United Airlines bug bounty program
united.com
united.com
Conferring lifetime status isn't necessarily even that expensive to the airline--you only get the benefits after you give the airline your money for tickets. It also creates an incentives to buy tickets on one particular airline, even when they might be slightly more expensive (which is the whole purpose of frequent flier CRM programs).
Now they no longer do that. So it makes the miles far less useful. And, since it doesn't apply to GS, all the other premiers still get screwed by this change. So it's not like it's gonna improve premier status for the rest of us anyways.
Ranty anecdote: Oh and they don't even respect what their ticketing and policies on this state. It was that any such ticket booked before 15 Apr would use the old rules, and indeed the baggage calculator would show that. Sent my sister somewhere, counting on some big bags to bring equipment. GA starts making a fuss, saying no, made her unpack and so on. Even after calling United and being assured she'd be treated properly on the return flight, nope, still not handled correctly and made to pay extra. United's IT is terrible. That's why we call their site ".bomb".
UA needs to get their shit together.
(quotes as delimiters; I can't find the exact quote )
"Do not attempt: ... Brute-force attacks"
This seems contradictory. I assume the intent is to not allow DoS attacks (although they call that out separately further down the list)?
Seems they're saying they'd accept a bug that can be caused by brute-force, but do not actually attempt a brute force yourself.
But yeah I'd guess they don't want intentionally invite a bunch of people to DoS the site.
It's very strange to see website timing attacks as worth rewarding, but not avionics. Perhaps they'd rather not incentivize people to attack airplanes in flight?
Though the avionics industry would obviously balk at the proposition, those systems are already spectacularly vulnerable, and they'd hate to lose face.
Absolutely untrue, unless you have physical access to them (at which point any system is vulnerable). In truth, the maintenance port on a 787, for example, (which is the only place you could feasibly get the kind of access you'd need to even attempt an exploit) is located in the avionics bay. At the point that an unauthorized party has gained access to the avionics bay, you've got a much bigger problem than software exploits.
If you're referring the Chris Roberts' dubious "Planes, Trains, and Automobiles" grrcon talk ... well, I'm sorry, but claiming that you've "made friends <giggle>" with an airplane doesn't seem very substantive to me.
Avionics code is some of the most extensively tested code in the world, with 100% statement and decision coverage, 100% requirements test coverage, extensive robustness testing, and somewhere between a handful and hundreds of eyes having reviewed every single line (depending on criticality level). Additionally, design constraints are followed for high criticality software that simply eliminate many types of attacks - no dynamic allocation, mathematically provable static stack analysis, etc. etc. etc. (get yourself a copy of DO-178B and read it if you really want to know all the details). I would bet a significant amount of money that the defect rate per N lines of code in avionics software is probably substantially lower than almost all other commercial software. There's also the fact that on modern aircraft using Ethernet based networks, message routing and authentication are implemented in both hardware and software at multiple layers by independent teams, which greatly reduces the chances of a common fault that allows a successful attack (even if you could gain physical access to the network).
United probably isn't interested in paying for someone else's bugs.
"Bugs or potential Bugs you discover may not at any time be disclosed publicly or to a third-party. Doing so will disqualify you from receiving award miles."
It's as if it was designed in the same spirit as a frequent flyer program -- really stingy payout, with lots of strings attached. I can't see how this can incentivise anyone to do free penetration-testing for them.
A lot more if you redeem for int'l biz/first class...
Another gem in the ToS: "You are responsible for any tax implications that apply based on your country of residency and citizenship."
I know miles earned from credit cards are not taxed, but I do know for a fact that Citibank sends out a 1099 for new checking accounts that come with bonus miles.
If United sends you a 1099 based on the market value of a mile (likely between 2-3 cents each), then you're looking at non-trivial tax implications as well.
I made a calculator to answer the question: should I pay cash or spend miles. I set the "good value" threshold at 2c/mile: https://kballenegger.github.io/miles-or-cash/
I would have been a lifeline customer, but Continental ruined it.
If I put ?param=' and it crashes with an SQL error have I performed code injection on a live system?