Earlier quoted context omitted.
That article claims to have “0 comments”, but currently sits at a score of -7 (negative 7) votes of helpful/not helpful. I think they have turned off comments on that article, but aren’t willing to admit it. EDIT: It’s -11 (negative 11) now. Still “0 comments”.
They have definitely turned off comments. Attempting to post one refreshes the page but nothing happens, and the comment never appears.
1 bug, $50k in bounties, a Zendesk backdoor
401–410 of 437 posts
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#402Earlier quoted context omitted.
“I will consider not disclosing if you compensate me for my time.”
You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#403Earlier quoted context omitted.
So when the researcher said it was a bug, they said, "No, it's fine. No bug bounty, sorry." THEN the researcher eventually goes public. Later, Zendesk announces the bug and the fix and says there will be no bug bounty because the researcher went public. Is that how it went? I mean if so, that's one way to save on bug bounties.
We have 2 conflicting sides of the story, who knows which one is bullshiting.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#404Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#405I.e. you have domain support.example.com, CNAMEd to Zendesk, so you cannot add any other DNS record to it, but Zendesk should do it on their side. But they refuse, and force you to put CAA to your root domain example.com.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#406Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That is presumably the reason they failed to pay out. The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted i…
Isn't the simplest solution here to not support SSO at all? I get there's a convenience factor, but even more convenient is the password manager built into every modern browser and smartphone. If the client decides to use bad passwords, that's will hurt them whether or not they're using SSO.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#407Earlier quoted context omitted.
And it’s still out of scope for the HackerOne bug bounty program.
Got a -1 on this comment. Must mean that I’m wrong and that it’s become part of the scope now! Maybe someone wants to post a link?
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#408Earlier quoted context omitted.
I do web app testing and report a similar issue as a risk rather often to my clients. You can replace Google below with many other identity providers. Imagine Bob works at Example Inc. and has email address bob@example.com Bob can get a Google account with primary email address bob@example.com. He can legitimately pass verification. Bob then gets fired for fraud or sexual harassment or something else gross misconduct…
You don't need full blown workspace, which costs money, you can set up "cloud identity free" and claim the domain. When you're setting it up, you can choose what to do with any existing accounts that are part of your domain: kick them out or merge them in.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#409Earlier quoted context omitted.
That helps, but I still don't have a full picture. What's the threat here? Is it that: if a hacker gains temporary access to Bob's email bob@example.com, they can create an Apple account attached to it, and use that account to sign in with a service ABC, then that hacker gains access to Bob's private info in service ABC? But if the hacker already has email access, can't he just log into service ABC directly anyway? A…
> Also, is it impossible to have a Google account with a non-gmail address? You can have your own domain if it is a workspace account
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#410Earlier quoted context omitted.
“I will consider not disclosing if you compensate me for my time.”
You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…