Earlier quoted context omitted.
> ...or drug addicts looking for money for their fix. What a catastrophically bad idea..
Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.
I Got Paid $0 from the Uber Security Bug Bounty
121–130 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#122Re: I Got Paid $0 from the Uber Security Bug Bounty
#123Earlier quoted context omitted.
Sounds great until you realize 1. riders would only use the app if they could sort by 'price,' 2. drivers would therefore have to constantly change their rates to reflect what those in the area are charging at a given time/supply/demand level, so.. 3. in order to do this effectively without creating massive unexpected price swings for both drivers & riders, you'd end up automating this 'bidding' system and hey whaddy…
Genuinely curious about this - why would the price swings in this case be worse than with uber? With enough drivers, I would expect prices to reach an equilibrium that depends on time of day/day of week, with highly rated drivers charging more. And even if the price swings were larger than uber's, wouldn't the prices be more optimal since they would be set by individual actors with more local info about the cost of p…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#1243 of the bug reports are now publically disclosed: https://hackerone.com/reports/293358 https://hackerone.com/reports/293363 https://hackerone.com/reports/293359
#293358: it's not ideal that the certificate isn't pinned, but to exploit this an attacker needs to either install their own root certificate on the victim's device, somehow obtain a private key for a certificate already installed, or have a certificate authority misissue a certificate to them for an Uber domain used by the app.
#293363: an attacker still needs to acquire the victim's X-Uber-Token somehow for this to be useful. It's also somewhat mitigated by the token being invalidated when the victim changes their password.
#293359: as pointed out by Uber, no weaknesses in the token generation algorithm were actually demonstrated, and brute forcing the 2^128 keyspace is infeasible.
Also, the rudeness he displayed was petty and unhelpful:
> given the fact that at least one of your system architects were apparently high when they designed and implemented your bearer token assignment process
> Not completely unexpected though, given the caliber of talent utilized by Uber such as the “security” group that you hail from. You would do well in government security consulting, for sure.
> Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ
All in all, rather a poor result for this vulnerability researcher.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#125So what protects HackerOne users from companies claiming that every report is a known issue and not paying anything out ever?
Re: I Got Paid $0 from the Uber Security Bug Bounty
#126Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#127Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.
Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#128Earlier quoted context omitted.
I challenge you to explore addiction more fully - it is simplistic to assume that all addicts are opioid-linked and that maintenance dosages would remove harm (methadone programs are basically performing this function, so it is not as though this doesn’t happen). Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Becaus…
I'm the child of an addict. It really depends on how you measure cost - the current regime of punishing it, or treating it as a character weakness is clearly not working - plus moving sustained addiction outside of a care network to the black market, also clearly isn't working either. Everything we do has a cost to the community, the question is, since we know we can't eliminate the cost, how can we reduce it?
Re: I Got Paid $0 from the Uber Security Bug Bounty
#129“I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system.”
Where’s the proof? I don’t see any whatsoever. I highly doubt that you were actually able to bypass the OneLogin because if you did, they’d definitely pay out and it’d be an actual issue rather than some crappy bugs.
Lack of certificate pinning IS NOT a critical issue. Critical issues are code execution, file read, etc.
The odds of you actually guessing UUIDs are super low and pretty difficult, they did the right thing in closing as informative. You’d have to try “~ 10²⁹ values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second.” You claimed their PRNG was broken but had no evidence or support to back it.
“Are you seriously the Program Manager for Uber’s Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting?” — you’re a complete moron, glad you know how to personally attack people, Uber definitely had the right to ban you from their program.
Programs CANNOT delete comments from HackerOne Reports (as you claim in https://hackerone.com/reports/293359)
Uber DEFINITELY made the right choices in closing your reports as informative, but go ahead, fool yourself