Live data from Hacker News

I found Prezi's source code

blog.shubh.am

131–140 of 266 posts

Re: I found Prezi's source code

#131
post #90

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

Having these kinds of rules on bug bounty programs is excellent for hackers though. If I wanted to hack Prezi I now have a lot of very useful information. 1) Prezi is not interested in blocking access to people who already have the ID of the presentation. This is good news since it means I can enumerate the IDs and get access to private presentations - some of which could have useful private data. 2) Prezi is not int…

'Just want to add that this shows a very large misconception in the corporate security world. Security is not something you can get a "B - good effort" for. Security is all encompassing. You either get an A+ and the hacker does not get in, or you get an F and your data is gone. There is no middle ground.'

That's not true. There are substantially different levels of security required depending on the expected resources an attacker can devote to attacking you, and you can be better or worse at resiliency and recovery (where dollars and hours very much form a continuum).

Re: I found Prezi's source code

#132
post #116

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

[deleted]

Someone that hacks your systems won't be limited to a single system or domain, I don't see why your reward system should be.

Would you rather that vulnerabilities discovered in out-of-scope systems be sold on forums instead?

Re: I found Prezi's source code

#133
post #116

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

[deleted]

It seems that he pointed out a security vulnerability in your infrastructure - something you do have control over. And if a vulnerability is found in an external service you use, do you feel that you don't have a responsibility to mitigate the risk posed by the service whether or not you have direct control over it?

Re: I found Prezi's source code

#134
post #86

I hope he downloaded their whole sourcode. That should make locating in-scope bugs much easier.

I don't know about you, but I'm not about to proof read someone else's source code for a system I don't even know.

I'm willing to do it for $500 a bug :-)

Re: I found Prezi's source code

#135
post #59

Earlier quoted context omitted.

Well of course there have to be rules. Does spear phishing employees email accounts and using their password to access control panels count as a bug? I bet I could hack a lot of companies that way. Does being susceptible to a massive DDoS count as a bug? Cutting power to the building? I can't speak for Prezi, but it seems like they want people to test the security of their app, but not of their employees or back offi…

Large tech companies routinely run pentest exercises against themselves that involve phishing their own employees. Good security has to include educating the human element as well: if you have great technical security but all you have to do to get in is ask an employee their password, you've lost. Large companies also invest significantly in protection against massive DDoS and power cuts to the building, along with d…

I wasn't trying to say those things aren't really security problems... just that they perhaps aren't things you'd want random people on the internet attempting to exploit.

Re: I found Prezi's source code

#136
post #66

Break the rules, don't get the money. Surprise!!?? After reading the entire email thread, I think Prezi comes out better off than the OP: Actually we're continuously thinking on your case and struggling on the right move. On one hand, your finding was very useful for us, and we learnt a lesson from it. On the other hand, intra.prezi.com is out of scope, and by using the credentials to log in you violated the terms an…

...if we were about to pay, we couldn't justify our out-of-scope decisions for anyone else.

What, are we in kindergarten? Does Prezi not have managers entrusted with taking decisions? They can run their bounty program however they want.

That they choose to run it in this fashion sends several messages in addition to the obvious, "we are obnoxious miserly prats". While hackers in white hats might be hearing "concentrate your efforts elsewhere", those in black hear exactly the opposite message. Many people who might previously have admired Prezi for their innovation and paid them money for their services, have now heard a reason to find other means to create presentations. Potential acquirers and potential hires have heard that this company's management finds running a bounty program challenging.

EDIT: Maybe I'm being too harsh. Apparently this is a largely Hungarian company; it's possible there are cultural misunderstandings in play. From a (perhaps cliched?) American perspective, however, following the rules is less important than accomplishing the goals of the program.

Re: I found Prezi's source code

#137

There should be some neutral third party non-profit that adjudicates bug bounties so that security researchers don't need to worry that their efforts will go to waste. Companies could sign on to using this third party and pay a fee and put up escrow for the service. This would motivate researchers to find bugs for those companies that utilize the service, knowing payment will be impartial.

A simple option is CrowdCurity - reward programs as a service. Private or public, dollars or bitcoin payments - everything setup and managed for the companies.

https://www.crowdcurity.com/

Disclosure: I'm co-founder of CrowdCurity

Re: I found Prezi's source code

#138
Bug bounty program or not, I would be pretty afraid to try to log into a source code repository without authorization to do so. It seems like a lawyer could really go after you for doing something like this.

Re: I found Prezi's source code

#139
post #129

Earlier quoted context omitted.

This is a no-brainer. Surely the risk of putting off skilled people from your bug bounty program due to the press from this could cost you a lot more than $500.

[deleted]

Someone at your company should probably be thinking about Prezi's reputation. That person should probably have a discussion with whomever is running the bounty program.

Re: I found Prezi's source code

#140
post #116

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

[deleted]

Fuck the bounty, just give the guy 1k reward to save your ass from an epic fail!
Post reply on HN