Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

51–60 of 174 posts

Re: Beg Bounties (2021)

#51

I miss the old internet.

On the old internet, if you could trick someone into revealing their IP address, you could knock them offline: https://en.m.wikipedia.org/wiki/Ping_of_death

But it was fun because we were young, the "attackers" were our friends, and there weren't billions of dollars on the line.

Re: Beg Bounties (2021)

#52
post #9
post #4

I guess I wonder about the opposite side of this. While I hate the beg bounty people as well, I don't think security researchers should work for free. I have found several security vulnerabilities that I have never reported to the company because their security policy was basically "send us everything you found for free and we won't give you any credit".

nobody's asking security researchers to work for free. the people asking security researchers to work are paying them for that work. if you're doing un-asked-for work, you can't expect to get paid

I agree. But there are advantages to be gained beyond mere payment. Assuming the work is somewhat more that just "I fed your name into ssllabs")

Say you find a genuine issue. You can document it and send it to them. You might suggest an appropriate amount, but you've given them something to evaluate. Chances are you get nothing, but there is still other value in the exercise.

You can also add this to your portfolio. Once you have a few of these apply for jobs at security firms. They can judge your skill level to see if you're worth adding to the team.

You can also determine if this is a whole class of problem. Publishing the issue (without naming the company involved) raises your profile. You can leverage that profile into paid work down the road.

Of course you should understand all this before you "do the work" in the first place. If you're gonna do random drive-by work you should understand your goals. Given that the parent did not disclose, presumably there was some other motivation in play.

Re: Beg Bounties (2021)

#53

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

I’m not sure the BronxWench cares strongly about what people on the Internet think of her.

It seems far more likely that they didn’t understand the email from Troy or dismissed it as spam or a scam.

They took notice because a bunch of their regulars started getting emails from HIBP. Some of these did understand, and brought the issue to the attention of the admins admins in a way they understood.

Re: Beg Bounties (2021)

#54

> Alas, all reasonable measures were exhausted without response, I loaded the data into Have I Been Pwned (HIBP) and then they took notice Every single time. They don't really care about users, their safety and privacy. They care about legal liability and not looking foolish in public. It seriously makes me wish people would just publish vulnerabilities straight up complete with exploit source code so they'd have lit…

I’m not sure the BronxWench cares strongly about what people on the Internet think of her. It seems far more likely that they didn’t understand the email from Troy or dismissed it as spam or a scam. They took notice because a bunch of their regulars started getting emails from HIBP. Some of these did understand, and brought the issue to the attention of the admins admins in a way they understood.

She clearly cared enough to threaten to "report" the guy.

Re: Beg Bounties (2021)

#55

Earlier quoted context omitted.

It’s so bizarre that every time I upload something to S3 I have to jump through a hoop to make it publicly readable and Amazon displays a massive warning sign. Like the only thing I use S3 for is hosting open source software binaries. Maybe there’s a use case for restricting access, but I don’t even know what that would be.

Inadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_se...

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

Re: Beg Bounties (2021)

#56
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

[flagged]

What an uncharitable and uncalled for accusation. Dude's twitter is him living his life and posting it. No one is asking you to follow him or read his stuff. He's rich and posts about some of it. Who cares. I've never seen him pretend to be a celebrity and the accusation of giving merch for harassing others sounds like an outright lie. I've been following him for years and have seen no such thing

Re: Beg Bounties (2021)

#57

Earlier quoted context omitted.

Inadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_se...

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

S3 is just a general storage bucket, anything you could use a hard disk for, some app is using S3 for that instead. It's particularly common in serverless app backend architectures where no permanent storage exists at all, so volumes are not an option.

A good deal of hosting is done on ephemeral VM instances that get rebuilt, so you choose between volumes and S3, and S3 is a bit more flexible.

Re: Beg Bounties (2021)

#58

Earlier quoted context omitted.

Feel like recording intimate moments like that should just about be a crime at this point. Sick of every dicknose with an iPhone trying to "remember" a group dinner

Before we make it a crime, should we have a theory of the harm it inflicts?

Face recognition. In terms of govt scale intelligence, and increasingly just plain OSINT. Not everyone is as tight with their pictures as you are, they probably auto upload them on Google Photos or Dropbox or something. You are now irreversibly linked to everyone else in that photo who probably has social media profiles, public contact emails, show up on people search websites etc. I don't want to cause problems for you just because someone wants to blackmail me. I also don't want you to tell people where I live because someone broke into your house and is removing your toenails with a pair of pliers.

Subjective opinion time, I just think it's lame. I don't sit back and reminisce over pictures. I don't want to be in your group picture. I want to hang out with the people in the group and have a laugh.

Re: Beg Bounties (2021)

#59

Earlier quoted context omitted.

Inadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_se...

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

Many applications use s3 as a data store for... Whatever. Uploaded or generated files, intermediate outputs, as a key-value store for large blobs.

You can put all sorts of things on s3. The PDF containing your bank statement, your medical test results, whatever - S3 is plenty secure enough for that with sane configuration, and even by default with sane account management.

Re: Beg Bounties (2021)

#60
post #57

Earlier quoted context omitted.

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

S3 is just a general storage bucket, anything you could use a hard disk for, some app is using S3 for that instead. It's particularly common in serverless app backend architectures where no permanent storage exists at all, so volumes are not an option. A good deal of hosting is done on ephemeral VM instances that get rebuilt, so you choose between volumes and S3, and S3 is a bit more flexible.

[deleted]
Post reply on HN