Bug Bounty Ethics
facebook.com
facebook.com
Normally the thing we do with rapidly developing stories, i.e. when a new post adds significant information, is bury the previous thread and leave the new one up. But my sense is that people wouldn't prefer that in this case, and since the current post is already being discussed in (edit: at the top of) the other thread, we'll leave that one up instead.
The obvious solution is to support aggregating related URLs, and we will do that eventually, but there are other things that need to be done first (I don't just mean that have higher priority, but that are literal prerequisites). In the meantime, it's partial manual fixes for the lot of us.
I agree the researcher shouldn't have escalated/pivoted once they had access, that in itself breaks their ToS for the bug bounty program. However in doing so the vuln went from "so-so" to "holy shit".
Whether this policy for disabling pivoting is realistic/a bit of a cop-out from the vendor is arguable. In the real world an attacker wouldn't hesitate, however FB can't have people crawling around their internal network, potentially breaking or leaking user information.
The researcher, with all of his experience (incl a 24K bount payout from MS) should be aware of the above. However less ethically inclined hackers would have sold this access for $100K+.
EDIT: User ryanlol has made a good point, I thought they included fucking around within the server to break ToS. But their page does not indicate that. From the article it says:
> Intentional exfiltration of data is not authorized by our bug bounty program
However the ToS only talks about USER data. AWS S3 keys aren't included we can assume.
This is a tricky situation.
Except it doesn't?
Updated original reply.
Not interact with other accounts without the consent of their owners.
Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypair that did not belong to him, and he had no consent of the owner.
Edit: I feel that your edit is still stretching the terms a bit. It seems pretty clear that this isn't the abuse that the clause intends to prevent.
Also, the guy seems to only have verified that the credentials worked.
Or, he got in touch with the company he thought the researcher was affiliated with, to discuss what he felt was a very serious issue without involving lawyers. The classic outrage case is when a big company starts sending scary letters signed by lawyers, first thing. Maybe we should be less outraged when someone goes out of his way to be reasonable.
The best possible outcome there would have been a grumpy letter from lawyers asking him to sign an affidavit he's destroyed all the data he picked up. The worst would have been people in suits packing away his every computing device at 4 am. None of this happened and it seems the main reason it didn't is 'Alex Stamos is not a dick and Facebook lets him not be a dick'. That's a good outcome, by any measure.
The whole point is kinda moot, seeing how they did not have proper auditing and can't know if the keys were taken either way.
> We were surprised because he did not mention these actions in his previous correspondence with us.
Painting a picture/creating a narrative, poor us, we're surprised.
> it was reasonable to believe that Wes was operating on behalf of Synack
Filling in affiliations, or using a company address during parts of communication could very well have been out of detailing legitimacy as well as convenience. You can not, and should not infer a researcher operates on behalf of their company when reporting a bug, and as a CSO and someone who acts as a security researcher you KNOW that we always distance ourselves from our workplace when reporting or talking about security.
> Wes to set a precedent that anybody can exfiltrate unnecessary amounts of data
Logging in, grabbing keys but not touching user data is most certainly not breaking your ToS. Yet you paint it as unethical here. Where do you draw the line? Internal network names? Internal IP's, passwd files?
> one of my engineers involved in this issue once found a great (and in his case, original) RCE
Really, "and in his case, original"? Come on, act professional you're presenting one of the largest companies in the world.
> we have no evidence that Wes or anybody else accessed any user data
DING! DING! DING! Yet using terms like "intentional exfiltration of data" to draw grey areas that convenience you.
They've definitely screwed the pooch on this one.
This is pretty questionable, and seems more like a hastily made up excuse. If Alex wasn't acting with malicious intent then the logical approach would've been to ask the researcher if he's operating on behalf of synack.
This guy was definitely acting in bad faith when he called the guy's boss and not the guy himself first.
> His account on our portal mentions Synack as his affiliation
Note 'his account' here is just his Facebook account. So you can rewrite that line as 'his Facebook account lists him as employed at Synack'
> he has interacted with us using a synack.com email address
That would be a crazy new precedent if we use email addresses as authority
> and he has written blog posts that are used by Synack for marketing purposes.
having written blog posts is even crazier.
Were Alex genuine in thinking this was Synack he would have copied Wes on the email and/or he would have asked him. He straight up went behind his back and over his head.
Facebook had a bounty program that was very respected and operated well. I don't understand how they've completely fucked this up and turned it into a pissing contest.
Just say sorry, forgive the guy for the data download, clarify that it was against the rules anyway, give the guy $20k, apologize for contacting his employer and just get it over with.
This way it is just going to drag on for days now and everybody has already forgotten that it was the reporter who made the first mistake.
I really, really don't get this.
edit: tip to researchers - create a new alias for each bug you report. once the bug is all done and settled claim it under your real/public name. avoid blowback, everyone gets it at least once.
Wait, how does that work? Are there negotiations involved in Bug Bounties? But there's no leverage once the bug has been exposed!
The bug lead to full access to critical data, and possibly to full control of their servers. It's interesting what these other "more critical" bugs were.
"Not very original" != "not critical". Alex seems to imply these are equivalent.
Someone needs to call Zuckerberg to let him know about the aggressive and unethical behavior of his employee.