Live data from Hacker News

How to send DMs on Twitter without permission

homakov.blogspot.com

51–60 of 60 posts

Re: How to send DMs on Twitter without permission

#51
post #19
post #16

Earlier quoted context omitted.

> Companies without bug bounties don't deserve responsible disclosure? That seems to be homakov's view, yes, and I can't say I don't understand his view.

Of course you understand it, but do you agree with it? If you seek out bugs in a company's code with the expectation that you'll be rewarded for it, and then the company fails to reward you, I can see that it might be perceived as unfair, especially if the company indicated that such an expectation was reasonable. If you happen across a bug in a company's code, and then publicize it because they aren't going to pay y…

Another way to look at it is that if there are no bounties, then the company may not have security issues high on its priorities list.

I'm not saying it's true, but it's plausible that some people in Egor's position think that way. And he seems to like his publicity, so 1+1 = 2.

Re: How to send DMs on Twitter without permission

#52

Not sure how many hours go into finding these sorts of vulnerabilities, but his rate of $150/hour[1] seems like a steal compared to the lost revenues he can prevent. [1] http://www.sakurity.com/

On the flip side, Homakov personally has incredibly bad OPSEC practices which would make me think twice for using him. There's a correlation between what you pay and what you might get.

Re: How to send DMs on Twitter without permission

#54
post #4

the 'd' syntax for sending DMs has been around from nearly the beginning (or from the actual beginning?) of Twitter. That in itself is not a bug. However, Twitter should be stripping that leading 'd' from anything that is reposting or from a 3rd party OAauth session.

It's not a bug per se, but it's certainly a hideous misfeature to have ever had that kind of input parsing except on the SMS interface to Twitter. It's just completely unnecessary.

This isn't the first bug to be found because of it!

Re: How to send DMs on Twitter without permission

#55
post #12

> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters". Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think th…

> Companies without bug bounties don't deserve responsible disclosure?

The term "responsible disclosure" implies that other types are "irresponsible disclosure".

If you discover new information through research, there is nothing irresponsible about publishing it on the open web.

Stop this stupid linguistic battle.

Re: How to send DMs on Twitter without permission

#56
post #33

Earlier quoted context omitted.

Well given that homakov has found this bug, there are a few possibilities: A. Homakov could do nothing. This leaves Twitter in the same state that it is now, but it if everybody did this, it is likely that nefarious people would find and exploit bugs in Twitter B. Homakov could donate his time, as a skilled and highly-trained professional consultant, to a $32bn publicly-traded company C. Homakov could practice full d…

> This isn't even close to blackmail. This is a security consultant publishing a vulnerability that he discovered on his own time, that apparently Twitter's internal security team missed. That might be embarrassing for Twitter, but that's hardly homakov's problem as a third party. Perhaps "blackmail" was too harsh a word. A better analog might be discovering a business left their back door unlocked. Do you announce i…

Do you become a little more recognized by your peers by publishing that the door is open to your neighborhood?

Are people going to get killed or lose a lot of cash by knowing how to send unsolicited private messages on twitter?

Like most analogies; it shows your bias rather than some enlightenment on the subject.

Re: How to send DMs on Twitter without permission

#57
post #12

> I wrote a full disclosure post 5 minutes after finding the bug because twitter doesn't reward "bounty hunters". Companies without bug bounties don't deserve responsible disclosure? Twitter has a pretty clear way to reach them, and recognition is given on their page. If recognition isn't sufficient for responsible disclosure, how much money would be enough? I think bug bounty programs are great, but I don't think th…

Why should companies expect disclosure at all?

The fact that the bug has been disclosed rather than exploited is, itself, a huge favour to Twitter.

Re: How to send DMs on Twitter without permission

#58

Not sure how many hours go into finding these sorts of vulnerabilities, but his rate of $150/hour[1] seems like a steal compared to the lost revenues he can prevent. [1] http://www.sakurity.com/

On the flip side, Homakov personally has incredibly bad OPSEC practices which would make me think twice for using him. There's a correlation between what you pay and what you might get.

What do you even mean to have "incredibly bad OPSEC practices"? Without an explanation, your comment comes across as more unnecessary snark, which unfortunately isn't uncommon in threads that remark upon Homakov, or on HN in general.

Re: How to send DMs on Twitter without permission

#59

Earlier quoted context omitted.

On the flip side, Homakov personally has incredibly bad OPSEC practices which would make me think twice for using him. There's a correlation between what you pay and what you might get.

What do you even mean to have "incredibly bad OPSEC practices"? Without an explanation, your comment comes across as more unnecessary snark, which unfortunately isn't uncommon in threads that remark upon Homakov, or on HN in general.

https://twitter.com/homakov/status/387805705669206016 https://twitter.com/homakov/status/345544666483130368 https://twitter.com/homakov/status/218630370231451648

Re: How to send DMs on Twitter without permission

#60

Earlier quoted context omitted.

What do you even mean to have "incredibly bad OPSEC practices"? Without an explanation, your comment comes across as more unnecessary snark, which unfortunately isn't uncommon in threads that remark upon Homakov, or on HN in general.

https://twitter.com/homakov/status/387805705669206016 https://twitter.com/homakov/status/345544666483130368 https://twitter.com/homakov/status/218630370231451648

I am not trying to hide my real name. If you need my ID just ask.
Post reply on HN