Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

291–300 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#291

Earlier quoted context omitted.

It presumes a definition of "responsible" that suits the interests of vendors and treats the safety of end-users as an externality, in such a way that anyone operating in good faith and responding to different legitimate incentives is by definition "not" disclosing "responsibly". It's a linguistic ploy, and not one that should be dignified. In 2020, non-ironic use of the term "responsible disclosure" has become somew…

That sort of makes sense, but what are examples of other legitimate incentives that might compel a researcher to disclose the presence of a vulnerability before the vendor has a fix?

For instance, the vulnerability is being actively exploited already, or is trivial to find.

In reality, it's not incumbent on researchers to wait for patches at all. You can straightforwardly argue that you're obliged to give users enough of a head start to stop using the product if the risk is intolerable to them, and then disclose ready-or-not.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#292

Earlier quoted context omitted.

calling the Card issuer is always my first stop. CS these days is abysmal at most companies.

Unfortunately, any platform with any kind of lock in will have you over a barrel here. Try disputing a card transaction with Steam - your 18 y/o account with thousands of games and dollars invested will be gone in a flash. Same goes for Google/Amazon/Microsoft/etc.

yikes, ive never tried with any of those, but that would certainly suck. in my experience most platforms have a pretty fair compliant resolution policy though.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#293
post #279

Earlier quoted context omitted.

First, I do not work at Paypal, and have never worked at Paypal. Second, if I did, it would be none of your business. Third, comments like these are forbidden by the site guidelines, which demand that you not make accusations of astroturfing simply because you disagree with a comment.

I think there is a subtle but real difference between claiming astroturfing versus claiming conflict of interest.

exactly.

FWIW. I wasn't claiming either, I was questioning source of knowledge, as the claim seemed to be factually informed, but are in fact just the posters opinion on the matter.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#294

Earlier quoted context omitted.

out of curiosity, do you work at PayPal or is the first paragraph all assumptions? One would have thought Wells Fargo had a talented team of people to catch their millions of fake accounts they made, but alas it went on for a decade. I will always assume companies have their backs turned to security, until proven otherwise, regardless of size or perceived risk.

First, I do not work at Paypal, and have never worked at Paypal. Second, if I did, it would be none of your business. Third, comments like these are forbidden by the site guidelines, which demand that you not make accusations of astroturfing simply because you disagree with a comment.

i am not assuming anything nor making any accusations. I am simply inquiring as to the source of the claim made. i guess, we will establish that its just the opinion of the poster.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#295

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I submitted a vulnerability to a vendor on H1 along with a typical “I plan on publicly disclosing this vulnerability on X date” note, and started getting emails directly from H1 telling me that this undermined vendors’ confidence in the platform and that doing what I was doing might make it…

I 100% agree with this.

I reported to one program, which ignored the report and effectively stalled until the startup had pivoted to a different idea. HackerOne didn't remove them from the platform and did not make it possible for me to publish the report through their platform (and publishing it otherwise would have likely violated some ToS).

I reported a second issue to Cloudflare. It was acknowledged as a known issue within less than an hour, but still not fixed months later, and again I was unable to publish it.

Despite waiting for months and requesting disclosure repeatedly, none of these reports are disclosed yet.

In the future, if I find a vulnerability and the only reporting path the company provides is HackerOne, I will apply full disclosure instead.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#296

People have a weird mental model of how big-company bug bounty programs work. Paypal --- a big company for sure, with a large and talented application security team --- is not interested in stiffing researchers out of bounties. They have literally no incentive to do so. In fact: the people tasked with running the bounty probably have the opposite incentive: the program looks better when it is paying out bounties for…

> I'm inclined not to believe their claim that Paypal acted abusively here (and I am not a fan of Paypal). I agree that they have some issues with the way they've reported it, and I agree with your numbered points except that they imply that #5 may make the support agent vulnerable, but I'm not sure you can say PayPal haven't acted abusively. Many of the reports are legitimate vulnerabilities even if they aren't crit…

The page I failed to edit in: https://hackerone.com/paypal

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#297
If anyone in this thread is interested in talking about their experiences with HackerOne, please shoot me an email at david.morris@fortune.com.

Positive or negative. We can set up a time to talk, or if you're more comfortable, just include details in your email.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#298
post #84

Earlier quoted context omitted.

Upvoted, but not sure it's a tragedy. Much like that quote about democracy, it's a bad system, except the others are worse. Would be nice to have something better tho.

> the others are worse I think we need more experimentation with solutions to the (open-source) public goods problem before we can say that the others are worse. Ditto with experimentation on variants of democracy. Significantly harder to experiment with that than with open source funding though.

I would think experimenting with variants of democracy would be a more frequent event. Consider the small scale class president or family voting for a movie.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#299

Earlier quoted context omitted.

Authorization is not authentication, by definition. Furthermore, your link is talking about an entirely unrelated meaning of ATO. I believe tptacek meant it to stand for "account take-over".

You're right; that's what ATO means here.

Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#300

Earlier quoted context omitted.

But why does that system exist at all, if it's not supposed to do something ? It's not "impossible to use stolen credentials", it's "you have to clear this barrier to use stolen credentials". If that barrier is broken, that sounds like a flaw in the security model.

It's analogous to the systems that make your password show up as dots when you type it in. The security model isn't affected at all - dedicated attackers can "break the barrier" by just looking at your keyboard instead - but it significantly mitigates harm by making certain low-effort attacks harder to perform.

A not-for-sure harm mitigation as part of defense in depth is a great thing to put in a security model.

But with the flaw here, the effectiveness drops to zero. The "making certain attacks harder to perform" is basically gone in the scenario where someone is buying a bunch of credentials. That's not good!

Post reply on HN