Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.
Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…
Instagram's Million Dollar Bug (2015)
41–50 of 98 posts
Re: Instagram's Million Dollar Bug (2015)
#42The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.
Re: Instagram's Million Dollar Bug (2015)
#43Earlier quoted context omitted.
Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.
He had signing keys for the Instagram app and the *.instagram.com keypair. Do you think that's not valuable and dangerous?
Re: Instagram's Million Dollar Bug (2015)
#44The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.
With their first bugs, researchers are entirely unknown quantities to the company. Stating, "I have a critical zero-day, but I won't tell you what it is until you pay me $BUCKS," clearly won't work.
A reliable escrow service, to whom the researcher can provide the exploit and the company can provide $BUCKS, offers insurance to both parties. If the exploit is not as described, the researcher loses the exploit entirely and gets no $BUCKS, but if the exploit is as described, the company cannot renege on the deal.
(Edit, addressing the direct question more-clearly: perhaps what is necessary to avoid the perception (and reality) of extortion is the emergence of accepted professional understanding for assessing the value of exploits. Without such a system, there will always be a strong incentive pushing people in the direction of blackhat work.)
Re: Instagram's Million Dollar Bug (2015)
#45Earlier quoted context omitted.
He had signing keys for the Instagram app and the *.instagram.com keypair. Do you think that's not valuable and dangerous?
sorry, can you explain what the signing keys and keypair would allow someone to do?
Re: Instagram's Million Dollar Bug (2015)
#46The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.
Sounds like a third party might be able to improve the situation by providing escrow. With their first bugs, researchers are entirely unknown quantities to the company. Stating, "I have a critical zero-day, but I won't tell you what it is until you pay me $BUCKS," clearly won't work. A reliable escrow service, to whom the researcher can provide the exploit and the company can provide $BUCKS, offers insurance to both…
From their website [1]:
> "We pay BIG bounties, not bug bounties"
Re: Instagram's Million Dollar Bug (2015)
#47The problem with bug bounties is they are one-sided, against the researcher. The conditions of bounties typically stipulate that any attempt at negotiation can be interpreted as extortion, so it is either take it or leave it.
The researcher doesn't have zero knowledge before choosing to work with/for a company. The history of payouts and the perception of the company in the community are meaningful indicators of willingness to pay.
Re: Instagram's Million Dollar Bug (2015)
#48On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png
Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world would have this kind of bug live so long (and yes, I have reported it multiple times).
Re: Instagram's Million Dollar Bug (2015)
#49Earlier quoted context omitted.
sorry, can you explain what the signing keys and keypair would allow someone to do?
Would allow you to make an app that steals all your info and release it as if it was the latest app from instagram.
Re: Instagram's Million Dollar Bug (2015)
#50Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.
Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…