Linkedin's Response to My "Phishing with Intro" Post
jordan-wright.github.io
jordan-wright.github.io
I think it's inevitable that most tech companies are going to end up offering formal bounty programs, but you should remember that only a select few do today.
I may be mistaken, but I was under the impression that there generally was a tacit agreement that you only get the bounty if you don't go public with it before it's fixed.
This is why I was so impressed. The contacted me after I published the post, and yet they still sent me a token of their appreciation. That to me showed a ton of class.
I'm not necessarily saying people shouldn't disclose first, but labeling it as responsible is grating.
Absolutely. That kind of language marginalizes people who are public whistleblowers who have no faith in the internal systems in which they reside.
With that said, it's kind of a grey area. Some may reward you but others may not. Google for example asks for responsible disclosure. They will most likely be reluctant to give you a reward if you didn't play by the rules and undermine the entire purpose of the vulnerability reward program anyways.
The program's aren't meant to show off how smart the engineers are who work there. The programs are meant to prevent legitimate attacks. No news is good news in the security world...and you don't know that you made the news until too late.
I should add, when reporting the bug, I know google asks if the bug is made public and they also ask for a URL to where it is available. So maybe the area is more grey than I think. Nobody will know until someone reports a public bug, I guess.
The original blog post basically summed up and condensed that everybody who knows about HTML could have seen. I didn't even blink in surprise when I saw it. It was well executed and written and as such a worthy contribution but the attack vector was rather obvious. Pretty much my first thought when I saw what LinkedIn is doing was "There's certainly a way to abuse this and inject false info.". AFAIR similar feelings were voiced in the HN thread about the original submission.
I'm all for responsible disclosure, but in this case I don't think it was warranted.
But it is the kind of company that set up this massive MITM hole in the first place, and thought it was a good idea to "offer" this "feature" to unsuspecting targets, er, "users".
They may have fixed this "bug", but the bug that is the feature itself remains, and it can only be fixed in one way...
Recognizing people for being good people, as the author did, should be completely separate from a product that you believe is a bad product.
How is that disingenuous? Was the accusation not sincere?
1. Not straightforward or candid; insincere or calculating
2. Pretending to be unaware or unsophisticated;
3. Unaware or uninformed; naive.
Generally it is used to mean untruthful on purpose, with an intent to deceive, usually by acting as if you're unaware of something.
I'm very glad to hear this.
Disappointed (in general) that this even needs to be noted, but glad to hear it. Unfortunately, this is not something that can be taken for granted.
While I think that a bug bounty is the RIGHT thing to do in this scenario, the security guy likely couldn't just decide on his own to give out thousands of dollars, so something is better than nothing, and if the expectation was nothing, then well, sounds decent to me.
Please just give me the money. I'll decide which companies I will do free advertising for.
On the other hand, if some company wants to thank me for something in the future with something more than tradeshow swag, I would not turn down a nice bottle of whisk[e]y, just sayin'.
I was hoping that at the very least, they'd offer you a job.
2. They sent him a trophy. It wasn't just any ball pen with the company logo but a nice, topical t-shirt
As someone else pointed out - he disclosed the vulnerability publicly before informing LinkedIn. Most companies wouldn't have given him anything.
Don't be a 'cheap kind of company' linkedin. Pay up.