249 karma · joined January 9, 2015
The issue stayed on Triage state and I missed the reporter updates. I talked to the author of the post and I believe we are in good terms now.
The security and privacy of our customers is extremely important to us, everything we say in our security page is true and I've been working on this for years.
By the time the report was originally sent the feature was just released, and while we never deployed a code change to directly address it, it wouldn't be the first time that we receive something that I believe it was genuinely a security issue and stopped being reproducible due to an seemingly unrelated change around the same time.
The truth here is that we were never able to fully reproduce the issue from the beginning, but struggled to close it because of the fear of missing something. Shortly after when we got back to the reporter for the last time, saying that we'll find a resolution, is when we were convinced that we were not able to reproduce it. Around that time we received a similar OAuth-related report. Unfortunately, this led to an internal mix-up, making us believe that we had addressed and communicated the resolution.
Because of the way I have notifications set up, I missed the follow-ups, and the issue stayed in Triage state indefinitely without receiving updates. This is by no means an excuse about the lack of updates, about which I'm deeply sorry. I've been a bug bounty hunter for many years and understand how frustrating it is to wait for updates from companies.
Finally, I'd like to reassure y'all that the security of our customers is of the utmost importance to us, and everything we say in our security page is true.
Looks like for the typical case (~200ms calculating the hash) bcrypt beats argon2. I guess that’s what I understand from those discussions, I’m not an expert by any means. It is related with cache hardness: https://twitter.com/Sc00bzT/status/1149963675069026304
I used MD5 because that's the typical hash you find unsalted on leaks, but if you do the math with others it is almost impossible to find an example where storing beats using a GPU to crack (even an older one) for a couple of hours.
[0] https://github.com/nabla-c0d3/ssl-kill-switch2 [1] http://mitmproxy.org/
Most of the 6k registered users on Quitter Spain are inactive and it has nothing to do with Podemos and the indignados movement (they use Twitter actively along with Facebook). Even the user that started this "false migration" (@barbijaputa) is using Twitter and is inactive on Quitter.
- Be ready to answer every single report on a short timeframe
- Be fair and provide feedback to the reporter
- Be nice, be thankful and reward the researcher if they deserve it
- Be patient with the duplicate reports and people just trying to get an unfair HoF
Otherwise it may backfire you and eventually it will.