news.volyx.in

“We found PayPal vulnerabilities and PayPal punished us for it” (cybernews.com)

980 points by teslademigod1 · 2420 days ago · 328 comments on HN

Article summary

The article discusses the experience of security researchers who found vulnerabilities in PayPal's system and were punished for reporting them through HackerOne. The researchers claim that despite the issues being eventually patched, they received no bounty, credit, or thanks, and instead had their reputation scores negatively impacted. The details of the article are not available, but the comments suggest that the vulnerabilities involved bypassing two-factor authentication and other security measures. The researchers and commenters are critical of PayPal's handling of the situation and its bug bounty program.

Main themes

  • PayPal security vulnerabilities
  • Bug bounty programs
  • HackerOne policies
  • Security researcher rewards
  • Two-factor authentication bypass

What commenters say

  • PayPal's bug bounty program is flawed and punishes researchers for reporting legitimate vulnerabilities.
  • The company's policy on out-of-scope issues is unclear and can be used to reject valid reports.
  • Security researchers should be rewarded for reporting vulnerabilities, even if they are eventually patched.
  • HackerOne's reputation system can be unfair and negatively impact researchers who report legitimate issues.
  • PayPal's security measures, including two-factor authentication, are inadequate and can be easily bypassed.
  • The company's handling of security vulnerabilities is a sign of a larger problem with its approach to security.
  • Researchers should be cautious when reporting vulnerabilities through bug bounty programs and may be better off disclosing them publicly.
  • The lack of transparency and consistency in bug bounty programs can lead to frustration and mistrust among security researchers.