(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…
> triagers have a whole pile of crap to wade through, to get to the useful material. This is very true. > The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer who gets to make a significant judgement call on the value of the work done. The problem, in my experience, is that they never analyze it by its potential. Why would they, th…
Instagram's Million Dollar Bug (2015)
61–70 of 98 posts
Re: Instagram's Million Dollar Bug (2015)
#62God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.
https://web.archive.org/web/20151217232048/https://www.faceb...
Re: Instagram's Million Dollar Bug (2015)
#63This was discussed at length when it was first submitted here 5 years ago. The researcher found a (known) exploit, claimed $2500, then a month later used internal details he gathered (and saved) from the first exploit to breach the system further to demand a bigger payout.
They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.
Re: Instagram's Million Dollar Bug (2015)
#64Previous discussion (5 years ago): https://news.ycombinator.com/item?id=10754194
Re: Instagram's Million Dollar Bug (2015)
#65Previous discussion (5 years ago): https://news.ycombinator.com/item?id=10754194
Alex's response is no longer available. (His link to his Facebook post is dead.) Anyone have a mirror?
Re: Instagram's Million Dollar Bug (2015)
#66Earlier quoted context omitted.
Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…
I think FB's greatest achievements is convincing their employees that their jobs are actually good for society, or at least neutral. Plenty of good people working there who seem honestly confused about how their jobs lead to so corruption and downfall of our society.
Of course, I also work at a FAANG, so people in glass houses and all that...
Re: Instagram's Million Dollar Bug (2015)
#67Re: Instagram's Million Dollar Bug (2015)
#68Earlier quoted context omitted.
> triagers have a whole pile of crap to wade through, to get to the useful material. This is very true. > The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer who gets to make a significant judgement call on the value of the work done. The problem, in my experience, is that they never analyze it by its potential. Why would they, th…
IMHO it’s only a matter of time until someone blows up a unicorn just for the thrill of it. That’s not something I’d support, but I won’t feel bad for companies that don’t pay adequate bug bounties.
Re: Instagram's Million Dollar Bug (2015)
#69(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…
> Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case? Those "mail us your gold" ads on TV.
Re: Instagram's Million Dollar Bug (2015)
#70Earlier quoted context omitted.
They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.
Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.