Live data from Hacker News

I found Prezi's source code

blog.shubh.am

91–100 of 266 posts

Re: I found Prezi's source code

#91
The rules seem to allow a reward for this kind of vulnerability,

What’s up with other vulnerabilities? ... we will consider if they are eligible for a bounty or not

What is the bounty? ... we will increase it at our discretion for distinctly creative or severe bugs

Prezi explicitly designed the rules to be flexible, so they could give the award in this case, but decided not to because "intra.prezi.com is out of scope".

The rules about scope appear to exclude vulnerabilities in 3rd-party services such as AWS, not backends, e.g., the backends for our iPad and desktop applications are in scope

http://prezi.com/bugbounty/

Re: I found Prezi's source code

#92
post #73

My problem here is that the OP did not mask the names. Actually he did quite the opposite: he bolded them. This is no good. I can imagine the dev searching for his name in google and finding that post.

Hi, I'm the author of the blog post. I've masked last names from the post and PDF, hopefully meaning that they wont be indexed with that post. Thanks for bringing that to my attention.

Re: I found Prezi's source code

#94
post #61

Earlier quoted context omitted.

Prezi the company is in Hungary, not the US, and intra.prezi.com (70.38.38.86) seems to be in Montreal, Canada.

And the dude in question is in Australia. None of this happened in the United States at all - it's amazing! Non-Americans also have businesses!

Not very good ones, apparently.

Re: I found Prezi's source code

#96
post #40

Earlier quoted context omitted.

So because it was out of scope it means that it could not have harmed the company so he should have just left it there?

You're not entitled to a bounty just because you found a bug. Some companies offer these bounties and it's good that they do, but that doesn't mean every company is obliged to offer them, or that a company that offers bounties for some bugs is obliged to offer them for all bugs.

For sure, he's also not obligated to not sell this information to the highest bidder.

Re: I found Prezi's source code

#97

Earlier quoted context omitted.

How about a moral obligation? Honestly, it sounds like if a taxi driver returns a bag full of cash to the owner, it is perfectlly alright if they just say "Thank you" and walk him to the road. Legally: nothing wrong, morally: being a greedy asshole.

That's a false analogy. Taxi drivers are obligated to return lost property, but nobody is obligated to report bugs. That's why you create an incentive to report, i.e., the bug bounty. "Taxi drivers and owners must return property they find in a taxicab." - http://www.nyc.gov/html/tlc/html/passenger/sub_lost_prop_inq...

Aye! Its not a perfect analogy but I was pointing out why people should reward the guy if he didn't exploit the situation in a wrong way. In this case, it was the whole source available to him. Albeit, he was more or less inclined to report the bug but what if he hadn't and probably sold it somewhere? why shouldn't the company reward for his effort.

Re: I found Prezi's source code

#98
post #82

Earlier quoted context omitted.

How about a moral obligation? Honestly, it sounds like if a taxi driver returns a bag full of cash to the owner, it is perfectlly alright if they just say "Thank you" and walk him to the road. Legally: nothing wrong, morally: being a greedy asshole.

That's an interesting point of view. I consider it being a greedy asshole when you feel entitled to a reward for doing the right thing.

Clearly, you are being sarcastic!

If not, I am amazed by your naïveté.

Re: I found Prezi's source code

#99
post #71
post #37

Earlier quoted context omitted.

I doubt it could have been called 'stealing' if he only accessed what was posted publicly by the authors themselves at the time. Until he contacted Prezi, how could he be certain beyond any doubt that they weren't already aware of it? Could you explain that to me?

Using login in credentials that are not your own found in a public place to take source code is like finding someones house key on a park bench and coping their secret invention designs or trade secrets.

As I read it, he didn't use the credentials to take the source code; he found the credentials in the source code. He used the credentials merely to verify the credentials were valid.

Re: I found Prezi's source code

#100
post #82

Earlier quoted context omitted.

How about a moral obligation? Honestly, it sounds like if a taxi driver returns a bag full of cash to the owner, it is perfectlly alright if they just say "Thank you" and walk him to the road. Legally: nothing wrong, morally: being a greedy asshole.

That's an interesting point of view. I consider it being a greedy asshole when you feel entitled to a reward for doing the right thing.

It should absolutely be in the interest of companies to reward security researchers who find flaws in their systems. Otherwise, they will be screwed by the less scrupulous.
Post reply on HN