Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

31–40 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#31
post #8
post #3

God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.

I wouldn't really blame the guy if he decides to sell the next one on the darknet.

According to free market economics, this is exactly what should happen. Security researches sell their exploits on the dark web until bug bounties rise to the same or higher prices as the dark web will pay.

It's crazy that they can find a bug that would cost Instagram 1M+, yet payouts are in the thousands or maybe tens of thousands if you're super lucky.

I'm curious if it's illegal to sell exploits. Using them is obviously illegal, but is the transfer of knowledge for money illegal? I.e. I'm not allowed to build an M16, but presumably I could by the schematics for one if I wanted (I've never tried, but I can't imagine possession of them is illegal since they make posters of it and what not).

Re: Instagram's Million Dollar Bug (2015)

#32

Earlier quoted context omitted.

> Companies always say they will investigate the full impact of a vulnerability when you follow the protocol they urge of "as soon as you find something, report it and don't try to escalate". But this is nearly impossible to do even if you're trying in good faith. Disclaimer: I was a Security Engineer on the FB Security Team until last month and regularly attended the payout meetings :-) I've seen plenty of bug bount…

So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"? > Facebook has big pockets. As a bug bounty hunter, I'd not worry about being screwed by them. It's by far one of the best paying bounty programs. I don't think the middle sentence is related to the other two. Every company I triaged for had deep pockets. I routinely saw payouts in…

> So what do you think is going on in this piece (5 years old), where Alex Stamos characterizes the issue as "trivial and of little value"?

I sadly wasn't there at the time, and Stamos post doesn't refer to it at all. So I can't comment on this.

I guess the truth on this is just known to the researcher, their boss, and Stamos.

> But what I'm describing above are ways for the company to screw the researcher without really being motivated by stinginess. Fairness is not a concern.

That's a fair point, and I can see how representation can cause a significantly different payout decision, especially if there is no technical payout panel with a security background.

Phrasing something as "Reflected XSS" vs. "Account Take-Over via XSS" sounds undoubtedly different. But it is impact-wise probably the same.

The problem is mitigated at Facebook by having engineers in the payout panel that understand the tech stack and security implications. But I think many companies don't have that luxury, and you undoubtedly may end up with inconsistencies.

Thanks for sharing your perspective. Much appreciated!

Re: Instagram's Million Dollar Bug (2015)

#33
(my comment is on the overall trend, as the specifics on this incident are complex)

The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case?

Alternatively, triagers have a whole pile of crap to wade through, to get to the useful material.

Furthermore, it really is hard to place an accurate monetary value on a bug that's responsibly reported, and patched. This is in part due to unclear monetary results from being breached. What precisely is the monetary loss from the recent MS Teams bug that was reported but not exploited vs the incidents this year at Twitter and SolarWinds?

Having had some involvement in the bug bounty arena as a reporter, I have to say I'm a big fan of those companies that open up all of their reports after a fix period of time. This allows them to build trust with those who look into their products, and develop a reputation for being prompt and consistent.

Re: Instagram's Million Dollar Bug (2015)

#34
post #31
post #8

Earlier quoted context omitted.

I wouldn't really blame the guy if he decides to sell the next one on the darknet.

According to free market economics, this is exactly what should happen. Security researches sell their exploits on the dark web until bug bounties rise to the same or higher prices as the dark web will pay. It's crazy that they can find a bug that would cost Instagram 1M+, yet payouts are in the thousands or maybe tens of thousands if you're super lucky. I'm curious if it's illegal to sell exploits. Using them is obv…

I honestly think this is what free market economics will get us, due to the high barriers to selling on the black market (ethically, legally, and logistically). The bug bounty targets with high payouts from the company line up roughly with the ones with high payouts on Zerodium etc.

As I stated elsewhere in the thread, I'm not honestly convinced the fallout from a company being breached is that high, which leads to the current pricing for bug bounties. Twitter stock is massively up from when their incident happened in July. We'll see what happens with SolarWinds.

Re: Instagram's Million Dollar Bug (2015)

#35
post #31
post #8

Earlier quoted context omitted.

