Abusing Amazon‘s Look Inside feature to leak unreleased content
justmaku.org
justmaku.org
I'm not surprised Amazon would pay with nothing more than a nice email. What's more surprising is that Blizzard would give the author the shaft like that. They're usually pretty good about this sort of thing.
Nice one, good job guys.
The bad practices for me, are their pivoting toward lootbox pay2win gambling designs.
Destiny2 had some issue with theirs but didn’t they listen to the community and fix those.
I’m not a fan of loot boxes but their are not as bad as others in the industry.
Which was a feature in games before WoW but isn't a pay to win mechanic as you can not pay for "drops". WoW for the longest time refused to have a real money gold shop as was more that people were buying in game gold from 3rd parties anyway so might as well make a safe way to do it (which isn't a direct cash for gold transaction, more that another player has to buy your game time token, but that will usually happen within 30 mins).
As for hearthstone I would lay the blame more at Magic: The Gathering Online personally (though not the first), but I see you point that the game has very popular and became the "cardboard crack" that IRL Magic was (Atleast with Magic: The Gathering Online you could trade / sell your online cards with others until you piss off WotC and they nuke your account).
My point about the drops is that skinner boxes are dangerous. My RA flunked out due to wow. Some small group of people really struggle with casino stuff
Or sell it to someone who can make use of it.
It's incredibly entitled for a company to not run a bug bounty program then complain when people drop 0-days on their github blogs.
Bug bounties are a good incentive for hardening your security, but is exploiting flaws the moral thing to do by default? Does there need to be a monetary incentive for people to do the right thing?
I run a service that has a few users and makes about $200/mo. Someone once emailed me that they found a bug and whether I run a bug bounty program. I told them I couldn't really afford one and they never replied. Are they now morally justified to publicize the flaw?
Telling everyone (unfortunately including thieves)? I think it is. Such negligence should be disclosed.
Your service may be too small for this, but a company like Amazon typically saves money overall by running a bug bounty program because uncaught bugs can be extremely expensive.
That being said, your analogy is broken and doesn't fit here at all. First, parking lots are passive and have no intelligence. Amazon is neither of those things. Also, there are no such people who dedicate their career to lawfully testing the security of parking lots in exchange for money.
In the real world of mega corporation technology (which is almost as different from a parking lot as you can get) there are countless black hats motivated by money to steal from Amazon, and countless grey hats who would help combat or mitigate the issues if properly compensated. White hats are the rare exception and report issues even without compensation.
There are numerous grey hats who: 1) If there is a bug bounty program, would report the issue to be fixed 2) else, would ignore the issue entirely.
You know this is true because you experienced it yourself. The difference is you can't afford the service of a grey hat.
So forget the morality of these hackers.
Amazon refusing to pay out a bug bounty program is amoral. Because what you're seeing is Amazon trading the security of their customers, and for what? Greed and hubris it seems.
Conversely, if you accuse the person who tells you the door is open of stealing from you and threaten to call the police, should you really be surprised if next time that happens they tell someone, maybe in exchange for a cut of the profit?
Not at all similar. One is leaving open the door to your own car. The other is someone who is being entrusted with keeping something safe for third parties "leaving the door open", i.e. being in breach of that trust, and essentially saying that they don't give a frack about their infraction.
So how can Amazon be sanctioned for this infraction?
While I also don't see "breaking in" as necessarily a great option, it may be less bad than letting Amazon just get away with it. Unless there is a good way to fine or otherwise sanction Amazon, I am not sure there is an actual good option.
If there's any entitlement, it's within the small but vocal subset of security researchers that feel that unsolicited bug finding should be compensated under threat of public disclosure.
Some information on the topic: https://en.wikibooks.org/wiki/Next_Generation_Sequencing_(NG...
http://search.lores.eu/books.htm (near bottom of page)
Of course, back then it was the norm to publish this information in a place for those seeking information or otherwise "keep it tight", and not instead let them tighten the nooses around our necks by instantly snitching to the company for the hope of a paltry monetary reward...
Although reading it again it does seem to be quite unclear...