Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

211–220 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#211
post #116

Earlier quoted context omitted.

Except it says "whichever" is higher, so if they decided to fine you 10 million or 2% of revenue, and your 2% is much lower than 10 million, guess which one you're paying... > Up to €10 million, or 2% of the worldwide annual revenue of the prior financial year, whichever is higher See: https://www.gdpreu.org/compliance/fines-and-penalties/

They key part there is "if they decide to fine you...". The max(€10m, 2%) and max(€20m, 4%) are the most that supervisory authorities may issue as fines. But supervisory authorities have a legal duty to issue fines that are proportional which means than unless you breach the GDPR in a wilful and egregious manner you're unlikely to be fined that much (and if you are you can appeal the fine to a court who would reduce…

When would it ever be proportional to charge a small business more than 2% if they can never charge a large business more than 2%? Are small businesses, as a general rule, somehow more capable of causing damage than larger businesses?

Is the law as written somehow vulnerable to some legal hack where all my revenue goes through Company A but all my data goes through Company B, so that Company B has a small global revenue despite being extremely profitable to the controllers of the companies?

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#212

Earlier quoted context omitted.

> I keep thinking we need some sort of new license for open source that limits which entities can use the software based on their net worth or the networth of their shareholders. That might be a new license, but it is by definition not open source. And, no, companies like Google won't “automatically” buy commercial software with that style of license; from their perspective it's worse than regular commercial software…

Hey, try not insulting people that are trying to have a reasonable conversation. > EDIT: How about instead a “new” license that, if you feel the software isn't maintained adequately for the needs of your organization, allows you to hire whoever you want to maintain it to your requirements, instead of impotently raging that other people aren't supporting it? It makes sense for the people that are getting the most prof…

> It makes sense for the people that are getting the most profit from a piece of software to be the ones paying for basic maintenance/cleanup/improvements.

It often does make sense for them, and you can see lots of cases where this is is done with actual open source software without resorting to a commercial license that discriminates on scale. If it doesn't make sense for the people you want to pay, making a free-for-everyone-else license isn't going to convince them that it does, it's just going to convince them that they are better served elsewhere.

> If you want customizations or new features, that's when it makes the most sense to 100% self-fund.

I would argue that it makes sense to 100% self-fund the additional work whenever you want something more than the open-source offering provides and doing so is less expensive than commercial (off-the-shelf or bespoke) solutions, whether the additional work is basic maintenance or something else, and if you are using an open source solution and it's not maintained adequately for your need, the responsibility for addressing that isn't on other users that you’d like to have subsidize your use.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#213
post #91

Earlier quoted context omitted.

From reading a different article, the terminology seems to be a bone of contention here. This ’2FA' is an email message PayPal send when they detect a new login location. They do not call it 2FA and they do offer actual 2FA that cybernews have not bypassed.

It's very obviously a distinction without a difference though. Like the authors say, this is a amazing opportunity for black-market paypal account buyers. It's the only line of defense that thousands of people have between black hats and their bank account. In any case, I'd definitely call this 2-factor authentication - the only difference is the trigger (every login vs suspicious logins). It just so happens that the…

There's a huge difference between an informational email "somebody just logged into your account, was it you?" and 2FA workflow which does not let you log in without entering proper code. The latter is a security feature, the former is at most auxiliary informational feature.

> I'd definitely call this 2-factor authentication -

You'd be misunderstanding what "authentication" means then. Notification and authentication are different things. Email is notification, not authentication. Confusing it means either not knowing what authentication is, or purposely confusing matters to present issue as something it isn't.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#214

I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.

HackerOne, itself, is pretty generous about reported bugs. (As in, you reported an issue in the website hackerone.com.) They have to be, because their existence depends on everyone thinking bug bounty platforms are a good idea -- it's part of their way of encouraging people to hunt for bug bounties in general. Payouts for bugs in other products are determined by those companies, not by H1.

Bah no they aren't, HackerOne has a small collective of security testers that they consistently make awards to, over and over again. If you submit a critical vulnerability, magically one of HackerOne's top ranked folk end up getting the award, AND HackerOne won't share any aspect of that triage information with you to actually prove that the vulnerability you submitted was legitimately discovered prior to your submission.

