Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

71–80 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#71
post #9

Ah nice. Facebook resorts to intimidating bug bounty participants acting in good faith by threatening them through their employer instead of talking. Can't say I'm surprised, given the level of ethics Facebook exhibits at every conceivable level.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

[deleted]

Re: Instagram's Million Dollar Bug (2015)

#72

Earlier quoted context omitted.

> Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case? Those "mail us your gold" ads on TV.

Hospitals do this, but backwards. The service provider gets to set the price.

Basically only in America, though. Elsewhere the situation where someone gets into a car wreck, goes to hospital and then gets told how broke they are now just doesn't exist.

In much of the rest of the world, the health system sets and publishes the rates - and guarantees payment to service providers. The doctors perform the services, and then submit for renumeration directly to the health system. The patients, well, they're sick and don't have to worry about any of it.

Re: Instagram's Million Dollar Bug (2015)

#73
So, to summarize, you go to bank and you say "your back door is vulnerable can you check", instead of checking and giving you some kind of praise, they call police to beat the hell out of you...

This is exactly sort of thing that will make community of white hackers stop caring, and leave open door to foreign agency malicious hackers to do as they please.

I would like to know what was really going inside of their heads, was someone internally trying to steal the thunder, was it vanity/pride, was it lack of funds?!, was it fear?

Re: Instagram's Million Dollar Bug (2015)

#74
post #31

Earlier quoted context omitted.

According to free market economics, this is exactly what should happen. Security researches sell their exploits on the dark web until bug bounties rise to the same or higher prices as the dark web will pay. It's crazy that they can find a bug that would cost Instagram 1M+, yet payouts are in the thousands or maybe tens of thousands if you're super lucky. I'm curious if it's illegal to sell exploits. Using them is obv…

I honestly think this is what free market economics will get us, due to the high barriers to selling on the black market (ethically, legally, and logistically). The bug bounty targets with high payouts from the company line up roughly with the ones with high payouts on Zerodium etc. As I stated elsewhere in the thread, I'm not honestly convinced the fallout from a company being breached is that high, which leads to t…

> I'm not honestly convinced the fallout from a company being breached is that high

The market clearly doesn't care, and so neither do executives. What needs to happen is a household company gets exploited/hacked/pwned/whatever so hard that their entire business collapses, maybe not entirely but significantly. Then the market will price these breaches very differently.

Re: Instagram's Million Dollar Bug (2015)

#75

So, to summarize, you go to bank and you say "your back door is vulnerable can you check", instead of checking and giving you some kind of praise, they call police to beat the hell out of you... This is exactly sort of thing that will make community of white hackers stop caring, and leave open door to foreign agency malicious hackers to do as they please. I would like to know what was really going inside of their hea…

By the way while reading this, I was expecting happy ending, something nice to start the day, but, alas, this is almost like a heavy Russian drama, starts with light tone and ends so depressive I would rather go back to bed crawling under the blanker and into fetal position.

Re: Instagram's Million Dollar Bug (2015)

#76
post #50

Earlier quoted context omitted.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

Forgive us (non-facebook engineers) if we don't take your (single rank-n-file engineer) anecdotal experience for official company policy when there's a public documented case of the head of the department doing otherwise.

Based on FB's official rebuttal, he had mentioned his company affiliation on the bug bounty portal account and had used a company email address for the communications. To me, this indicates that he was acting in an official company capacity.

Further, they didn't reach out to the CEO of the company until after he'd exfil'd data from the IG S3 bucket outside the scope of the bug report to try and leverage a bigger payout.

I have no reason to doubt any of that.

There's a lot of negatives about working at Facebook, but a lack of professionalism is not one of them.

Re: Instagram's Million Dollar Bug (2015)

#77
post #41

Earlier quoted context omitted.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

I think FB's greatest achievements is convincing their employees that their jobs are actually good for society, or at least neutral. Plenty of good people working there who seem honestly confused about how their jobs lead to so corruption and downfall of our society.

Their culture of continuous (and I do mean continuous) performance review ensures they're always focused on not losing their jobs. If you know someone who works there, ask 'em.

Re: Instagram's Million Dollar Bug (2015)

#78

Earlier quoted context omitted.

Hospitals do this, but backwards. The service provider gets to set the price.

Basically only in America, though. Elsewhere the situation where someone gets into a car wreck, goes to hospital and then gets told how broke they are now just doesn't exist. In much of the rest of the world, the health system sets and publishes the rates - and guarantees payment to service providers. The doctors perform the services, and then submit for renumeration directly to the health system. The patients, well,…

Most developing countries are moving to the US model - private hospitals in India, China and the Middle East, for instance.

What baffles me is how expensive government hospitals too are in the US.

Re: Instagram's Million Dollar Bug (2015)

#79

So, to summarize, you go to bank and you say "your back door is vulnerable can you check", instead of checking and giving you some kind of praise, they call police to beat the hell out of you... This is exactly sort of thing that will make community of white hackers stop caring, and leave open door to foreign agency malicious hackers to do as they please. I would like to know what was really going inside of their hea…

I think the issue was he went into the back door, and then found a key, and then started unlocking more doors. In other words, he used the initial bug to escalate access into their systems. Which is pretty obvious a no-no.

Re: Instagram's Million Dollar Bug (2015)

#80
post #3

God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.

Technically he used the 1st bug to enter their systems and then escalate access through other security holes or bugs.

That's not likely to be accepted by default by most companies. I would assume a default "do not escalate access" unless explicitly asked for.

Post reply on HN