Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

101–110 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#103
post #2

The edited title on HN is incomprehensible. The original is: ”1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies” A better edit might be something like: “The $50k bug where Zendesk backdoored Fortune 500 companies”

That title is also completely misleading because the author did not in fact get paid. 50k corresponds to the money they made with unrelated bug bounties. I wish they would fix the title so that it properly calls out zendesk refused to pay for a serious bug.

I understood it to mean that he received $50K from enterprises using Zendesk who were vulnerable to this bug, but it's not entirely clear.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#104
post #60

Earlier quoted context omitted.

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

I am actually seriously interested in what people there do day to day. I’m wondering this about a lot of very large companies, I would definitely watch a documentary about that.

Hour-long meetings about whether the copy should read "data center," "datacenter," "data-center," or whether it is really even correct to say any of these at all. And then negotiating with the design folks to fit in the extra character. Only to throw it all away because nobody thought about the fact that it has to support 5 different languages.

I wish I was kidding. Used to work at a place that did crap like that, pulling in developers for these time sucks because "only they really know the correct technical usage for our industry."

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#105
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

[flagged]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#106
post #68

Earlier quoted context omitted.

I look at the Docusign building every day and shake my head. 20 stories of office space!

Software developers being surprised that software companies need to do a lot more than just write code is kind of like sailors being surprised that global logistics involves a lot more than handling a ship.

Still naive enough to buy into the lie that they can just be “left alone to do the REAL work” and a business just…spontaneously appears around them.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#107
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

> they have toured the world, headlining major festivals and sharing the stage with legendary acts like Sweater Head, DynoPlax, and The Banana Nuts. Now, Zendesk Alternative has begun a new chapter in their storied career. They have joined forces with Zendesk® to record an anthemic concept album of epic proportions. On the surface, it's a collection of songs about customer service. Underneath, it's about so much more…

No they wouldn’t. You just dislike Apple.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#108
post #30
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

Aaaaaahhh I am on a rollercoaster of customer experience. I am beyond annoyed at Zendesk for stiffing this kid, but actually kinda charmed by this quirky marketing gimmick. But also, SECURITY culture concerns beat culture culture. Companies should def consider ditching them for this lapse and their poor form in making it right. If Zendesk is smart, they should hop on this thread and pay this kid out while everyone is…

>but actually kinda charmed by this quirky marketing gimmick.

I'm actually pretty annoyed at the stupidity, it's the kind of thing that even a shitty search engine won't be fooled by and hey when I search for Zendesk alternatives I don't see any brand called Zendesk alternative in first few results.

I mean it's like they're too stupid to do what every other weaselly scumbag does, get some fake reviews up comparing your brand to alternatives with the reviews carefully weighted so your target customer base will be uh, I guess Zendesk is really what we want then.

Or at least buy an ad words for the search - with the words Zendesk - There is No Alternative showing up before all the alternatives.

It's ok Zendesk if you use my clever slogan because you can't think of one on your own - I'm not expecting you to pay me for it.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#109
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

Let me guess, you could build it over the weekend?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#110
post #16

Earlier quoted context omitted.

That is why a black market exists for this stuff.

The black market also exists because the potential payout for serious 0days by official programs is almost always less than what a third-party adversary will pay (if the target(s) for them are worth it).

The price for 0days is highly variable according to this presentation (starting slide 65):

https://github.com/mdowd79/presentations/blob/main/bluehat20...

The same presentation also mentions (starting slide 17) how the requirements of 0days differs from public research, which is why some vulnerabilities would be difficult to sell.

Post reply on HN