Junk company, waste of time and effort which results in all of their clients getting 95% free security analysis services.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#215

Earlier quoted context omitted.

> failing to respond to a self-XSS report This really downplays the report or shows a complete lack of understanding. Getting access to someone's Paypal account which could potentially mean all their credit cards and banks is definitely an issue that needs to be addressed. This in itself should not be reason to lose PCI certification. However, as the article further indicates [1], failure to respond (or even closing…

It's not at all clear to me what you're saying here. Are you making a case that the whole report all put together is impactful? Or are you actually trying to argue that self-XSS is a critical security vulnerability?

The former; the author's report (short of seeing what was intentionally left out for proper disclosure reason) is credible, and Paypal's failure to respond/remediate the issue is improper.

Getting access in this way to users' financial accounts is absolutely a vulnerability.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#216

Earlier quoted context omitted.

It is possible to escalate your dispute with a company to H1 itself. They'll review the report and the company's policy, and they may contact the triager or the company to try to resolve any questions. I wouldn't do that as a regular thing; you're pretty well guaranteed to piss off everyone on the company's side of things. I should note that I've personally seen probably in excess of $100,000 paid out through H1; the…

That sounds like it's a payout lottery. H1 can't force its customers to pay. It's acting as a go-between on behalf of its customer, the company offering the bounty, not as an neuteal arbiter when there is a dispute. Perhaps I would take them seriously if there was an escrow account companies paid into and was released to the reporting party when a plurality of multiple, disinterested parties agreed that the report wa…

HackerOne can force their customers to pay, that's the entire point of their "guaranteed bounty" program, that's it's a guaranteed bounty!

Even with a guaranteed bounty and a critical security vulnerability, HackerOne will punt the entire thing to one of their Portswigger groupies for collection and then won't disclose the details about the discovered flaw that supposedly they found prior to your submission.

Those guys are terrible, worthless product offering unless you are one of their clients getting free penetration testing and vulnerability analysis services.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#217

Earlier quoted context omitted.

It's not at all clear to me what you're saying here. Are you making a case that the whole report all put together is impactful? Or are you actually trying to argue that self-XSS is a critical security vulnerability?

The former; the author's report (short of seeing what was intentionally left out for proper disclosure reason) is credible, and Paypal's failure to respond/remediate the issue is improper. Getting access in this way to users' financial accounts is absolutely a vulnerability.

They are getting access to the accounts of people who do not have 2FA enabled and whose credentials have been stolen. Every bounty program I've ever paid attention to would close that report. Risk-based anti-ATO systems are heuristic.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#218

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

(remove message)

Sorry, on further thought while I still disagree with the analysis above as being overly dismissive, I think the OP may share some blame for not writing higher quality reports with POCs. Also, the OP doesn't explain whether or not they saw the original reports for those marked Duplicate. That's a very critical point. See here -

https://docs.hackerone.com/programs/duplicate-reports.html

For anyone actually interested here and not just drive by commenting (like me, ahem), it's worthwhile looking into the platform in more detail. See my post below -

https://news.ycombinator.com/item?id=22406372

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#219

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

out of curiosity, do you work at PayPal or is the first paragraph all assumptions?

One would have thought Wells Fargo had a talented team of people to catch their millions of fake accounts they made, but alas it went on for a decade. I will always assume companies have their backs turned to security, until proven otherwise, regardless of size or perceived risk.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#220
post #20

This doesn't surprise me. I'm currently trying to get a refund out of PayPal after what looks like a massive flaw in their refund process. I paid for something on eBay and it appears to have been a compromised account. The original auction, feedback history, etc, looked legit. The flow was this: 1) I pay for a product on eBay using PayPal, using my creditcard (direct from card, not from any existing PayPal balance).…

You put in way too much effort. Call your credit card company first. Your credit card company profits from vendor (PayPal) mistakes by charging fees, so they are always happy to help you.

calling the Card issuer is always my first stop. CS these days is abysmal at most companies.
Post reply on HN