Live data from Hacker News

Remote Code Execution in Slack desktop apps

hackerone.com

91–100 of 201 posts

Re: Remote Code Execution in Slack desktop apps

#91
post #87

Earlier quoted context omitted.

> However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers. Shouldn't people like you be able to do this for a living if you want to? It's valuable work. It has real market value. It seems like you're doing this for fun and genuine interest and I do admire…

Yes they should and I think I could. This exploit was more of a fun challenge. I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethic…

How much time did you spend on this?

Would you have done without excepting any rewards, i.e. just for fun?

Re: Remote Code Execution in Slack desktop apps

#92

Earlier quoted context omitted.

So, what is the right thing to do if you find a vulnerability in Slack?

This might be unpopular, but if you don't feel like the compensation adequately reflects your effort, then you're free to do whatever you think is fair. It's your work. Slack isn't entitled to that work. Ideally, you'd check beforehand what a bug bounty program usually pays out and then decide whether to work on some other company's product that pays better. But you're always going to have people who are interested i…

> Slack isn't entitled to that work.

Sure, but that isn’t the user’s fault, and they’re the ones who are going to get attacked. I don’t disagree with your other points but I don’t think selling an exploit on the black market is the right solution.

Perhaps the best compromise, as I think about it, is to just make the exploit public with no prior warning to the vendor. That’s not great for users either, but at least they’re informed, and the vendor will be left scrambling. But in that case, the researcher gets paid nothing at all.

Re: Remote Code Execution in Slack desktop apps

#93

Earlier quoted context omitted.

So, what is the right thing to do if you find a vulnerability in Slack?

This might be unpopular, but if you don't feel like the compensation adequately reflects your effort, then you're free to do whatever you think is fair. It's your work. Slack isn't entitled to that work. Ideally, you'd check beforehand what a bug bounty program usually pays out and then decide whether to work on some other company's product that pays better. But you're always going to have people who are interested i…

> whatever you think is fair

Please give us some examples of what you would consider fair in this situation.

Re: Remote Code Execution in Slack desktop apps

#94
post #79
post #73

Earlier quoted context omitted.

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

> If you haven't had food for a few days everything is indeed about money I doubt anybody capable of finding an exploit like this is in that situation

I suggest you try and peek outside your bubble then. Software Engineering isn't free money everywhere.

Re: Remote Code Execution in Slack desktop apps

#95
post #78
post #45

Earlier quoted context omitted.

I haven't said anything about black markets but: >You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money Not me, not you, but many people make it all about money. I don't think it's ridiculous to think that people can have absolutely zero ethics.

I haven't done any security research for decade, but it was my hobby long ago. While it's not true in every case sometimes finding worthy bug and then successfully exploiting it can literally take weeks of work. Like 14 hours a day work with break for sleep in attempt to solve some puzzle. Usually without any payoff. This is profession where your actual skills mean very little until you do something exceptional to ha…

I don't live in a 'western country' nor do I make anything near a Silicon Valley salary

Re: Remote Code Execution in Slack desktop apps

#96
post #16

So Slack offers the guy a paltry $1,750, then attempts to take credit for his work while also screwing him out of his own disclosure. This kind of response to security researchers just invites the next researcher to sell the exploit instead, or to actively exploit it. Why does Slack seem like a company that is floundering? It took them over two years to release a simple feature like shared channels. It seems like the…

> A simple feature like shared channels

You think merging two or more organizations workspaces in a sane and secure manner after likely basing the entire app infrastructure around the idea of a single workspace is a "simple feature"? This is a textbook example of the classic HN comment "Why does this this company need X engineers to create Y product. I could do it in a weekend."

Re: Remote Code Execution in Slack desktop apps

#97

Earlier quoted context omitted.

Unfortunately, we live in a world governed by money as a motivator. While you might not be in it for the money, many people are, to a certain degree (you know, to make a living and to be able to afford a decent life). If companies are unwilling to pay anything remotely close to what researchers' time is worth, then they shouldn't wonder when people prefer to sell the exploits that they find to those who do value thei…

So, what is the right thing to do if you find a vulnerability in Slack?

There are western vulnerability brokers that sell advance warning of exploits to clients like large corporations and governments so they can protect themselves, then presumably handle notifying the company in question so the bug can get fixed. Of course, one problem is that their clients are free to abuse the exploits, and another problem is there's no guarantee they'll make sure the exploits get fixed... but that's certainly an option for you if you aren't comfortable using HackerOne.

Another option is to just disclose it to the public a set number of days after notifying them, like Project Zero.

Re: Remote Code Execution in Slack desktop apps

#98

Earlier quoted context omitted.

Most software is made entirely free with no source of income. The job market for software is terrible, and those people work entirely seperate jobs from it. Many program on a very minimum life expenditure.

https://levels.fyi disagrees. I can confirm the offers on there are real

You replied to a claim about “most software” with a site that compares big tech companies, and only their US offices. The world is much bigger than your bubble.

Re: Remote Code Execution in Slack desktop apps

#99
post #87

Earlier quoted context omitted.

Yes they should and I think I could. This exploit was more of a fun challenge. I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethic…

How much time did you spend on this? Would you have done without excepting any rewards, i.e. just for fun?

Context matters. In this case it was a challenge because of previous research and I would've done it just for fun and the experience. I'm lucky I can afford to do that. Doesn't mean I don't value compensation.

In other cases maybe yes, maybe no - for some nonprofit, maybe someone needs help? are they a business and can they afford to compensate this kind of work? maybe it is some prominent product? there is no simple answer

Re: Remote Code Execution in Slack desktop apps

#100
post #73
post #39

I wrote that exploit & report. Just some thoughts on comments here. Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming. I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces?…

> You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money If you haven't had food for a few days everything is indeed about money. Either you reward someone properly for the work that they can do or they'll find someone else who does. I doubt most people get fuzzy warm feelings helping a big US corporation that's too greedy to actuall…

If you haven't had food in a few days, there are many better ways to get food on the table than trying to find exploitable vulnerabilities and sell them for tens of thousands of dollars, including

- Work on a bounty program that rewards mitigations instead of exploits (e.g., https://www.google.com/about/appsecurity/patch-rewards/). Those are much more deterministic. (But there's no black market for them.)

- Get a conventional job (possibly in software, possibly not), which pays you on a schedule.

I get the argument you're making about money, but I'm having trouble believing that going after bug bounties ever makes sense to someone in that situation, given how non-deterministic it is to find a bug.

Also (as this bug shows), it typically takes a long time between reporting a bug and having the responding team decide that it merits a bounty. In this case it took a month. (And then there's logistics about actually getting you the money at that point.) Are people who haven't eaten for a few days really going to be happy not eating for another month, even if they get a hundred thousand dollars then?

Post reply on HN