I wouldn't really blame the guy if he decides to sell the next one on the darknet.

According to free market economics, this is exactly what should happen. Security researches sell their exploits on the dark web until bug bounties rise to the same or higher prices as the dark web will pay. It's crazy that they can find a bug that would cost Instagram 1M+, yet payouts are in the thousands or maybe tens of thousands if you're super lucky. I'm curious if it's illegal to sell exploits. Using them is obv…

That seems to depend on some very specific and unusual definition of "free market economics." Usually there is some unspecified assumption of rights (particularly property rights), and actions which violate those rights are not considered to be "free market" interactions. As an obvious example, if you creep around neighborhoods looking for people with valuable property that isn't well-secured against theft, then offer to sell a homeowner the information about the security problems you've discovered, and then sell that information to professional thieves if the homeowner declines, I don't think that would be "exactly what should happen according to free market economics."

Re: Instagram's Million Dollar Bug (2015)

#36
post #24

Earlier quoted context omitted.

yeah, you cracked a bunch of selfie pics. What can you do with it. FTA: "specifically I gained access to a lot of data including SSL certs, source code, photos, etc" Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. And now?

Bug bounty programs pay you for the severity of the exploit, not the potential damage you could do with it. The researcher found an unpatched server with a known Ruby RCE and cracked a weak password. Whether he found the server empty or containing nuclear codes isn't what determines the payout. Storing user data and private keys on your computer after reporting the hack and using them again to access the systems is w…

> the severity of the exploit, not the potential damage you could do with it

Isn't severity measured in terms of potential damage?

Re: Instagram's Million Dollar Bug (2015)

#37

Earlier quoted context omitted.

> How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" Hello Strawman! > The second case would routinely cause a further review in any decent program We literally just read a example of how a big corp responds to #2. Do you think it was a 1 of?

I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated and, if justified, higher bounties issued. This blog post seems a bit one-sided and doesn't correlate to the facts that I have heard. I wasn't there at the time being so I don't know the truth. But that blog post seems not quite 100% to be…

> A reasonable claim like "I think this should be higher because XYZ" gets investigated and, if justified, higher bounties issued.

That's highly dependent on the individuals and the company doing the bounty. It's incredibly reasonable that people are suspicious of the process, when it is opaque as it is, and the disparity in negotiating power being the company and the person submitting the bug.

My personal experience is the FB bug bounty process has been generally positive, but inconsistent at times in the graded severity of issues and transparency of the decisions being made. I've clearly presented my case, and asked for additional information, but not gotten very far. My only real option in response is in how I allocate my time.

Having reports and payout amounts be permanently hidden results in stories like this being the only insight to the process.

Re: Instagram's Million Dollar Bug (2015)

#38
post #24

Earlier quoted context omitted.

Bug bounty programs pay you for the severity of the exploit, not the potential damage you could do with it. The researcher found an unpatched server with a known Ruby RCE and cracked a weak password. Whether he found the server empty or containing nuclear codes isn't what determines the payout. Storing user data and private keys on your computer after reporting the hack and using them again to access the systems is w…

> the severity of the exploit, not the potential damage you could do with it Isn't severity measured in terms of potential damage?

Yes.

https://www.facebook.com/BugBounty/posts/approaching-the-10t...

CDN bug report... Earlier this year we received a report from Selamet Hariyanto who identified a low impact issue in our CDN... a very sophisticated attacker could have escalated to remote code execution. As we always do, we rewarded the researcher based on the maximum possible impact of their report, rather than on the lower-severity issue initially reported to us. It is now our highest bounty — $80,000.

Re: Instagram's Million Dollar Bug (2015)

#39
post #9

Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

Fool me once, shame on you.

Re: Instagram's Million Dollar Bug (2015)

#40

I tried a little searching but I can't find anything that says how this all ended. Alex Stamos denied saying anything bad. But then what? It looks like it was all just dropped pretty much as is?

> But then what? It looks like it was all just dropped pretty much as is? That usually means some money was exchanged and some NDAs were signed.

Why would Facebook NDA paying a researcher? Shouldn't they be shouting it at the top of their lungs?
Post reply on HN