HNHacker News
TopNewBestAskShowJobs

sxcurity

67 karma · joined December 24, 2017

just a lowly mattress salesman @ boring.co
submissionscomments
sxcurity··on I hacked the Dutch government and all I got was this t-shirt
I got one of these shirts in high school for a bug I found & thought it was the coolest thing. It's funny & sets expectations – https://x.com/hacker_/status/863057296309485569/photo/1
sxcurity··on Hacking Kia: Remotely controlling cars with just a license plate
Stop connecting vehicles to the internet pls & thanks
sxcurity··on Hackers abuse ‘chaotic’ Nomad exploit to drain almost $200M in crypto
Hey, I work @ Zellic. If you have any questions, definitely feel free to reach out!
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
Great argument end sarcasm, you yourself are also obviously biased
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
How? These were terrible P5 reports that would get closed as informative in ANY PROGRAM. He has no evidence behind the claims of the "xss" and the "OneLogin bypass" which they would have indeed paid out if it was valid. I'm highly disappointed in people here, geez.
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
Posted this as a response on Medium but got blocked cause I guess he just wants yes men around lol:

“I’m also able to bypass the Uber OneLogin SSO portal, resulting in source code disclosure from their internal uChat employee messaging system.”

Where’s the proof? I don’t see any whatsoever. I highly doubt that you were actually able to bypass the OneLogin because if you did, they’d definitely pay out and it’d be an actual issue rather than some crappy bugs.

    Lack of certificate pinning IS NOT a critical issue. Critical issues are code execution, file read, etc.
    The odds of you actually guessing UUIDs are super low and pretty difficult, they did the right thing in closing as informative. You’d have to try “~ 10²⁹ values to get a valid token assuming a billion accounts, which would take millions of years at 1 trillion requests per second.” You claimed their PRNG was broken but had no evidence or support to back it.
    “Are you seriously the Program Manager for Uber’s Security Division, with a 2013 psych degree and zero relevant industry experience other than technical recruiting?” — you’re a complete moron, glad you know how to personally attack people, Uber definitely had the right to ban you from their program.
    Programs CANNOT delete comments from HackerOne Reports (as you claim in https://hackerone.com/reports/293359)
Uber DEFINITELY made the right choices in closing your reports as informative, but go ahead, fool yourself
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
A bunch of P5's that were rightly closed as informative. I completely agree w/ Uber's decisions here...
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
lool he has valid points though.
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
AMEN. I totally agree with this, Uber was 100% right on these decisions. My response is here: https://medium.com/@cdll/im-also-able-to-bypass-the-uber-one...
sxcurity··on I Got Paid $0 from the Uber Security Bug Bounty
I agree w/ Uber on these bugs, they're trash and would be considered informative by almost every program