HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…
What does "broken" mean here? If the development team is unresponsive, what do you expect H1's response to be?
“We found PayPal vulnerabilities and PayPal punished us for it”
321–330 of 337 posts
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#322Earlier quoted context omitted.
Hacking PayPal is a crime tho'. Except for when you play their game, which means: submit bugs via h1 and only disclose if they allow.
Legitimately interested in your explanation as to how this specific research would be a crime absent contact with HackerOne. Please cite statute. I'm not saying you're wrong - simply asking you to back up your claim with evidence.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#323Earlier quoted context omitted.
No idea which one it was, or both. 23K isn't something to sneeze at though, and would be plenty of incentive for the folk at Portswigger to work with douchebags like whoever this shubby dude is in order to collect these bounties. 24K for one bounty... or sell $299 licenses to nerds.. hmm, which one is more profitable...
...the second one is significantly more profitable.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#324Earlier quoted context omitted.
They key part there is "if they decide to fine you...". The max(€10m, 2%) and max(€20m, 4%) are the most that supervisory authorities may issue as fines. But supervisory authorities have a legal duty to issue fines that are proportional which means than unless you breach the GDPR in a wilful and egregious manner you're unlikely to be fined that much (and if you are you can appeal the fine to a court who would reduce…
When would it ever be proportional to charge a small business more than 2% if they can never charge a large business more than 2%? Are small businesses, as a general rule, somehow more capable of causing damage than larger businesses? Is the law as written somehow vulnerable to some legal hack where all my revenue goes through Company A but all my data goes through Company B, so that Company B has a small global reve…
No. Who the data controllers are is a matter of fact, not assignment.
To quote the Court of Justice of the European Union in the Fashion ID case (C‑40/17) at paragraph 68:
"[A] natural or legal person who exerts influence over the processing of personal data, for his own purposes, and who participates, as a result, in the determination of the purposes and means of that processing, may be regarded as a controller".
Furthermore, as per that case, multiple data controllers may exist for some processing activities.
So both Company A and Company B may be considered to be Data Controllers and thus both liable.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#325Earlier quoted context omitted.
It's not a regulation. It's a contractual obligation between the merchant and the PCI counsel (which is made up by VISA/Mastercard/the backing banks/etc). It was put in place to avoid regulation.
Then perhaps regulation is necessary if this is their level of scrutiny?
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#326Earlier quoted context omitted.
You're right; that's what ATO means here.
Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#327Earlier quoted context omitted.
> I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong. Actually this makes a pretty good case for this regulation being a joke. They clearly aren’t up to the responsibility of being a payment processor and are leaning on the law to sustain their business rather…
> Actually this makes a pretty good case for this regulation being a joke. PCI-DSS is not government regulation, but an industry created and enforced standard. Compliance is not mandated by federal law and only a couple of states have laws that reference it. For example, Nevada requires compliance while Washington doesn't require compliance but does remove liability for breaches for compliant businesses.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#328Earlier quoted context omitted.
I went to enable the opt-in 2FA in response to this report. It's pretty rough, IMO. It gives you no way to use scratch codes as a backup. You're stuck with either adding a second TOTP device or allowing SMS as a backup. Adding a second TOTP device is OK security-wise but adding a second device to my safe and making sure it's still working periodically kind of sucks. SMS is not OK. Printed scratch codes would beat the…
You can make a backup by saving in some safe place a copy of the QR code and/or the 16 character text code Paypal gives you to set up your TOTP device. You can then use that later to set up a replacement TOTP device if something happens to your first one. I usually use "grab" on my Mac to save a copy of the QR code as a PNG, encrypt that, and save it in an offsite location. Another popular approach is to print the QR…
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#329Earlier quoted context omitted.
Even when the disclosure is not actually coordinated, in the common sense of the word, because the vendor doesn’t agree to the deadline and/or isn’t given any option to pick a longer deadline? Edit: The Google Project Zero FAQ[0] explicitly states its approach is not coordinated disclosure: > Prior to Project Zero our researchers had tried a number of different disclosure policies, such as coordinated vulnerability d…
I don't know what else to tell you. "Responsible Disclosure" was literally a coercive marketing strategy cooked up by vendors; it isn't a term we arrived at organically. Don't use that term. Use any other term you like, but the convention in the field is "coordinated disclosure".
The vendor is informed before disclosure. The security researcher is an informed expert disclosing to end users. Good behavior vendors can further inform these researchers on challenges driving vendor need for alternative timing.
On the timing dimension, consider “cadenced disclosure”?
Less about consensus, more about the beats.
Re: “We found PayPal vulnerabilities and PayPal punished us for it”
#330People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…
Security analysis and penetration testing always results in the perception that the security auditor is calling their baby ugly. Always.