Every Twitter's bounty amount is divisible by 140.
HN user
franjkovic
[ my public key: https://keybase.io/josipfranjkovic; my proof: https://keybase.io/josipfranjkovic/sigs/4EYnl7a6Vko4DGKQFypdzXwAxT-YnFN8DEc5X34RttQ ]
My security blog: https://www.josipfranjkovic.com
I wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.
how many hours did you spend researching this?
Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps.
I think $5,000 is a joke
This is still $5,000 more than I would get reporting a similar bug to 99.999% of companies, and I am OK with the bounty. Here is good comment on the topic of bug bounty rewards: https://news.ycombinator.com/item?id=11249173
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.
I'd say it does.
Not interact with other accounts without the consent of their owners.
Edit: whoops I mis-read this a bit, but the point still stands - he escalated using AWS keypair that did not belong to him, and he had no consent of the owner.
I think they did not reward me because you cannot really hurt anyone by having multiple usernames.
Thanks! I reported the bug to security@ email, and one of your team's members replied on the same day (January 6th). Either way, good job on fixing this really fast. I wish more teams are as responsive as yours.
Facebook puts out stats from their bug bounty program once a year. Most of bugs are invalid reports - in 2013 they had 14,763 reports, with 687 being valid.
(https://www.fb.com/818902394790655)
They probably got a couple people working exclusively on bug bounty reports. I also have to say they did a great job changing communication channels from emails to tickets which show in /support/, it is way easier now. The downside is that you must have a Facebook account, not sure if it was needed before the change.
The bounty actually surprised me, too. I expected between $1000-$2000. That is one of reasons I like reporting bugs to Facebook - they pay really good, critical bugs are fixed really fast (<1 day).
One time they paid me $5000 for a bug I never could have found, but they did internally based on my low severity report. (http://josipfranjkovic.blogspot.com/2013/11/facebook-bug-bou...)
I agree with this, too. Personally, I would probably do the same. A day of breaking small part of site vs killing local file read seems like a good trade.
HN, I am wondering about your thoughts on the $5500 bounty. This is a bug that affected third party system on Facebook's servers, and the network was locked down. I could have gained access to resume analysis software and maybe resume uploads themselves. There was a small to none chance I could get Facebook internal code or binaries. So, was the bounty enough?
Yeah. In the 1 day timeframe between temp and permanent fix you could not upload resume, which is a breaking change for end users.
But, I think it was pushed because it was Sunday and Careers team was not on site to properly/permanently fix the bug.
Great bug, congratz!
I saw that request when going through iphone.facebook.com, but never tried anything there... I assume it worked on all x/mobile/m/touch/iphone.facebook.com?
Just added timeline for the report on blog.
I agree with this - yet BB programs are still very successful. Why? Because not everyone who knows about websec has a job in the field. The second thing is, $500 as a minimum reward may seem small in 1st world countries, but in the rest it is close to the average monthly pay.
Redirect URL when you give access to Facebook is different for other email providers. Hotmail (that is, Outlook) is the only one that worked as far as I know - I have tested Gmail and yahoo, but neither of them were exploitable (there is also chance I missed something, so it is worth checking again).
You can read about all kinds of bugs and "bugs" I found in bounty programs on my old blog, too http://josipfranjkovic.blogspot.com/
I spend 4-5 hours a week hunting for bugs.
The "session" I found this bug in was around 2 hours long.
Actually I waited until we pushed Pyxio website on-line. Since I am not native English speaker, what would be best replacement for current title?
12,500$. (More than)Good enough for me, takes a year of work on average salary to get this much money in my country.