Live data from Hacker News

A Bug in the Bug Bounty

engineering.prezi.com

11–20 of 37 posts

Re: A Bug in the Bug Bounty

#11

This is a trite response to an actual concern: Placing scope limits on bug bounties is meaningless and dangerous. Hackers will not respect your scope. The scope of a bug bounty program should always be "Anything that affects our, or our users, data or security". There's plenty of non-entities that get reported: Failures of XSS protections on data that is actually public, vulnerabilities on vendors sites that don't im…

I think that oversimplifies the problem. I think a scope helps keep overeager researchers from doing things that result in legal problems for the company. For example, are laws that require notification of data breaches and personal identification triggered in certain cases? This isn't an academic setting, these are real businesses.

I think the best of both worlds would be very wide scopes with targeted limitations. Don't log into user accounts or company accounts at other services, but here's a few sample user accounts that are fair game and if it's an external service, here's a rep to vet whether credentials you gathered are correct or not.

Re: A Bug in the Bug Bounty

#14
post #5

Earlier quoted context omitted.

"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.

I don't know about that: "from now on" seems to imply that in the future that will be the case.

Check the end of the quote, it says "retroactively".

Re: A Bug in the Bug Bounty

#15
The last time I checked Prezi was extremely buggy to the point of being unusable. So they should be very thankful for any bugs reported. Probably their app usability is the consequence of not responding to the user reports.

Are they still relying on adobe flash when everyone else moved on?

Re: A Bug in the Bug Bounty

#16
Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the contest ended with no winning solution, but oh by the way we've changed our policy and will not make the student grades data available during the day.

We did get them finally fess up that it was my suggestion which they had adopted and they gave me the prize (which was a $250 scholarship as I recall). But it has never ceased to amaze me that people don't think of security as holistically as they should.

Re: A Bug in the Bug Bounty

#18
Kudos to Prezi. They were not obligated to respond this way but they chose to, and I think it is the best response they could have made. I particularly like their statement that they would look to see whether anyone else had found volunteer abilities that also should be rewarded under the new program.

Re: A Bug in the Bug Bounty

#19
post #5

Earlier quoted context omitted.

"To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided that they do not violate our users’ information and that their report triggers us to improve our code base. We will also retroactively check to see if other reports found issues that fall into this category." This means Shubham will get the bounty.

I don't know about that: "from now on" seems to imply that in the future that will be the case.

Also: "and that their report triggers us to improve our code base".

Closing port 8001 isn't quite improving the code base.

Post reply on HN