Live data from Hacker News

A Bug in the Bug Bounty

engineering.prezi.com

21–30 of 37 posts

Re: A Bug in the Bug Bounty

#22
Why don't you just pay him for the service he provided you? Is your bounty that high that you can't afford to?

It seems the negative publicity you are getting is going to cost you more..

Re: A Bug in the Bug Bounty

#24

Prezi's apparently trying to cover their posteriors in the wake of Shubham's disclosure and subsequent snub ( http://blog.shubh.am/prezi-bug-bounty/ ). "We greatly value this feedback." Weak sauce. Shubham's disclosure saved Prezi from a future nightmare. If they're not going to pay him from the bug bounty coffers, they should at least try and sound more like grateful humans rather than a pissy HR department trying t…

I agree as well - this "apology" sounds so wishy-washy and weak.

Re: A Bug in the Bug Bounty

#25
I haven't been following this story that closely but I just don't understand why they don't pay him outside the bug bounty.

"Sorry this security hole wasn't in our bug bounty but we'd like to give you the reward anyway. Please sign these legal documents and let us know if you find anything else."

There is so much you can do by just being reasonable. Like if Prezi said they can't officially acknowledge it under the bug program but can just pay out some sort of reward it makes way more sense.

Besides. If the bug was in the code under a subdomain that someone exposed source code it would be the same thing.

Re: A Bug in the Bug Bounty

#26

Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…

In today's world, you'd be expelled...

https://www.google.com/#q=expelled+for+reporting+security+bu...

Re: A Bug in the Bug Bounty

#27
post #19

Earlier quoted context omitted.

I don't know about that: "from now on" seems to imply that in the future that will be the case.

Also: "and that their report triggers us to improve our code base". Closing port 8001 isn't quite improving the code base.

But combing source code repositories for config files containing private information might be. 

Re: A Bug in the Bug Bounty

#28
post #26

Anecdotally I was snubbed at a younger age when the school district was looking for a security system to prevent manipulating school grades. My suggestion was to remove the disk pack (ok so it was a while ago) that contained student records while the students had access to the system via dialup, and replace it at night when the various accounting programs ran (attendance, grades, etc). Imagine my surprise when the co…

In today's world, you'd be expelled... https://www.google.com/#q=expelled+for+reporting+security+bu...

[deleted]

Re: A Bug in the Bug Bounty

#29
post #23

Let's all agree that had Shubham not posted what had happened prezi wouldn't have done anything. This is just a PR stunt to save face.

No, I'm not going to agree. From Shubham's post it looks like they were already planning to expand the scope of their program in response to his findings. This is from their email to him on Nov. 4, a full month before his blog post:

First of all, we're still very thankful for pointing this issue out. The credentials you found were real threat. I agree when you write it was easy to exploit.

[...]

When we created the terms and conditions, we tried hard to add every web app which we have impact on, and where a reported issue is a value for us. At that time we weren't thinking of leaked password or such. In the past we turned down the bounty request of people finding issues in out-of-scope services. We had a lot internal discussions about your request: if we were about to pay, we couldn't justify our out-of-scope decisions for anyone else.

It seems reasonable from that email to assume they were discussing this incident seriously and thinking about how this would affect future bug bounties. I am willing to give them the benefit of the doubt unless you have a strong reason otherwise. When the matter was private between them and Shubham they issued a private apology and explanation. Now that Shubham has made the issue public they have issued a public apology and explanation. This is an appropriate response, not just a PR move.

Re: A Bug in the Bug Bounty

#30
post #22

Why don't you just pay him for the service he provided you? Is your bounty that high that you can't afford to? It seems the negative publicity you are getting is going to cost you more..

It seems reasonable to assume that they will pay him:

To improve the program from now on we will reward bug hunters who find bugs outside of the scope provided [...] We will also retroactively check to see if other reports found issues that fall into this category.

Post reply on HN