Honestly Uber's response to all of these seems pretty professional and reasonable. The submitter was hard to work with and seemed pretty eager to jump to conclusions about the Uber team's motivations. I haven't seen the details of the JavaScript XSS one but given the past behavior I'd understand some skepticism.
Their response to the Microsoft Store lack of cert-pinning seems fair (though disappointing for the submitter): https://hackerone.com/reports/293358
> This limitation is already known to us and as such we'll be closing this duplicate per our program guidelines.
to which he replies:
> Cute. Big surprise.
They should link to a submission if one exists, but it's possible and reasonable they already had an internal ticket.
The second issue, not revoking tokens on the server side after logout, the Uber rep replied:
> Thanks for the report, but after looking into it, this is a known limitation of our legacy authentication system and we're actively working on a new system that will replace these long-lived tokens with a more mature bearer token. Currently, the value associated with the x-uber-token HTTP header is a token that is only changed upon password reset.
The submitter added a long list of CWE items for OAuth, one of which was relevant (CWE-613: Insufficient Session Expiration). The Uber rep replied:
> Closing it Informative is not a judgement on the validity of the report -- it simply indicates we already knew about this and are actively addressing it already.
Seems reasonable that Uber's team knows their tokens don't expire and that it's not a good practice.
The rate limiting on the promo code endpoint report is the worst. It looks like Uber actually forwarded this one on to an internal expert, who replied with:
> we would consider the lack of multi-factor authentication a best practices concern, out of scope for our bug bounty program. Additionally, Uber tokens (UUIDs) are made up of 128-bit highly entropic values, making them very difficult to guess or brute force. We’ll be closing this report Informative, as this does not pose a security risk in itself. We wish you the best of luck on your next report!
Which is completely fair (you'd have to try ~10^29 values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second). The submitter argued their PRNG might be broken but provided no evidence that was the case. The submitter then posted some very hateful personal attacks against the people responding, including:
> Oh my God. Are you seriously the Program Manager for Uber's Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting? LULZ
I can understand feeling less than obligated to give a payout on these.