Live data from Hacker News

Beg Bounties (2021)

troyhunt.com

91–100 of 174 posts

Re: Beg Bounties (2021)

#91
post #35
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

“But I already washed your window while sitting at the stop light” It’s one thing to go begging, it’s another when they feel entitled to some sort of payout. I never asked for their “services” - and in my limited experience, they lash out at you too, when you explain you’re not paying.

My parents lived in New York City during the early 1970s, a time of serious decay. The "free" car window washers was a thing. You would stop in traffic (Manhattan) usually, then someone would start to clean your front window with a dirty squeegee, then come to your driver side window and ask for a tip (payment).

By the time it started showing up in 1980s comedy films, it was mostly gone in real life. I am surprised to see an Ozzie referring to this. Or is he referring to something tlese?

Re: Beg Bounties (2021)

#92
post #35

Earlier quoted context omitted.

“But I already washed your window while sitting at the stop light” It’s one thing to go begging, it’s another when they feel entitled to some sort of payout. I never asked for their “services” - and in my limited experience, they lash out at you too, when you explain you’re not paying.

My parents lived in New York City during the early 1970s, a time of serious decay. The "free" car window washers was a thing. You would stop in traffic (Manhattan) usually, then someone would start to clean your front window with a dirty squeegee, then come to your driver side window and ask for a tip (payment). By the time it started showing up in 1980s comedy films, it was mostly gone in real life. I am surprised t…

He's referring to car window washers at traffic lights.

Maybe in Australia which has had them at various location in capital cities in the 80s, 90s, 10s by my recall. Maybe in other countries as while Troy is Australian he's moved about a bit ... but probably Sydney - it's one of those modern clean yet dirty cities with a bit of everything.

EDIT: The quote doesn't come from Troy, it's sourced from a twitter reply he received from "John" @j3g

Re: Beg Bounties (2021)

#93
post #90

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

No criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.

Oh yes. In 2011 I got raided by the police because I clicked a link someone sent me over IRC [1].

You don't even need to be destructive to become a target for prosecution sometimes. Being stupid or incautious is enough.

[1] https://blog.haschek.at/2015-that-not-so-awesome-time-the-po...

Re: Beg Bounties (2021)

#94

Earlier quoted context omitted.

It’s so bizarre that every time I upload something to S3 I have to jump through a hoop to make it publicly readable and Amazon displays a massive warning sign. Like the only thing I use S3 for is hosting open source software binaries. Maybe there’s a use case for restricting access, but I don’t even know what that would be.

You really need to think carefully about whether you want to expose an S3 bucket publicly. There are probably some valid reasons out there, but if you're not an AWS expert, it's likely that you're making a mistake. If I find out the name of your bucket I could cost you thousands of dollars of egress tonight before you wake up in the morning. It's _especially_ likely to happen to hosters of open source binaries becaus…

Hosting a file on a url anyone can access from anywhere is the whole point…

Re: Beg Bounties (2021)

#95

Earlier quoted context omitted.

Inadvertent public buckets leading to data loss is what created those hoops. Trying to take the ammo out of the footgun. https://www.theregister.com/2022/12/14/aws_simple_storage_se...

But why would they upload private data to S3 in the first place? I’m just not understanding the context here.

A fair chunk of modern corporate data ends up in OLAP systems that are now more often or not stored using s3 (or their MS/Google equivalents) in 'Data Lakes'. The concept of 'private data' whilst using cloud providers is an interesting one, but there has been enough work done by all parties involved to ensure that all but the most sensitive data is now created, stored and analysed using the systems provided by "Big Cloud".

Re: Beg Bounties (2021)

#96
post #93
post #90

Earlier quoted context omitted.

No criticism because teenagers do dumb things, but for anyone else it should be assumed that if you break into a system without permission, benignly or not, you run the risk of getting prosecuted for it.

Oh yes. In 2011 I got raided by the police because I clicked a link someone sent me over IRC [1]. You don't even need to be destructive to become a target for prosecution sometimes. Being stupid or incautious is enough. [1] https://blog.haschek.at/2015-that-not-so-awesome-time-the-po...

I vaguely recall this case. I sure hope police have become more cyber literate in the past 10 years, but yeah this is the virtual equivalent of leaving fingerprints on the crime scene.

Re: Beg Bounties (2021)

#97

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

A good lesson to never do that - just use VPN to login to IRC to some hacking channel and report the issue there.

Of course you should also do the white hat part in anonymized fashion.

Re: Beg Bounties (2021)

#98

Throwaway account for obvious reasons. I've been employed as a triager on two primary bug bounty platforms for over seven years. The circumstances are distressing and carry tangible real-life consequences. I'm open to answering questions within my personal comfort zone.

This comment would be a lot more interesting if it wasn't so vague

Re: Beg Bounties (2021)

#99

I remember when I was a teenager I found a huge security flaw in a website: they allowed to include any PHP file passed as a query string parameter, and that file could be a remote one too. They didn't listen to me and I found that offensive, so I used the flaw to get access, and leave a message on their FTP server. I didn't destroy nor steal any data. They responded by reporting the incident to the police.

It's the danger of good intents but still breaking the law. If a house is unlocked and you go in to prove it's unlocked, maybe leave a helpful note, you're still breaking in. Report and move on.

Re: Beg Bounties (2021)

#100
post #16

I don't really understand the point of making a big stink about Beg Bounty Hunters. They're invariably people in developing countries, for whom occasional SPF or Clickjacking payouts will be meaningful. And there's an unbounded supply of them. They're not going away. All you can control is the way you respond to them; lashing out at them in public seems like a pretty unhealthy response. Not for them; who cares? There…

There are a few reasons. 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm. 2. The second reason is the approach that the beg bounty uses: that of fearmongering. If the beg-bountier disclosed the vuln and asked for the bounty that would be ok,…

> 1. The first is literally the first example of the article: real/important vulnerability disclosures get confused with beg bounties which dont need to be acted on / are not serious (most of the time). That can cause real harm.

I have a hard time sympathizing with this. Our project gets a handful of these "beg bounty" things a year; usually they're repeats -- SPF and "clickjacking" are common ones, but we also get other ones. ("You're exposing people's usernames through this weird JSON thing!" "Yes, we're also exposing people's usernames in the 'by' line of the post itself. There's nothing in that JSON that's not also available by just doing plain web scraping."). If we see a new complaint we always look at it to see if it's something we actually care about.

If you're working with pictures and audio of kids, or have details of people's activities that they may not want made public (like their taste in "Adult Fanfic"), there's absolutely no excuse for not looking at each report, even if 95% of them are low-value.

EDIT: I mean of course the "Report and then ask for a bounty" kinds, not the "Give me the bounty and I'll tell you the bug" kinds.

Post reply on HN