Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

41–50 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#41
post #9

Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

I think FB's greatest achievements is convincing their employees that their jobs are actually good for society, or at least neutral. Plenty of good people working there who seem honestly confused about how their jobs lead to so corruption and downfall of our society.

Re: Instagram's Million Dollar Bug (2015)

#42

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

The researcher doesn't have zero knowledge before choosing to work with/for a company. The history of payouts and the perception of the company in the community are meaningful indicators of willingness to pay.

Re: Instagram's Million Dollar Bug (2015)

#43

Earlier quoted context omitted.

Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.

He had signing keys for the Instagram app and the *.instagram.com keypair. Do you think that's not valuable and dangerous?

sorry, can you explain what the signing keys and keypair would allow someone to do?

Re: Instagram's Million Dollar Bug (2015)

#44

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

Sounds like a third party might be able to improve the situation by providing escrow.

With their first bugs, researchers are entirely unknown quantities to the company. Stating, "I have a critical zero-day, but I won't tell you what it is until you pay me $BUCKS," clearly won't work.

A reliable escrow service, to whom the researcher can provide the exploit and the company can provide $BUCKS, offers insurance to both parties. If the exploit is not as described, the researcher loses the exploit entirely and gets no $BUCKS, but if the exploit is as described, the company cannot renege on the deal.

(Edit, addressing the direct question more-clearly: perhaps what is necessary to avoid the perception (and reality) of extortion is the emergence of accepted professional understanding for assessing the value of exploits. Without such a system, there will always be a strong incentive pushing people in the direction of blackhat work.)

Re: Instagram's Million Dollar Bug (2015)

#45
post #43

Earlier quoted context omitted.

He had signing keys for the Instagram app and the *.instagram.com keypair. Do you think that's not valuable and dangerous?

sorry, can you explain what the signing keys and keypair would allow someone to do?

Would allow you to make an app that steals all your info and release it as if it was the latest app from instagram.

Re: Instagram's Million Dollar Bug (2015)

#46
post #44

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

Sounds like a third party might be able to improve the situation by providing escrow. With their first bugs, researchers are entirely unknown quantities to the company. Stating, "I have a critical zero-day, but I won't tell you what it is until you pay me $BUCKS," clearly won't work. A reliable escrow service, to whom the researcher can provide the exploit and the company can provide $BUCKS, offers insurance to both…

AFAIK this is similar to Zerodium's business model, except they sell the zero day exploits to governments [0].

From their website [1]:

> "We pay BIG bounties, not bug bounties"

[0]: https://en.wikipedia.org/wiki/Zerodium

[1]: https://www.zerodium.com/

Re: Instagram's Million Dollar Bug (2015)

#47

The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.

The researcher doesn't have zero knowledge before choosing to work with/for a company. The history of payouts and the perception of the company in the community are meaningful indicators of willingness to pay.

A large number of companies keep their bug bounty payouts and reports permanently private, which I feel is a disservice to the community.

Re: Instagram's Million Dollar Bug (2015)

#48
Off topic, but there is a bug on Instagram that has been bothered me for quite a while.

On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png

Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world would have this kind of bug live so long (and yes, I have reported it multiple times).

Re: Instagram's Million Dollar Bug (2015)

#49
post #45
post #43

Earlier quoted context omitted.

sorry, can you explain what the signing keys and keypair would allow someone to do?

Would allow you to make an app that steals all your info and release it as if it was the latest app from instagram.

Wouldn't you also need login info (prob including 2fa) to an Apple developer account?

Re: Instagram's Million Dollar Bug (2015)

#50
post #9

Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

Forgive us (non-facebook engineers) if we don't take your (single rank-n-file engineer) anecdotal experience for official company policy when there's a public documented case of the head of the department doing otherwise.
Post reply on HN