> That's right, the response contained Facebook's /etc/passwd. Now we were going somewhere. By then I knew I had found the keys to the kingdom. After all, having the ability to read (almost) any file and open arbitrary network connections through the point of view of the Facebook server, and which doesn't go through any kind of proxy was surely something Facebook wanted to avoid at any cost. But I wanted more. I wanted to escalate this to a full Remote Execution.
> A lot of bug bounty programs around the web have a rule that I think is very sensible: whenever you find a bug, don't linger on messing around. Report the bug right away and the security team will consider the worst case scenario and pay accordingly. However, I didn't have much experience with the security team at Facebook and didn't know if they would consider my bug as a Remote Code Execution or not. I Since I didn't want to cause the wrong impressions, I decided I would report the bug right away, ask for permission to try to escalate it to a RCE and then work on it while it was being fixed. I figured that would be ok because most bugs take a long time to be processed, and so I had plenty of time to try to escalate to an RCE while still keeping the nice imaginary white hat I have on my head. So after writing the bug report I decided to go out and have lunch, and the plan was to continue working when I came back.
https://www.ubercomp.com/posts/2014-01-16_facebook_remote_co...
That's the difference between paying a ransom and a bounty.
The hacker definitely downloaded files, but Uber also asked him to download production data to confirm the hack (um, what?) Uber escalated the payout; the hack wasn't particularly interesting, but it was substantial, so who knows there. The hacker's communication was dodgy, but he eventually met in person, and the fact he didn't want to leave his house indicates a possible social disorder.
Their handling was poor, but this may just be a case of "hating uber because they're uber".
"Oh yeah? Then fucking do it then", seems fairly Uber.
So no, this was not disqualifying and he was told to do so. This is not extortion, just pay negotiations.
BB’s are complicated and can be messy. You never know what the behavior of the participant will be after the award. Someone had to fight for approval of this payout at significant career risk for themselves. If we broadly assume bad faith on the reporter or on the recipients, we’ll lose the protection that bb’s can provide and white hats will be more at risk of CFAA prosecution. We need to be more willing to make mistakes when it comes to these situations.
I think that, in this case, it is more likely that someone was told, or felt it to be the case, that their career or options were at risk unless they could come up with some sort of cover so that Uber could claim it did not have to disclose the leak.
There is a simple test for whether someone is seeking a bug bonus, or to extort you: if someone says he has a way to get your data and would you care to know how, its a BB case, but if they say they have your data, give us some money to say we deleted all copies of it, that's extortion.
Total bounties paid $1,345,845
Highly doubt 100k is included in there.
Sadly this is a core part of discourse in the Bay Area and American society at this point, which I believe contributes to people’s inability to connect well and develop shared empathy.