.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#257
post #255

Earlier quoted context omitted.

First, I do not work at Paypal, and have never worked at Paypal. Second, if I did, it would be none of your business. Third, comments like these are forbidden by the site guidelines, which demand that you not make accusations of astroturfing simply because you disagree with a comment.

Charitably interpreted, it's 'just' an accusation you can't possibly know the quality of PayPal's security team since you don't work there and lack the necessary insider knowledge. Calling you a naïf, not a shill!

You're right.

For clarity's sake: anyone with a significant number of acquaintances in SFBA appsec knows people working appsec at Paypal or their subsidiaries.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#258

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> I'm inclined not to believe their claim that Paypal acted abusively here (and I am not a fan of Paypal).

I agree that they have some issues with the way they've reported it, and I agree with your numbered points except that they imply that #5 may make the support agent vulnerable, but I'm not sure you can say PayPal haven't acted abusively. Many of the reports are legitimate vulnerabilities even if they aren't critical ones. The first is clearly a security issue yet PayPal have said that it isn't. In return they have received nothing but a reputation hit, and this is clearly unfair.

Do PayPal specifically say that anything involving stolen details are out of scope? This seems a bit weak considering they have numerous systems in place to combat misuse of stolen accounts. And even if they do it doesn't explain #2.

edit: To answer my own question, the page at lists "Vulnerabilities involving stolen credentials or physical access to a device" as out of scope for web applications. They likely intend that to apply to mobile applications also, but they've structured the page in a way that makes that ambiguous.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#259

Earlier quoted context omitted.

H1 used to have a mechanism where researchers could push to make raised issues public if a ticket was ignored or marked as wontfix. That was a good way to keep companies honest, an implementation of responsible disclosure. So H1 could implement that again. It doesn't get them a bounty but it does stop companies pretending reports don't exist, if that's what has happened here.

If you have a Squid RCE, what prevents you from getting a CVE for it, writing a blog post, and announcing on Twitter?

HackerOne has threatened to ban researchers who disclose responsibly.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#260

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

My experience with Hacker One is almost entirely negative and I don't understand why it has such mindshare.
Post reply on HN