> I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough.
> This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have deemed as an improper response, or lack thereof ...
Seems pretty straight forward: hackers have already downloaded all the personal data out of these organizations and are probably using it in ways harmful to the general public already. This guy is forgoing his probable bug bounty payouts as this is, as he says, a really serious issue.
Thank you to him!
And the feds are standing at his front door in 3 .. 2 .. 1.
> I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.
Might be the important part of the quote you missed.
He reached out, and didn't have any luck. Companies truly need to learn how to deal with these breaches in a way that re-invites the public trust
"Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer.
It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme."
[1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new...
EDIT: The quote previously included "Yahoo is notorious for its disregard of bug bounty hunters, having last year rewarded one such hacker who identified three bugs in Yahoo's servers with a $25 voucher for company merchandise." but I moved it here as it caused confusion regarding which issue the article was referencing.
http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the...
(and HN discussion: https://news.ycombinator.com/item?id=6488897)
Bounty hunters do this stuff for a living. If the company pays with $25 vouchers and the black market pays on the order of tens/hundreds of thousands, who do you think "these people" will go to?
There are close to zero companies that pay tens/hundreds of thousands for a bug, and yet clearly bounties are being paid and not 100% of bugs end up on the black market.
Facebook has paid $12,500 for one (http://techcrunch.com/2013/09/02/security-researcher-discove...)
Google will pay up to $20,000 for one (http://www.google.com/about/appsecurity/reward-program/#rewa...)
Forbes even posted an article a couple years ago on the market of zero day exploits and listed prices someone could get for zero day exploits with prices in the tens/hundreds of thousands. (http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...) It should be noted that they state in this article that the groups that will buy these exploits for these prices are generally western governments.
I identified that a few major sites were actually compromised using the vulnerability - Yahoo! being one in
particular. Tripod/Lycos and WinZip.com were also compromised. Yahoo! reached out and gave me a response, albeit a very
weak one, only after the FBI, media and CEO Marissa Mayers was contacted... WinZip patched their boxes and didn't
bother responding or notifying me that they got it done.
And, amusingly, an apology for his rambling:Please do excuse the scattered nature of the email sent to Marissa Mayers @ Yahoo! - there were other correspondences that are currently being kept private, and at the time that I wrote that one, I had been awake for roughly 48 hours and was fueled on caffeine and nicotine.