Live data from Hacker News

“We found PayPal vulnerabilities and PayPal punished us for it”

cybernews.com

331–337 of 337 posts

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#331
post #120

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

> HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Completely disagree with this. I launched a HackerOne program for my company last month (for free, not using their “managed” service). Of the many reports people submitted, we triaged 30-40 valid reports (most very minor, one or two moderate). We paid out a few thousand dollars in rewards. At the same time, we also did a more tradition…

Surprise, you don't need hacker one to get reports. sendbugshere@company.com solves the same issue without introducing a new trusted party.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#333

Earlier quoted context omitted.

I don't know what else to tell you. "Responsible Disclosure" was literally a coercive marketing strategy cooked up by vendors; it isn't a term we arrived at organically. Don't use that term. Use any other term you like, but the convention in the field is "coordinated disclosure".

To counter Orwellian term, consider “informed disclosure”? The vendor is informed before disclosure. The security researcher is an informed expert disclosing to end users. Good behavior vendors can further inform these researchers on challenges driving vendor need for alternative timing. On the timing dimension, consider “cadenced disclosure”? Less about consensus, more about the beats.

I'm really not interested in trying to coin new terms.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#334
We run a private bug bounty (not via H1 but another platform), classical pentests, dynamic code assessment and a responsible disclosure program.

Pentests are ok, they help to scrap plenty of bugs. I am not a great fan otherwise because it is based on a fixed rate.

Private bb ended up fantastic. Great bugs, great researchers, reasonably good pay (not Apple grade but we paid some 30k€ irrc). Feedback from researchers was good, including unexpected public praise.

Dynamic code reviews are a mixed bag. Usually crap, sometimes hidden gems.

Responsible disclosure is a mixed bag too. It is very binary : 20% great from great researchers we usually invite to the private bounty afterwards, and 80% garbage. Oh man, the garbage. Often I do not even understand the submission (not being a native English speaker either).

One other problem with public programs are legal implications to pay an anonymous reporter (imagine a US company paying someone affiliated with NC or Iran or Daesh, and that info published in the press)

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#335

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

HackerOne’s community team also seems trained to gaslight ethical reporters who try to follow responsible disclosure practices. I submitted a vulnerability to a vendor on H1 along with a typical “I plan on publicly disclosing this vulnerability on X date” note, and started getting emails directly from H1 telling me that this undermined vendors’ confidence in the platform and that doing what I was doing might make it…

Hi, if you’re at all interested in discussing this (including if you’d prefer your name not be disclosed) please email David.morris@fortune.com. Thanks.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#336

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

Hi, if you’re at all interested in discussing this (including if you’d prefer your name not be disclosed) please email David.morris@fortune.com. Thanks.

Re: “We found PayPal vulnerabilities and PayPal punished us for it”

#337
post #73

HackerOne appears to be completely broken and I wouldn't recommend it to anyone. Disagreements are to be expected on a bug bounty platform, but these days they just stop responding altogether and don't pay. It borders on outright fraud. I've been trying to report a Squid RCE (CVE-2020-8450) since October. The Squid maintainers seemed unprepared for dealing with the report as they kept being unresponsive and it took 2…

I worked as a contractor for a company that's a household name in the US. I am now convinced that HackerOne only exists for CISOs to say "look, I'm doing something" during the 2-3 years they stay at a company. The cybersecurity team had a backlog of roughly 30 critical issues discovered internally before starting HackerOne. We were unable to fix those issues, or the ones reported to us, because we had no visibility i…

Hi, if you’re at all interested in discussing this (including if you’d prefer your name not be disclosed) please email David.morris@fortune.com. Thanks.
Post reply on HN