A little note about Slack’s Bug Bounty program
41–50 of 52 posts
Re: A little note about Slack’s Bug Bounty program
#42Notes on “a little note”. Hi, this is Ryan. I work at Slack. Bug bounties are great, but managing them can be a challenge. Like many companies that run a popular bounty program, we receive quite a few vague reports, invalid reports, and reports generated by automated scanners. We work through these daily to ensure we are focused on the bugs that can have an adverse impact on our users. We have positive interactions w…
First off, spare us the advertising. Nobody here cares.
--
this is not a vulnerability
Unfortunately, we then received this message from
Anshuman:
“I am giving you a heads up that I will be blogging about
this sometime today. Thanks for your time.”
So he reported a bug. You think it's not a vulnerability. This means to any reasonable human that you're literally giving him free reign to talk about it in whatever forum he prefers, including his blog, since there is no vulnerability and as such no danger to you or any of your users. Further, if you feel he misrepresented, he let you know he'd blogged so you were in a position to present your disagreeing position there.This leaves us with one question, which you didn't even bother to try and address: Why is his doing that "unfortunately"?
Now, you've admitted that all of the blame for the fallout of the second bug report falls in your hands because you failed to communicate in a reasonable timeframe.
The HackerOne FAQ does state: "No. It is unacceptable to share the vulnerability with anyone without the explicit consent of the Response Team."
However this following sentence from you remains due to the facts of the matter, and your own admission, simply wrong:
You have twice gone against the spirit of a bug bounty
program by disclosing things without consent.
The first disclosure may have been of a bug of some kind, but not of a vulnerability (as determined by yourself) and is as such not covered by the FAQ.In the second case, as per your own admission, you failed to honor the implicit contract of the situation, which unbound him further from the rules.
So you'll be hard pressed to argue in any way that your claim of him having gone against the spirit of the bug bounty program twice is correct.
This leaves the issue of his banning from your program, which is doubly by your admission, based on wrong claims.
--
I will not speculate on your real intentions here, but i will let you know that everything you have done looks like you have ulterior motives. The post you made, while wordy, utterly fails as an excuse or even apology, the last of which you are due for.
Now have your upvote so people can see what kind of behavior they can expect from Slack.
Re: A little note about Slack’s Bug Bounty program
#43Notes on “a little note”. Hi, this is Ryan. I work at Slack. Bug bounties are great, but managing them can be a challenge. Like many companies that run a popular bounty program, we receive quite a few vague reports, invalid reports, and reports generated by automated scanners. We work through these daily to ensure we are focused on the bugs that can have an adverse impact on our users. We have positive interactions w…
If you accept that Anshuman should have been updated on the 2nd bug and it was only after multiple unanswered requests that he blogged about it (a completely reasonable reaction I'd say), why did you then (I'm guessing you're the same Rhuber as the one commenting on the 3rd bug) say that he had gone against the spirit of the site and had him removed from your bug bounty programme?
Re: A little note about Slack’s Bug Bounty program
#44Notes on “a little note”. Hi, this is Ryan. I work at Slack. Bug bounties are great, but managing them can be a challenge. Like many companies that run a popular bounty program, we receive quite a few vague reports, invalid reports, and reports generated by automated scanners. We work through these daily to ensure we are focused on the bugs that can have an adverse impact on our users. We have positive interactions w…
Good to see a response on this from someone at Slack. However I'm now somewhat confused. If you accept that Anshuman should have been updated on the 2nd bug and it was only after multiple unanswered requests that he blogged about it (a completely reasonable reaction I'd say), why did you then (I'm guessing you're the same Rhuber as the one commenting on the 3rd bug) say that he had gone against the spirit of the site…
1) https://hackerone.com/disclosure-guidelines states:
"If 180 days have elapsed with the Response Team being unable or unwilling to provide a disclosure timeline, the contents of the Bug Report may be publicly disclosed by the Researcher. We believe transparency is in the public's best interest in these extreme cases."
2) He set an arbitrary 90 day disclosure checkpoint.
3) We explicitly asked for more time in dealing with the bug.
4) We had an extremely negative experience with him during his first report. He was unnecessarily adversarial when we patiently explained that he had not found a vulnerability.
---------
Within the HackerOne interface, a "Duplicate" is actually listed as a Closed:Duplicate issue, and doesn't appear in the Open issues tab at all. Perhaps a method of attaching duplicates to the original and allowing communication between all involved is useful? ¯\_(ツ)_/¯
Re: A little note about Slack’s Bug Bounty program
#45Earlier quoted context omitted.
Good to see a response on this from someone at Slack. However I'm now somewhat confused. If you accept that Anshuman should have been updated on the 2nd bug and it was only after multiple unanswered requests that he blogged about it (a completely reasonable reaction I'd say), why did you then (I'm guessing you're the same Rhuber as the one commenting on the 3rd bug) say that he had gone against the spirit of the site…
There are a few reasons for my comment about going against the spirit: 1) https://hackerone.com/disclosure-guidelines states: "If 180 days have elapsed with the Response Team being unable or unwilling to provide a disclosure timeline, the contents of the Bug Report may be publicly disclosed by the Researcher. We believe transparency is in the public's best interest in these extreme cases." 2) He set an arbitrary 90 d…
Not sure I'd say 90 days is entirely arbitrary as some of the big boys (i.e. Google Zero) seem to have come to a conclusion that that's the appropriate delay between disclosure and fix (whether that's always reasonable is another matter).
