Here is my personal take on this: I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts. There are couple of things I want to point out to the author here: 1) You said that if these were Duplicate reports, they have to have a report…
For 3) what are you not sure about? He demonstrated arbitrary DOM manipulation, and it reads like the XSS worked with some WAF avoidance. Brass tacks do you agree they should have paid out something for this?
I Got Paid $0 from the Uber Security Bug Bounty
91–100 of 168 posts
Re: I Got Paid $0 from the Uber Security Bug Bounty
#92Earlier quoted context omitted.
How does being rude with personal attacks help your case at all? (On a purely emotional level, it even makes me want to side with Uber for this) > Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ ( https://hackerone.com/reports/293359#activity-2203160 ) > Cute. Big surprise. ( https://hac…
not to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.
I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#93Re: I Got Paid $0 from the Uber Security Bug Bounty
#94Re: I Got Paid $0 from the Uber Security Bug Bounty
#95Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…
it doesn't make sense for Uber to a) publish a list of current unpatched security vulnerabilities Hackerone could require them to publish a list of hashes of unambiguous descriptions of known bugs. That way they could prove beyond doubt which issues were already known - much like astronomers published anagrams to prove their discoveries' priority in the 1500s. It wouldn't solve the problem of people wasting their tim…
Re: I Got Paid $0 from the Uber Security Bug Bounty
#96Okay, so for the first 4 bug reports, I'm on Uber's side. In their Hackerone program details it says that one of the valid close states of a report is [1]: > duplicate -- a vulnerability that has previously been found either internally or via Hackerone As much as it sucks to find a bunch of vulnerabilities and not get them paid out, it doesn't make sense for Uber to a) publish a list of current unpatched security vul…
Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submitter): https://hackerone.com/reports/293358
> This limitation is already known to us and as such we'll be closing this duplicate per our program guidelines.
to which he replies:
> Cute. Big surprise.
They should link to a submission if one exists, but it's possible and reasonable they already had an internal ticket.
The second issue, not revoking tokens on the server side after logout, the Uber rep replied:
> Thanks for the report, but after looking into it, this is a known limitation of our legacy authentication system and we're actively working on a new system that will replace these long-lived tokens with a more mature bearer token. Currently, the value associated with the x-uber-token HTTP header is a token that is only changed upon password reset.
The submitter added a long list of CWE items for OAuth, one of which was relevant (CWE-613: Insufficient Session Expiration). The Uber rep replied:
> Closing it Informative is not a judgement on the validity of the report -- it simply indicates we already knew about this and are actively addressing it already.
Seems reasonable that Uber's team knows their tokens don't expire and that it's not a good practice.
The rate limiting on the promo code endpoint report is the worst. It looks like Uber actually forwarded this one on to an internal expert, who replied with:
> we would consider the lack of multi-factor authentication a best practices concern, out of scope for our bug bounty program. Additionally, Uber tokens (UUIDs) are made up of 128-bit highly entropic values, making them very difficult to guess or brute force. We’ll be closing this report Informative, as this does not pose a security risk in itself. We wish you the best of luck on your next report!
Which is completely fair (you'd have to try ~10^29 values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second). The submitter argued their PRNG might be broken but provided no evidence that was the case. The submitter then posted some very hateful personal attacks against the people responding, including:
> Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ
I can understand feeling less than obligated to give a payout on these.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#97Earlier quoted context omitted.
Clearly doesn't help his case, but it's not really material to whether they should pay out or not. Why didn't they disclose the one that most everyone here agrees was an obviously-qualified-for-payout vulnerability?
It looks like a "reap what you sow" situation. No one is looking good now.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#98Their bug bounty is definitely fishy. If you pull their reports for the last few months, every single one of them at HackerOne have been redacted/locked with no information published. According to HackerOne their vulnerability reports become public after 30 days, but they've given Uber the ability to lock them which keeps everything private.
Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works: 1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure…
Welcome to Hacker News, I see it’s your first time visiting.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#99Earlier quoted context omitted.
Not all drug addicts commit crimes. There is certainly a place in society for people who fill their void(s) by using drugs. You do need to be careful though, not all addicts are crimeless.
This is a really important thing - I look at addiction largely as a societal neutral, the societal harm is often more from the legal issues surrounding addiction, than the actual addiction itself. Before the laws changed in the early 20th century, prescribing maintenance doses of opioids for example, was considered normal and accepted practice.
Firstly, what is societal neutral? Is it where a person is able to indulge in their vices without affecting others, or causing cost to the community? Because if so, drug addiction (of prescription, or legal drugs - alcohol and tobacco - and illegal drugs) fails the test.
Speaking as someone working on the front lines (emergency departments) of societies care for vulnerable people, addiction is an enormous scourge that causes immense harm - particularly with ice which is highly destructive to the individual, their families and the social fabrics of communities.
Re: I Got Paid $0 from the Uber Security Bug Bounty
#100Earlier quoted context omitted.
not to mention linking someone's social profile in a blog post about a company: > So these tickets get assigned to Rob Fletcher with Uber’s security team. Unfortunately, at least for me, this comes off as public shaming.
Are you familiar with the freelancers' concept of "fuck you, pay me"? I guess, that's how the first part works. There are things you can try, and there are other things. Messing with freelance pen testers is clearly one of latter.