Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

81–90 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#81

Earlier quoted context omitted.

> Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case? Those "mail us your gold" ads on TV.

Hospitals do this, but backwards. The service provider gets to set the price.

Pretty sure they make you an offer on the gold that you can decline. Probably still predatory but I think you are mistaken

Re: Instagram's Million Dollar Bug (2015)

#82

Earlier quoted context omitted.

> How else would you phrase someone telling you "I have this bug and will exploit it if you don't pay me X amount" Hello Strawman! > The second case would routinely cause a further review in any decent program We literally just read a example of how a big corp responds to #2. Do you think it was a 1 of?

I was part of "big corp" for the past three years and was involved in many bug bounty reports. A reasonable claim like "I think this should be higher because XYZ" gets investigated and, if justified, higher bounties issued. This blog post seems a bit one-sided and doesn't correlate to the facts that I have heard. I wasn't there at the time being so I don't know the truth. But that blog post seems not quite 100% to be…

Well, it includes verbatim copies of the whole email chain, and those are looking pretty bad in itself without any of the surrounding text.

Unless you're saying they've been tampered with, or that there was additional communication in between that he omitted, it seems pretty clear that this is not a professional way to handle communications.

Re: Instagram's Million Dollar Bug (2015)

#83
post #40

Earlier quoted context omitted.

> But then what? It looks like it was all just dropped pretty much as is? That usually means some money was exchanged and some NDAs were signed.

Why would Facebook NDA paying a researcher? Shouldn't they be shouting it at the top of their lungs?

From Facebook's POV the researcher behaved badly and rewarding that behavior without an NDA will encourage other researchers to behave badly.

Re: Instagram's Million Dollar Bug (2015)

#84

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

There is plenty of price competition for your bug disclosure: the Chinese, the Israelis, the Saudis, the Americans, OR directly to Apple. :-)

He said legitimate.

Re: Instagram's Million Dollar Bug (2015)

#85

Earlier quoted context omitted.

Hospitals do this, but backwards. The service provider gets to set the price.

Basically only in America, though. Elsewhere the situation where someone gets into a car wreck, goes to hospital and then gets told how broke they are now just doesn't exist. In much of the rest of the world, the health system sets and publishes the rates - and guarantees payment to service providers. The doctors perform the services, and then submit for renumeration directly to the health system. The patients, well,…

Side note, just fyi, because I used to make the exact same (tiny) mistake all the time. It's spelt remuneration rather than renumeration.

I think it helps to think of the `muner` part as being derived from the same root word as money rather than `numer` as number (which had been my previous assumption I guess).

You just inspired me to actually google my memory technique above, and it turns out the `mun` is from a latin root word for gifting (think munificent)[0]

So now I can think of a munificent monetary remuneration, and should remember it!

[0] https://www.merriam-webster.com/dictionary/remuneration#:~:t...

Re: Instagram's Million Dollar Bug (2015)

#86
post #79

So, to summarize, you go to bank and you say "your back door is vulnerable can you check", instead of checking and giving you some kind of praise, they call police to beat the hell out of you... This is exactly sort of thing that will make community of white hackers stop caring, and leave open door to foreign agency malicious hackers to do as they please. I would like to know what was really going inside of their hea…

I think the issue was he went into the back door, and then found a key, and then started unlocking more doors. In other words, he used the initial bug to escalate access into their systems. Which is pretty obvious a no-no.

Why? He jimmied a lock. A bank should not use a padlock. He found a key and found a dead end... oh no, in the dusty closet there was another lost key. That one shouldn't be there... wait the old key opens everything? Oh no.

Privilege escalation is explicitly allowed by facebook. He escalated.

Re: Instagram's Million Dollar Bug (2015)

#87

Earlier quoted context omitted.

I honestly think this is what free market economics will get us, due to the high barriers to selling on the black market (ethically, legally, and logistically). The bug bounty targets with high payouts from the company line up roughly with the ones with high payouts on Zerodium etc. As I stated elsewhere in the thread, I'm not honestly convinced the fallout from a company being breached is that high, which leads to t…

As someone who's not in the infosec/cyber industry, what exactly is Zerodium and why is it generally considered a suboptimal buyer?

Zerodium is one of several companies that buys exploits and sells them to governments. This route supposedly pays more than public bug bounties, but with different secrecy etc requirements.

Re: Instagram's Million Dollar Bug (2015)

#88

Earlier quoted context omitted.

IMHO it’s only a matter of time until someone blows up a unicorn just for the thrill of it. That’s not something I’d support, but I won’t feel bad for companies that don’t pay adequate bug bounties.

You mean like cracking the most lucrative accounts on Twitter and then stealing Bitcoin? https://www.wired.com/story/inside-twitter-hack-election-pla...

As of right now, what is the lasting damage done to twitter by that attack? My argument is that it honestly wasn't that much, and thus bugs capable of that amount of damage aren't valued that much either.

Re: Instagram's Million Dollar Bug (2015)

#89

Earlier quoted context omitted.

Basically only in America, though. Elsewhere the situation where someone gets into a car wreck, goes to hospital and then gets told how broke they are now just doesn't exist. In much of the rest of the world, the health system sets and publishes the rates - and guarantees payment to service providers. The doctors perform the services, and then submit for renumeration directly to the health system. The patients, well,…

Most developing countries are moving to the US model - private hospitals in India, China and the Middle East, for instance. What baffles me is how expensive government hospitals too are in the US.

It's not about whether the hospitals are private or not, it's whether you know the price beforehand and can make an informed choice - the most basic thing about the free market.

Re: Instagram's Million Dollar Bug (2015)

#90
post #52

Off topic, but there is a bug on Instagram that has been bothered me for quite a while. On web (not sure about the app), if your language is Japanese, for any profile that has 0 following, it will show "Following: 0" as "フォロー中NaN人". A screenshot for the lazy: https://i.imgur.com/rTGXe3T.png Of course this is a rather minor issue, but it still feels weird to me that one of the most popular website/service in the world…

My Kindle says “2GB gratis de 3GB” (in Spanish) which doesn’t make any sense, instead it should say “2GB libres de 3GB” (2GB free of 3GB). Free can be translated to either “libre” or “gratis”, libre is as in freedom, gratis is free as in beer. I can’t understand how the most popular reading device would have that kind of mistake in one of the most common languages in the world.

They likely do i18n like other companies, and just outsource it to someone for cheap, and never fix translation errors.
Post reply on HN