I'd guess that the more time thing he may have felt didn't apply as he wasn't getting any more communications about the bug status...
And sounds like a good feature request for Hacker One on dupes, this won't, I'm sure, be the only instance where this kind of mis-communication happens!
Re: A little note about Slack’s Bug Bounty program
#46Keep their attitude toward security flaws and the disclosure today in mind when you consider what would happen if your entire company's private chatlogs suddenly became public. Same goes for Hipchat too. User accounts and passwords are easy to reset and fix. Credit cards are easy to reset and fix. Years of private company discussion showing up in the wild? You're unlikely to ever recover.
"Years of private company discussion showing up in the wild? You're unlikely to ever recover." I'd be angry but my company wouldn't be ruined. The worst thing I ever say in internal communications is to poke fun at a couple of our grumpier or more entitled users. I also probably curse slightly more than is entirely prudent. But, that'd be mildly amusing to have exposed, not ruinous. Perhaps if you're saying stuff tha…
I'd be worried about company strategy, vision, intellectual property, keys/passwords, system infrastructure or other details leaking which could hurt our competitive edge, lessen our valuation, or expose our user's PII.
Re: A little note about Slack’s Bug Bounty program
#47Earlier quoted context omitted.
Good to see a response on this from someone at Slack. However I'm now somewhat confused. If you accept that Anshuman should have been updated on the 2nd bug and it was only after multiple unanswered requests that he blogged about it (a completely reasonable reaction I'd say), why did you then (I'm guessing you're the same Rhuber as the one commenting on the 3rd bug) say that he had gone against the spirit of the site…
There are a few reasons for my comment about going against the spirit: 1) https://hackerone.com/disclosure-guidelines states: "If 180 days have elapsed with the Response Team being unable or unwilling to provide a disclosure timeline, the contents of the Bug Report may be publicly disclosed by the Researcher. We believe transparency is in the public's best interest in these extreme cases." 2) He set an arbitrary 90 d…
So, I report a bug that I think is a security vulnerability. You fail to even understand the report in the first place. You don't even try to watch the video PoC demonstrating it in action. In a nutshell, you handle it completely wrong in the first place.
Then, you come back and tell me it's not a security vulnerability because it's a hidden Feature or whatever the reason you have.
At this point, there is not much I can do but to present my justification as to why I think you are wrong. I present my opinion which I'm entitled to just like you are. And, I let you know that I will blog about it.
Do you really think I was being "unnecessarily adversarial" there? I rest my case.
With regards to the second issue being duplicate, I believe you guys must have already fixed it by now? If So, do you mind disclosing the original reported bug to bring some more light to the questions being asked whether it was really a duplicate or not. I understand you don't have to do that but it's just a suggestion. Feel free to ignore.
Re: A little note about Slack’s Bug Bounty program
#48Earlier quoted context omitted.
There are a few reasons for my comment about going against the spirit: 1) https://hackerone.com/disclosure-guidelines states: "If 180 days have elapsed with the Response Team being unable or unwilling to provide a disclosure timeline, the contents of the Bug Report may be publicly disclosed by the Researcher. We believe transparency is in the public's best interest in these extreme cases." 2) He set an arbitrary 90 d…
Good point about the Hacker One disclosure timeline, sounds like the reporter should have waited for that to elapse prior to disclosure. Not sure I'd say 90 days is entirely arbitrary as some of the big boys (i.e. Google Zero) seem to have come to a conclusion that that's the appropriate delay between disclosure and fix (whether that's always reasonable is another matter). I'd guess that the more time thing he may ha…
And it's not only me who has had such a terrible experience with their program. I know atleast 3 different researchers who have reached out to me to tell me that they have gone through the same experience. They prefer not to speak out. I did. Period.
Re: A little note about Slack’s Bug Bounty program
#49Earlier quoted context omitted.
On point 1, how do they even expect a researcher to know that some other researcher has found the exact same bug if it's not disclosed yet? This seems like a fake rule whose only possible effect is to suppress disclosure.
Exactly. Their word is as good as mine, right? This is the biggest problem I see in bug bounty programs. You are at the mercy of the program.
It doesn't let you know what others have discovered/reported, but it solves the "their word against my word" problem...
(Of course, if they're actively trying to minimise bug bounty payouts and are prepared to screw over people attempting "responsible disclosure" to do so, they've got a lot of motivation to _not_ implement this from their side. Doesn't stop researchers posting hashes when they make reports, then the rest of us being able to verify those hashes when the bug is publicly disclosd.)
Re: A little note about Slack’s Bug Bounty program
#50Notes on “a little note”. Hi, this is Ryan. I work at Slack. Bug bounties are great, but managing them can be a challenge. Like many companies that run a popular bounty program, we receive quite a few vague reports, invalid reports, and reports generated by automated scanners. We work through these daily to ensure we are focused on the bugs that can have an adverse impact on our users. We have positive interactions w…
Notes on “Notes on “a little note”.” First off, spare us the advertising. Nobody here cares. -- this is not a vulnerability Unfortunately, we then received this message from Anshuman: “I am giving you a heads up that I will be blogging about this sometime today. Thanks for your time.” So he reported a bug. You think it's not a vulnerability. This means to any reasonable human that you're literally giving him free rei…
This is hyperbole, unnecessarily accusatory, and counterproductive. Nothing above made it look like Ryan/Slack had ulterior motives. You disagree with how they interpreted things.