HNHacker News
TopNewBestAskShowJobs

hackeroneuser

50 karma · joined December 24, 2017

submissionscomments
hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
Simply putting my name as HackerOne user does not mean I am bias. Also no, hackerone or Uber none of them paid me to say the comments. If simply putting my points and pointing out the wrong facts will make me look bias then so be it.
hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
Also, I wish I am an hackerone employee or work in any of these platforms as an employee. I am simply a hacker and also employee of a company that runs a bbp so I have in both sides and I understand frustration of both side. Being frustrated does not provide excuses to the hacker's behavior of harassing an employeee based on their degree. This community is diverse and that is what we should learn to appreciate.
hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
My username has nothing to do with anything. I simply chose it to hide my identity. I said what I said because I hack multiple programs throughout multiple platforms. These kind of blogs usually give a sense to companies that all hackers are like these. This leaves a bad impression about what we actually do. I don't think simply having hackerone in my name will make me bias. If you check my comment, you will see I have not said that HackerOne is right and the hacker is wrong. I have simply pointed the right facts that I felt was important for everyone to see. His blog leaves out a lot of points and also misguides readers.

Hopefully this clears it to you.

hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
I will not say anything about whether he needs to get paid or not until Uber discloses the report. If he showed that it is a valid xss and not a content injection then I guess it would be valid. But again, right now we do not have the report made public.
hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
Alright, I need to make more things clear here because clearly you have no experience on how HackerOne's platform works:

1) Companies have ability to change when the disclosure happens. This is because sometimes, if I find a RCE lets say, companies have to run incident response. This sometimes take more than 30 days. Also to add, if I just request disclosure for any BS report then it will just cluster the disclosure page with no valuable information for new hackers.

2) I haven't seen reports getting locked unless reporter goes "Can i haz update" every 2 days. Then in such cases, Locking a report is more than fair.

3) You might be confusing this with Limited Disclosure. That is allowed in both sense by companies and hackers. Most of my reports are limited disclosure because sometimes, I have to share personal details or personal information that I don't want other hackers to see.

I support transparency that is why, till this day, all of my resolved reports for public programs are publicly disclosed. Even in Uber's case, I have disclosed bug but they were limited disclosure because it had my personal information. But if you check, Uber has allowed me to write public blogs on my reports.

So please, learn about the platform and a program works before you make any form of assumption.

hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
If you check reports that are actually valid, you can see that Uber actually pays for valid issues. Excluding the 100,000, Uber has already paid 1million+ in bug bounty. Please check their hackerone platform :)
hackeroneuser··on I Got Paid $0 from the Uber Security Bug Bounty
Here is my personal take on this:

I have worked personally in numerous occasion with Uber's security team. I have helped them with many security issues and they have always been open to securing vulnerabilities, listening to hackers to make a change and even pay good payouts.

There are couple of things I want to point out to the author here:

1) You said that if these were Duplicate reports, they have to have a report number assigned. If you use HackerOne application frequently (which it does not look like you do), a report number is only assigned if it was submitted by another hacker. There are situations when internal findings are also on process on being fixed.

Uber treasure map is simply a guide. If you find something that is bypass of what they said they have, does not mean its an original finding. I work at a company where we have our own security team breaking applications every day. Sometimes hacker submit similar findings that our security team found before. In such cases, if it is a low priority issue, it will take time for us to fix because we do not prioritize it. In that case, a hacker will get a report marked as Duplicate with no report number assigned.

For the first three report that is exactly what happened.

2) Personal attack against a employee of a company will not help you anyways. You went after an employee just based on your degree. If you look closely in the industry, it is the matter of experience not degrees. I have worked with colleagues who are way smarter than me in the field and have way more experience. I never judge them based on their degree.

3) I am still not sure about your reflected XSS bug. Were you able to get a XSS actually execute? Seeing reply from Rob makes me thing you probably found a valid xss that works on an old browser. In addition, you also said you gained access to internal uChat: "I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system." but you did not prove that anywhere in your blog so I don't know if that is legit.

To conclude, considering the recent media attention at Uber due to security mishaps that occurred before, it seems to me that you are just looking for a media attention. Your title first is clickbait because 3 of your reports are duplicate so I am not sure why you expected any bounty.

To make this clear: I am a hacker in the community and an active participant in Uber's bug bounty and also in HackerOne. I have never seen Uber be unfair to hackers in the platform. Hell, to even encourage hackers, they started to pay 500 on triage.

That said, I am looking forward to your comment on this and would love to see your discussion on my points listed above.