Earlier quoted context omitted.
Basically only in America, though. Elsewhere the situation where someone gets into a car wreck, goes to hospital and then gets told how broke they are now just doesn't exist. In much of the rest of the world, the health system sets and publishes the rates - and guarantees payment to service providers. The doctors perform the services, and then submit for renumeration directly to the health system. The patients, well,…
Side note, just fyi, because I used to make the exact same (tiny) mistake all the time. It's spelt remuneration rather than renumeration. I think it helps to think of the `muner` part as being derived from the same root word as money rather than `numer` as number (which had been my previous assumption I guess). You just inspired me to actually google my memory technique above, and it turns out the `mun` is from a lat…
Instagram's Million Dollar Bug (2015)
91–98 of 98 posts
Re: Instagram's Million Dollar Bug (2015)
#92Earlier quoted context omitted.
Most developing countries are moving to the US model - private hospitals in India, China and the Middle East, for instance. What baffles me is how expensive government hospitals too are in the US.
It's not about whether the hospitals are private or not, it's whether you know the price beforehand and can make an informed choice - the most basic thing about the free market.
I wasn't talking about hospitals going private - after all, there are private hospitals in Europe and the UK too. I was talking about poor price transparency in the US being adopted in all of those places by private players. I specifically called out government players in the US, since they engage in the same practice, while government hospitals in all of those countries do not.
Re: Instagram's Million Dollar Bug (2015)
#93God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.
I wouldn't really blame the guy if he decides to sell the next one on the darknet.
Re: Instagram's Million Dollar Bug (2015)
#94(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…
There is plenty of price competition for your bug disclosure: the Chinese, the Israelis, the Saudis, the Americans, OR directly to Apple. :-)
Re: Instagram's Million Dollar Bug (2015)
#95Earlier quoted context omitted.
Wouldn't you also need login info (prob including 2fa) to an Apple developer account?
If *.instagram.com keypair is the TLS certificate keypair, then they could MITM Instagram. They'd probably need to physically stalk some Instagram employees, but getting the TLS certificate key pair would be the difficult part. On a related note, what do MS Windows/OSX/Android/iOS/Linux do when they see a WiFi AP with an SSID (and maybe even MAC) they recognize, with a WPA2 key they know, operating without encryption…
Re: Instagram's Million Dollar Bug (2015)
#96Earlier quoted context omitted.
If *.instagram.com keypair is the TLS certificate keypair, then they could MITM Instagram. They'd probably need to physically stalk some Instagram employees, but getting the TLS certificate key pair would be the difficult part. On a related note, what do MS Windows/OSX/Android/iOS/Linux do when they see a WiFi AP with an SSID (and maybe even MAC) they recognize, with a WPA2 key they know, operating without encryption…
People do this with public WiFi - for example, set up at Starbucks with a duplicated SSID, wait for target to connect and route it through as if it were connected to the real Starbucks WiFi, all the while monitoring in the middle.
Re: Instagram's Million Dollar Bug (2015)
#97God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.
Technically he used the 1st bug to enter their systems and then escalate access through other security holes or bugs. That's not likely to be accepted by default by most companies. I would assume a default "do not escalate access" unless explicitly asked for.
On the other hand, software is built in layers. If there's an "inside" breach, i.e. I can get from an inner layer to a deeper layer, I would want to know about it.
Facebook were idiots to structure their policy this way.
Re: Instagram's Million Dollar Bug (2015)
#98Earlier quoted context omitted.
There is plenty of price competition for your bug disclosure: the Chinese, the Israelis, the Saudis, the Americans, OR directly to Apple. :-)
Yeah let me just call up Saudi intelligence real quick, what's the name in the yellow pages?