Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

51–60 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#51
post #45

Earlier quoted context omitted.

Would allow you to make an app that steals all your info and release it as if it was the latest app from instagram.

Wouldn't you also need login info (prob including 2fa) to an Apple developer account?

If *.instagram.com keypair is the TLS certificate keypair, then they could MITM Instagram. They'd probably need to physically stalk some Instagram employees, but getting the TLS certificate key pair would be the difficult part.

On a related note, what do MS Windows/OSX/Android/iOS/Linux do when they see a WiFi AP with an SSID (and maybe even MAC) they recognize, with a WPA2 key they know, operating without encryption? Will they still auto-connect in the clear? In other words, if an attacker cloned the SSID of someone's work/home network, with a strong enough signal, could they trick devices into auto-connecting to an unencrypted AP?

Re: Instagram's Million Dollar Bug (2015)

#52

Off topic, but there is a bug on Instagram that has been bothered me for quite a while. On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world…

My Kindle says “2GB gratis de 3GB” (in Spanish) which doesn’t make any sense, instead it should say “2GB libres de 3GB” (2GB free of 3GB).

Free can be translated to either “libre” or “gratis”, libre is as in freedom, gratis is free as in beer.

I can’t understand how the most popular reading device would have that kind of mistake in one of the most common languages in the world.

Re: Instagram's Million Dollar Bug (2015)

#53
post #31

Earlier quoted context omitted.

According to free market economics, this is exactly what should happen. Security researches sell their exploits on the dark web until bug bounties rise to the same or higher prices as the dark web will pay. It's crazy that they can find a bug that would cost Instagram 1M+, yet payouts are in the thousands or maybe tens of thousands if you're super lucky. I'm curious if it's illegal to sell exploits. Using them is obv…

I honestly think this is what free market economics will get us, due to the high barriers to selling on the black market (ethically, legally, and logistically). The bug bounty targets with high payouts from the company line up roughly with the ones with high payouts on Zerodium etc. As I stated elsewhere in the thread, I'm not honestly convinced the fallout from a company being breached is that high, which leads to t…

As someone who's not in the infosec/cyber industry, what exactly is Zerodium and why is it generally considered a suboptimal buyer?

Re: Instagram's Million Dollar Bug (2015)

#54
post #40

Earlier quoted context omitted.

> But then what? It looks like it was all just dropped pretty much as is? That usually means some money was exchanged and some NDAs were signed.

Why would Facebook NDA paying a researcher? Shouldn't they be shouting it at the top of their lungs?

From my experience working in the PR and media industry, this NDA appears to serve a key purpose: It discourages engagements/discussions on social media platforms, thus hastening this incident into irrelevancy to mainstream media, thus protecting the brand reputation and key shareholders of FB.

Security findings are never good for the share price. Therefore it is crucial for the company to take control of the narrative when possible.

Re: Instagram's Million Dollar Bug (2015)

#55
post #52

Off topic, but there is a bug on Instagram that has been bothered me for quite a while. On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world…

My Kindle says “2GB gratis de 3GB” (in Spanish) which doesn’t make any sense, instead it should say “2GB libres de 3GB” (2GB free of 3GB). Free can be translated to either “libre” or “gratis”, libre is as in freedom, gratis is free as in beer. I can’t understand how the most popular reading device would have that kind of mistake in one of the most common languages in the world.

Hah, "free" is often translated wrong into Chinese too for the same reason.

Re: Instagram's Million Dollar Bug (2015)

#56

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

> Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case?

Those "mail us your gold" ads on TV.

Re: Instagram's Million Dollar Bug (2015)

#57

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

There is plenty of price competition for your bug disclosure: the Chinese, the Israelis, the Saudis, the Americans, OR directly to Apple. :-)

Re: Instagram's Million Dollar Bug (2015)

#58

Off topic, but there is a bug on Instagram that has been bothered me for quite a while. On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world…

Maybe these bugs involved English speaking devs copy and pasting out of spreadsheets.

Re: Instagram's Million Dollar Bug (2015)

#59

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

> triagers have a whole pile of crap to wade through, to get to the useful material.

This is very true.

> The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer who gets to make a significant judgement call on the value of the work done.

The problem, in my experience, is that they never analyze it by its potential. Why would they, they have the details now and usually your legal details so if it leaks they'll have you busted in a heartbeat and sued for contract violation.

> Furthermore, it really is hard to place an accurate monetary value on a bug that's responsibly reported

I submit that from my experience threat modelling this is actual dead simple but nobody feels the need to do it.

> What precisely is the monetary loss from ...

As you point out, the issue is that there's a single buyer. You really need to open up the bidding. If you trusted a Russian mob to pay residuals (and they probably would) you might be able to sell this for what ended up being $50M+, and the criminals could clear billions if done right. Then the next time something like this came up you'd have more bargaining power. If the company was still there...

Thomas is right that there isn't specifically a market like flippa for exploits but there are dark markets and many of the vendors would be open to a chat. I'm not rooting for this, I'm just not blind and it will happen. (Well, if it's Twitter I'm rooting a little...)

Re: Instagram's Million Dollar Bug (2015)

#60

There is no real bug besides the ruby RCE thing. Cracking weak passwords is not eligible. Sorry. I can see why Facebook denied him a remittance but their approach of contacting his employer was wrong.

Not a "bug" in terms of incorrect code. But if I worked there, I'd sure like to know that

1. There were older versions of apps with config files stored in S3 that contained AWS keypairs for roles with wide open access

2. That such keypairs existed in the first place and were used on servers - probably no service role with such wide access should exist, and even if it did, it ought to be caught by routine audits for overpermissioned roles, and also old keypairs should be retired and rotated regularly

3. That a whole bunch of private key material basically encompassing the keys to the Instagram castle were stored in S3 buckets

Post reply on HN