God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.
Instagram's Million Dollar Bug (2015)
11–20 of 98 posts
Re: Instagram's Million Dollar Bug (2015)
#12Re: Instagram's Million Dollar Bug (2015)
#13Re: Instagram's Million Dollar Bug (2015)
#14Re: Instagram's Million Dollar Bug (2015)
#15God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.
Re: Instagram's Million Dollar Bug (2015)
#16This was discussed at length when it was first submitted here 5 years ago. The researcher found a (known) exploit, claimed $2500, then a month later used internal details he gathered (and saved) from the first exploit to breach the system further to demand a bigger payout.
Re: Instagram's Million Dollar Bug (2015)
#17This was discussed at length when it was first submitted here 5 years ago. The researcher found a (known) exploit, claimed $2500, then a month later used internal details he gathered (and saved) from the first exploit to breach the system further to demand a bigger payout.
They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.
Re: Instagram's Million Dollar Bug (2015)
#18This speaks to a couple of issues that bothered me while working in bug bounty triage. > Alex informed my employer (as far as I am aware) that I had found a vulnerability, and had used it to access sensitive data. He then explained that the vulnerability I found was trivial and of little value , and at the same time said that my reporting and handling of the vulnerability submission had caused huge concern at Faceboo…
Disclaimer: I was a Security Engineer on the FB Security Team until last month and regularly attended the payout meetings :-)
I've seen plenty of bug bounty programs making such claims, but the Facebook program keeps up to this promise the most. Every bug is root caused to the line that caused the issue and assessed on maximal potential impact.
Sometimes that leads to cases where low impact vulnerabilities got paid out tens of thousands of dollars. The big bounty often came as a big surprise to the reporter :-)
Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this into a Remote Code Execution and paid out 80k USD (https://www.facebook.com/BugBounty/posts/approaching-the-10t...)
Facebook has big pockets. As a bug bounty hunter, I'd not worry about being screwed by them. It's by far one of the best paying bounty programs.
There are many reasons to criticize Facebook or Instagram. But the handling of its application security should not be in the top 10 :-)
Re: Instagram's Million Dollar Bug (2015)
#19Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.
That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues.
Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this into a Remote Code Execution and paid out 80k USD to the researcher. (https://www.facebook.com/BugBounty/posts/approaching-the-10t...)
That said, I wasn't there in 2015, so I only know the story from some stories. (which portray the story a tad different) - Even if it were true, I haven't seen such treatment in the last three years at FB.