Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

21–30 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#21

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion.

The first case would get you likely in trouble. The second case would routinely cause a further review in any decent program, and if there's any merit to it, you get a higher bounty.

Nobody is forced to participate in any bug bounty program. If people feel the reward is too low, they should not partake.

Re: Instagram's Million Dollar Bug (2015)

#22

Earlier quoted context omitted.

They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.

Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.

He had signing keys for the Instagram app and the *.instagram.com keypair. Do you think that's not valuable and dangerous?

Re: Instagram's Million Dollar Bug (2015)

#23

Earlier quoted context omitted.

They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.

Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.

yeah, you cracked a bunch of selfie pics. What can you do with it.

FTA: "specifically I gained access to a lot of data including SSL certs, source code, photos, etc"

Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular.

And now?

Re: Instagram's Million Dollar Bug (2015)

#24

Earlier quoted context omitted.

Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.

yeah, you cracked a bunch of selfie pics. What can you do with it. FTA: "specifically I gained access to a lot of data including SSL certs, source code, photos, etc" Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. And now?

Bug bounty programs pay you for the severity of the exploit, not the potential damage you could do with it. The researcher found an unpatched server with a known Ruby RCE and cracked a weak password. Whether he found the server empty or containing nuclear codes isn't what determines the payout.

Storing user data and private keys on your computer after reporting the hack and using them again to access the systems is way beyond the scope of a bug bounty program (and probably criminal).

Re: Instagram's Million Dollar Bug (2015)

#25

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion. The first case would get you likely in trouble. The second case would routinely cause a further review in any decent program, and if there's any merit to it, you get a higher bounty. Nobody is forced to…

> How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount"

Hello Strawman!

> The second case would routinely cause a further review in any decent program

We literally just read a example of how a big corp responds to #2. Do you think it was a 1 of?

Re: Instagram's Million Dollar Bug (2015)

#26

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion. The first case would get you likely in trouble. The second case would routinely cause a further review in any decent program, and if there's any merit to it, you get a higher bounty. Nobody is forced to…

False dichotomy, they aren't threatening to exploit it, they simply won't give details of the exploit if they aren't paid.

Re: Instagram's Million Dollar Bug (2015)

#27

Earlier quoted context omitted.

How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion. The first case would get you likely in trouble. The second case would routinely cause a further review in any decent program, and if there's any merit to it, you get a higher bounty. Nobody is forced to…

> How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" Hello Strawman! > The second case would routinely cause a further review in any decent program We literally just read a example of how a big corp responds to #2. Do you think it was a 1 of?

I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated and, if justified, higher bounties issued.

This blog post seems a bit one-sided and doesn't correlate to the facts that I have heard. I wasn't there at the time being so I don't know the truth. But that blog post seems not quite 100% to be it.

What I have seen, however, in the past years, is that some people omit facts or misrepresent things to get some press. So I am quite a cynic on blog posts like this :-)

Re: Instagram's Million Dollar Bug (2015)

#28

This speaks to a couple of issues that bothered me while working in bug bounty triage. > Alex informed my employer (as far as I am aware) that I had found a vulnerability, and had used it to access sensitive data. He then explained that the vulnerability I found was trivial and of little value , and at the same time said that my reporting and handling of the vulnerability submission had caused huge concern at Faceboo…

> Companies always say they will investigate the full impact of a vulnerability when you follow the protocol they urge of "as soon as you find something, report it and don't try to escalate". But this is nearly impossible to do even if you're trying in good faith. Disclaimer: I was a Security Engineer on the FB Security Team until last month and regularly attended the payout meetings :-) I've seen plenty of bug bount…

So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"?

> Facebook has big pockets. As a bug bounty hunter, I'd not worry about being screwed by them. It's by far one of the best paying bounty programs.

I don't think the middle sentence is related to the other two. Every company I triaged for had deep pockets. I routinely saw payouts in excess of $1,000 and not uncommonly several thousand. I don't recall ever seeing one that hit $10,000. But what I'm describing above are ways for the company to screw the researcher without really being motivated by stinginess. Fairness is not a concern.

Re: Instagram's Million Dollar Bug (2015)

#29

Earlier quoted context omitted.

How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" vs. "I think the impact is bigger because of Y"? For me, the first sounds quite clearly like extortion. The first case would get you likely in trouble. The second case would routinely cause a further review in any decent program, and if there's any merit to it, you get a higher bounty. Nobody is forced to…

False dichotomy, they aren't threatening to exploit it, they simply won't give details of the exploit if they aren't paid.

I'd advise anyone against trying that for a system not owned by them. (e.g., someone's else website)

As soon as you do that, you venture into dangerous territory. Companies are required to investigate claims of breaches seriously. And as soon as something like this is escalated, it may be out of the Information Security team's hands to decide the next steps.

Re: Instagram's Million Dollar Bug (2015)

#30

I tried a little searching but I can't find anything that says how this all ended. Alex Stamos denied saying anything bad. But then what? It looks like it was all just dropped pretty much as is?

> But then what? It looks like it was all just dropped pretty much as is?

That usually means some money was exchanged and some NDAs were signed.

Post reply on HN