Live data from Hacker News

A little note about Slack’s Bug Bounty program

abhartiya.wordpress.com

11–20 of 52 posts

Re: A little note about Slack’s Bug Bounty program

#13
Keep their attitude toward security flaws and the disclosure today in mind when you consider what would happen if your entire company's private chatlogs suddenly became public. Same goes for Hipchat too.

User accounts and passwords are easy to reset and fix.

Credit cards are easy to reset and fix.

Years of private company discussion showing up in the wild? You're unlikely to ever recover.

Re: A little note about Slack’s Bug Bounty program

#14
http://slackhq.com/post/114696167740/march-2015-security-inc...

http://valleywag.gawker.com/slack-is-letting-anyone-peek-at-... https://news.ycombinator.com/item?id=8425799

Tbh, at this point I wouldn't be surprised if these "problems" occurred after someone discovered the bug and reported it.

Re: A little note about Slack’s Bug Bounty program

#15
post #3

I read the PDFs of #39132 and #51179, and first, these are very clear and well written vulnerability reports. Props to the author for that, many times these reports can be extremely hard to follow and these are shining examples to the contrary. I found them easy to follow, enough details to reproduce, and quite valid issues. Second, I'll put my neck out here a bit and say, I find myself agreeing with the author's sta…

I was banned from reporting any bugs to the Slack Bug Bounty program on the HackerOne platform after reporting the 3rd bug. What's worse is that I wasn't even notified of this? Even HackerOne didn't think it was necessary to do that.

Re: A little note about Slack’s Bug Bounty program

#16
post #3

I read the PDFs of #39132 and #51179, and first, these are very clear and well written vulnerability reports. Props to the author for that, many times these reports can be extremely hard to follow and these are shining examples to the contrary. I found them easy to follow, enough details to reproduce, and quite valid issues. Second, I'll put my neck out here a bit and say, I find myself agreeing with the author's sta…

On point 1, how do they even expect a researcher to know that some other researcher has found the exact same bug if it's not disclosed yet? This seems like a fake rule whose only possible effect is to suppress disclosure.

Exactly. Their word is as good as mine, right? This is the biggest problem I see in bug bounty programs. You are at the mercy of the program.

Re: A little note about Slack’s Bug Bounty program

#17

I'm currently in charge of answering reporters on a HackerOne program and I can tell that the way Slack is managing its own is completely unacceptable. Those reports were really high quality ones, whenever I receive a report like that I cry of joy. If you run a bounty program you should: - Be ready to answer every single report on a short timeframe - Be fair and provide feedback to the reporter - Be nice, be thankful…

Thanks. It is good to know that such programs exist as well.

Re: A little note about Slack’s Bug Bounty program

#18
post #5

I'm siding with the vulnerability researcher here. This is ridiculous. The spirit of a bug bounty program is for the company to incentivize a researcher to find bugs and work together to squash them. Maybe this more telling of HackerOne as a platform.

I think HackerOne as a platform failed here as well. I understand they try to leave themselves out as much as they can and just collect the fees for the bounties paid. But, in cases like this, I feel they should have been a little more proactive about it. I received an email from HackerOne shortly after I wrote this blog saying they will investigate but I haven't heard a word till now. Soon after that, I found out myself that I have been banned from reporting any bugs to Slack without any notification. HackerOne could have at the very least sent me an email out of courtesy but no, never happened. I even sent them a follow up email asking for clarification but haven't heard a word till date.

Re: A little note about Slack’s Bug Bounty program

#19
post #7

It feels to me that Slack is trying to be all high-and-mighty/"no you're wrong, we're right [even though you're right]"

I definitely got a very bad attitude from them. I was really trying to be nice and report bugs with detailed reports including detailed PoC videos demonstrating everything. But, it was disappointing to see their responses honestly.

Re: A little note about Slack’s Bug Bounty program

#20
post #2

Combined with their recent hack and their exposing of team names a few months ago, I'm becoming wary of using Slack. They don't seem to have a security-focused culture, and that's a massive problem for a communication service.

I accidentally signed into another organization's channels on Slack. Had to delete and re-make an account to get into my organization's channels. Apparently there were already concerns about Slack not taking security seriously, so it wasn't really all that shocking to me. Currently not using Slack, obviously.

Sorry other organization – I hope you guys move off some time soon.

Post reply on HN