Live data from Hacker News

Instagram's Million Dollar Bug

exfiltrated.com

321–330 of 562 posts

Re: Instagram's Million Dollar Bug

#321
post #287

Earlier quoted context omitted.

How is this unprofessional behaviour ? They are trying to condone the behaviour of data access which in all honesty falls on borderline unethical behaviour. Any professional who participates in any company's bug bounty should respect their rights as well. Whether the keys were accessible and it is a technical blunder is secondary but the action the researcher took a) accessing the data he did not need to b) making th…

I am not saying that the sec researcher is right here. I don't care about him, he is just some random guy who wants publicity. Talking about FB is more interesting because it is a huge public corporation which should behave smartly. But if you want talk ethical/not ethical -- he found a serious problem in their infrastructure. Had he not looked at the data ("respected their privacy") he wouldn't have found it. You ca…

[deleted]

Re: Instagram's Million Dollar Bug

#325

Earlier quoted context omitted.

Thanks for the response, but why did you start by contacting the CEO of Synack instead of the researcher directly?

> At this point, it was reasonable to believe that Wes was operating on behalf of Synack. His account on our portal mentions Synack as his affiliation, he has interacted with us using a synack.com email address, and he has written blog posts that are used by Synack for marketing purposes. I feel like that bullet point answers your question pretty well.

Without defending the researcher here, I thought that was the weakest point in Facebook's response. Was he interacting with Facebook using his synack.com email address during this exchange rather than at some point in the past? Was he signed up on Facebook with his synack.com address? (I haven't used the bug bounty program but it appears to require a user account.) Did he mention his employment with Synack in the course of the exchange? If any of those things were true, I suspect they'd say so, rather than leaving it at "has interacted..."

I don't know, if the guy was just shaking them down then maybe trying to get him fired is indeed a reasonable thing to do, but I don't buy that anyone would have just assumed under the circumstances that he was doing all of this on the clock.

Re: Instagram's Million Dollar Bug

#326
post #283

Earlier quoted context omitted.

Please don't do this here.

Can you please define "this"?

It was uncivil and unsubstantive. If you want to comment here you need to do a lot better than that, which I'm sure you can:

https://news.ycombinator.com/newsguidelines.html

https://news.ycombinator.com/newswelcome.html

We've detached this subthread from https://news.ycombinator.com/item?id=10755067 and marked it off-topic.

Re: Instagram's Million Dollar Bug

#328
post #90
post #72

Earlier quoted context omitted.

Thanks for the writeup. Based on what you've written, it sounds like you would have been surprised if Facebook had paid $1 million for the original report (and no further nefarious behavior by OP) since it was probably due to a simple oversight, even though it was a RCE that obviously could have been turned into total ownage of instagram. Is that accurate? If so, what class of vulnerability would make you say "Yep th…

There isn't a parallel universe in which this finding is worth $1,000,000. It it was, every pentester in the country is getting way underpaid, because this is not an uncommon pentest finding.

What about the parallel universe in which bug bounty hunters are blackhats who directly profit from the exploit? It seems like someone with that level of access could run up, among other things, a decent AWS bill.

Re: Instagram's Million Dollar Bug

#329

Earlier quoted context omitted.

Surely they would have to revoke all the keys anyway as they would have no idea if a blackhat got their first and took the keys before the vulnerability was reported?

According to the timeline, Instagram have known about the ssl keys since 1 Dec. My browser is currently showing an ssl cert for instagram.com that was issued in April and expires on Dec 31. Doesn't look like they're in any hurry to revoke that one. (I guess like Alex Stamos told his employer - it's "trivial and of little value"...)

Or, like almost any company that's reasonably competent, they have multiple certificates with different private keys.

Re: Instagram's Million Dollar Bug

#330

Earlier quoted context omitted.

According to the timeline, Instagram have known about the ssl keys since 1 Dec. My browser is currently showing an ssl cert for instagram.com that was issued in April and expires on Dec 31. Doesn't look like they're in any hurry to revoke that one. (I guess like Alex Stamos told his employer - it's "trivial and of little value"...)

Or, like almost any company that's reasonably competent, they have multiple certificates with different private keys.

And they just happen to only leave some of them in their S3 buckets?

Seems … contradictory.

Post reply on HN