Live data from Hacker News

I Got Paid $0 from the Uber Security Bug Bounty

medium.com

81–90 of 168 posts

Re: I Got Paid $0 from the Uber Security Bug Bounty

#81
This seems like it will self correct. Get a reputation for not paying, and now you have skilled adversaries with a grudge to settle. Bug bounties aren't the only way to monetize this particular skill set. Or maybe getting paid becomes less important than getting even.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#82

Earlier quoted context omitted.

Clearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?

It looks like a "reap what you sow" situation. No one is looking good now.

Irrelevant. If he found these bugs, even if he’s been a dick about it then he still found a bunch of vulnerabilities that Uber was exposed to. Pay the man, it’s a few thousand dollars as opposed to a major exploit!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#83

Earlier quoted context omitted.

^^^ What he said. How about "eBay for car rides"

It's not even eBay, since Uber sets the prices.

and tightly controls and rates customers and drivers. Think back to the 2014 downgrading of Uber drivers who worked for competing services.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#84

Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.

Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works:

1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure page with no valuable information for new hackers.

2) I haven't seen reports getting locked unless reporter goes "Can i haz update" every 2 days. Then in such cases, Locking a report is more than fair.

3) You might be confusing this with Limited Disclosure. That is allowed in both sense by companies and hackers. Most of my reports are limited disclosure because sometimes, I have to share personal details or personal information that I don't want other hackers to see.

I support transparency that is why, till this day, all of my resolved reports for public programs are publicly disclosed. Even in Uber's case, I have disclosed bug but they were limited disclosure because it had my personal information. But if you check, Uber has allowed me to write public blogs on my reports.

So please, learn about the platform and a program works before you make any form of assumption.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#85
post #22

I'm getting Uber fatigue. This company has been in the news mostly in a negative sense. It 's lost on me what innovation, technologically, or socially, they have brought to the table. Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders.

>Instead, perhaps we can focus on how we can fix this sharing economy, so that we can all benefit; not just the ones who happened to raise the most money from shareholders. I already benefit from it massively. Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where an…

Before my roommate got me into using Uber a few years ago, I was hesitant to travel to new cities or even go somewhere new or unusual in my own city because of being intimidated by having to figure out where and how to hail a taxi or having to figure out the bus routes.

I'm not familiar with he US, but taxis in most European countries have an app these days. Even >20 years ago you could just call their phone number and they would pick you up from (or drop you) anywhere, even in remote villages, even at 4am. Never had a problem. I find it hard to believe the same isn't true for the US.

Sure public transport isn't as flexible route/time wise but I don't see how Uber is different from regular taxi service - apart from the price.

Re: I Got Paid $0 from the Uber Security Bug Bounty

#86

Has anyone been paid for these sorts of bounties by Uber? (Short of the $100,000 extortion payout swept under the rug of bug bounties) It otherwise appears to be an attempt by Uber to get a bit of free crowdsourced pentest. I'm honestly curious about the HN community on Uber now: does anyone trust Uber on anything at this point? Do you still take any of their research, publications, whitepapers, etc., at face value?…

[deleted]

Re: I Got Paid $0 from the Uber Security Bug Bounty

#87

Earlier quoted context omitted.

Client side logout with seemingly no token expiration is a very serious vulnerability, especially for something like Uber where payments are involved.

I recall that either OAuth or SAML doesn't have capabilities for logout.

I believe it's OAuth (same with JWT) in that there is no endpoint one can POST to in order to "logout," but the end-of-authorization concept exists in both OAuth and JWT via token revocation on the server-side

SAML has an actual logout endpoint

Re: I Got Paid $0 from the Uber Security Bug Bounty

#88
post #48

Earlier quoted context omitted.

Yeah that's a big one, and an issue with the core of their entire authentication workflow that they cannot fix without invalidating tens of millions of apps or forcing everyone to upgrade. Whenever you sign off of their mobile app there is no communication with the network, they are just erasing the token on the client side.

Not the parent commenter and I get what you mean, but if they state that it's a duplicate issue (and assuming on good faith that it is), doesn't it make sense that they don't pay you out for that? I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.

Yeah, but we have no idea how long this has been unfixed. I reckon all security bugs not paid out to Uber at this point should just get automatically publicly documented.

Also: this is Uber. At this point, they’ve used up all their good faith. I definitely wouldn’t be taking anything they say in good faith - I still haven’t forgotten them threatening a journalist or publicly tracking the ride of a CEO for an entire room of people!

Re: I Got Paid $0 from the Uber Security Bug Bounty

#89

Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…

For 3) what are you not sure about? He demonstrated arbitrary DOM manipulation, and it reads like the XSS worked with some WAF avoidance. Brass tacks do you agree they should have paid out something for this?

Re: I Got Paid $0 from the Uber Security Bug Bounty

#90
post #18

Earlier quoted context omitted.

Are you basing this opinion on this one account? I would like to point out that Uber has a history of sleaze and would absolutely not use their behavior to judge any such programs. Are there other well described, similar instances of such poor behavior from legitimate companies? It seems to me that most of the bigger corps offering bug bounties may be paying too little but at least they follow their own rules.

Khaos Tian published a writeup a few days ago about how he discovered a wide-open HomeKit vulnerability [0]. He reported it properly months prior, but Apple ignored his followups and was unresponsive. After this extended radio silence, Tian reached out to a media contact. Within hours of being contacted by the website, Apple finally pushed a hotfix for the vulnerability. Apple subsequently denied Tian access to their…

Clearly a problematic exchange, but, nowhere is it said that this is a bug bounty program interaction nor is it an account of Apple denying promised payment for such a program.

I'm certainly not justifying a poor communication and response to the report, but, it seems like a very different kind of problem, and not one reflective of the kind of corporate sleaze often seen from Uber.

Post reply on HN