Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

281–290 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#281

Earlier quoted context omitted.

HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I submitted a vulnerability to a vendor on H1 along with a typical “I plan on publicly disclosing this vulnerability on X date” note, and started getting emails directly from H1 telling me that this undermined vendors’ confidence in the platform and that doing what I was doing might make it…

>HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I would say to step back and even question the concept of 'responsible' disclosure. For starters, even the very name seems to be manipulative by setting the tone of the conversation in a way that, in most other settings, doesn't pass the smell test. It seems like a short term optimization w…

I don’t like the name either but I don’t have a megaphone big enough to coin a new term of art and it is the only phrase I know that is used for “disclose to the vendor first, then after a fixed amount of time, full disclosure”.

There’s no question that the name is manipulative since it was first coined to refer to what’s now called “coordinated disclosure”[0], in an essay which referred to full disclosure as “information anarchy”[1].

In this case with HackerOne, the issue is not with terminology, nor is it with time-gated full disclosure versus immediate full disclosure. Rather, the issue is that HackerOne go out of their way to serve the interests of vendors who don’t want to fix defects quickly, at the expense of reporters, end users, and software security in general.

HackerOne could take the approach of saying “we are a neutral platform for connecting researchers and vendors, it is not within our purview to try to stop reporters from disclosing vulnerabilities if they feel it’s necessary”, but this is not how they operate today, and people should know this.

[0] https://en.wikipedia.org/wiki/Full_disclosure_(computer_secu...

[1] https://web.archive.org/web/20011109045330/http://www.micros...

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#282
post #228
post #120

Earlier quoted context omitted.

> HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Completely disagree with this. I launched a HackerOne program for my company last month (for free, not using their “managed” service). Of the many reports people submitted, we triaged 30-40 valid reports (most very minor, one or two moderate). We paid out a few thousand dollars in rewards. At the same time, we also did a more tradition…

> And H1 was 2-3x cheaper after paying out the bounties. Perpetuating a system wherein security researchers are massively underpaid for their services because of a terrible abusive platform doesn't seem like a very nice way to do business.

The platform has nothing to do with the rates; plenty of companies run bounty programs without H1, and there is a general standard range for findings across all platforms.

None of these findings appear to have been worth much of anything.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#283

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

I've never liked these rent-seeking bugbounty platforms which are inserting themselves as middle-men and mediators, but then take away the real value that comes from building direct client relationships. it's ok for people who start out and only want to work on vulns and not bother with "sales" (building long term client relationships). severely limiting though in the long run! much better to spend time on pitching y…

H1 doesn't really prevent you from building direct client relationships. People are just bad at building direct client relationships.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#284

Earlier quoted context omitted.

>HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I would say to step back and even question the concept of 'responsible' disclosure. For starters, even the very name seems to be manipulative by setting the tone of the conversation in a way that, in most other settings, doesn't pass the smell test. It seems like a short term optimization w…

The name "Responsible Disclosure" is in fact Orwellian and was designed that way, and people should avoid using it (or, really, the word "responsible" in discussions like this). The preferred term is "Coordinated Disclosure".

Help me out here, in what way is it Orwellian?

I always assumed the responsible part had multiple non-conflicting meanings, that 1) The researcher would not disclose it to the public until the vendor has a reasonable amount of time to fix it and 2) the vendor is assumed to want to do the right and responsible thing in fixing the flaw.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#285

Earlier quoted context omitted.

> PCI DSS requirements specify that companies have 30 days to refute or remediate externally reported issues [1]. If they don’t respond or fix some of these issues, then PayPal will no longer be compliant and all credit card companies will be forced to stop working with them unless they wish to set precedence that PCI-DSS compliance is no longer required to be followed. Quote from your source: > If your scan fails, y…

> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…

Sorry, technically correct is best correct.

Don't look behind the curtain.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#286

Earlier quoted context omitted.

The name "Responsible Disclosure" is in fact Orwellian and was designed that way, and people should avoid using it (or, really, the word "responsible" in discussions like this). The preferred term is "Coordinated Disclosure".

Help me out here, in what way is it Orwellian? I always assumed the responsible part had multiple non-conflicting meanings, that 1) The researcher would not disclose it to the public until the vendor has a reasonable amount of time to fix it and 2) the vendor is assumed to want to do the right and responsible thing in fixing the flaw.

It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified.

In 2020, non-ironic use of the term "responsible disclosure" has become somewhat of a "tell" that the person speaking isn't super connected to vulnerability research.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#287

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> I'm inclined not to believe their claim that Paypal acted abusively here (and I am not a fan of Paypal). I agree that they have some issues with the way they've reported it, and I agree with your numbered points except that they imply that #5 may make the support agent vulnerable, but I'm not sure you can say PayPal haven't acted abusively. Many of the reports are legitimate vulnerabilities even if they aren't crit…

Do PayPal specifically say [...]

This is why this article is a bad HN submission - it's not really on everybody on HN to figure out whether these reports are any good, whether they were handled correctly by PayPal, HackerOne, etc. It's up to the people writing them up to make this as clear as possible and they don't come anywhere close to that. This just creates a massive discussion driven by speculation and off-topic tangents about a problem people had on ebay and talmudic regulatory 'analysis'.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#288

Earlier quoted context omitted.

Help me out here, in what way is it Orwellian? I always assumed the responsible part had multiple non-conflicting meanings, that 1) The researcher would not disclose it to the public until the vendor has a reasonable amount of time to fix it and 2) the vendor is assumed to want to do the right and responsible thing in fixing the flaw.

It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…

That sort of makes sense, but what are examples of other legitimate incentives that might compel a researcher to disclose the presence of a vulnerability before the vendor has a fix?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#289

From PayPal's response to a 2FA bypass: > If the attacker has the victim's password, they would already be able to gain access to the account via web UI too. As such, the account is already compromised. As such, there does not appear to be any security implications as a direct result of this behavior. Seriously? This means PayPal's 2FA is just security theater. I'd rather they didn't offer it at all in this case, at…

From reading a different article, the terminology seems to be a bone of contention here. This ’2FA' is an email message PayPal send when they detect a new login location. They do not call it 2FA and they do offer actual 2FA that cybernews have not bypassed.

If PayPal says it is not a security issue, the researcher should just publish the details of how it's done.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#290

Earlier quoted context omitted.

>HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I would say to step back and even question the concept of 'responsible' disclosure. For starters, even the very name seems to be manipulative by setting the tone of the conversation in a way that, in most other settings, doesn't pass the smell test. It seems like a short term optimization w…

I don’t like the name either but I don’t have a megaphone big enough to coin a new term of art and it is the only phrase I know that is used for “disclose to the vendor first, then after a fixed amount of time, full disclosure”. There’s no question that the name is manipulative since it was first coined to refer to what’s now called “coordinated disclosure”[0], in an essay which referred to full disclosure as “inform…

> ... HackerOne go out of their way to serve the interests of vendors ...

I don't mean to sound so dismissive but... of course they do!

Who's paying HackerOne? The vendors!

Who is gonna be their first priority? The vendors that are paying them!

They certainly aren't going to do anything to harm that relationship that is keeping them in business.

Post reply on HN