News

Uber Accused of Skipping Out of Paying Bug Bounties

With all the apps and systems that are used, created and updated every day it is often impossible for you to be absolutely certain about their security. This resulted in the creation of external help through schemes like bug bounties unless your Uber who change the scope of what bug bounties they’ll be paying.

Bug bounty schemes are simple. If you find a problem in the code or system that a company uses, you report it to the company running the scheme and if they find it was a problem, you get paid. Even Microsoft and GitHub run schemes to help narrow down and find problems with their software. The issue comes here is that only this week popular taxi alternative app Uber launched its own bug bounty scheme.

Sean Melia found a few issues or rather a few admin panels/ports that were open. This fell in line with what Uber wanted under the grouping of “publicly accessible login panels” and “exposed administration ports (excluding OneLogin)”. After reporting the first issue which was quickly accepted as a bug, Melia went about finding others resulting in the large group he ended up reporting. The problem was that by this time Uber had updated their documentation to make these reports invalid, without informing people using the scheme. Free security support anyone?

The reason for the change? Ubers security engineering manager, Collin Greene, has stated they changed the rules so that they stopped researchers wasting their time on minor bugs. Greene then stated that “a successful bug bounty rests on researchers trusting us to run it well, which we take very seriously”, something that may not go down so well when you are willing to change the goalposts without telling people.

Was Uber right in this case? Should they have acted differently? A problems a problem, even with a lesser payment, should Melia have received something given that he did the work under the old rules?

Gareth Andrews

Disqus Comments Loading...

Recent Posts

MSI MAG B650M Mortar WIFI (Socket AM5) DDR5 Micro-ATX Motherboard

CPUAMD Socket AM5 for AMD Ryzen 7000 Series Desktop ProcessorsChipsetAMD B650Memory4 x DIMM, Max. 128GB,…

2 mins ago

Zotac GeForce RTX 3050 Twin Edge LHR 8192MB GDDR6 PCI-Express Graphics Card

ColourPrimary ColourBlackGraphics CardGPU SeriesRTX 30 SeriesFeaturesVirtual Reality ReadyYesClock SpeedsMax. Memory Clock14000 MHzMax. GPU Clock (Boost)1777…

4 mins ago

AMD Ryzen 9 7900X3D Twelve Core 5.60GHz Processor

With this enthusiast processor, you can enjoy extreme performance for gaming, creating, streaming, or whatever…

12 mins ago

Ssupd Meshlicious Mini ITX Case – Tempered Glass 

Compact and stylish Mini-ITX case Clearance for 315mm GPUs with up to three slots PCIe…

25 mins ago

Aerocool Integrator Gold 1000W 80 Plus Gold Modular Power Supply

Compatible with all intel form factors up to ATX12V Ver 3.0 All premium Japanese branding…

27 mins ago

Refract Gaming Celeste – 1080p/1440p Pre-Built Gaming PC

Pre-built gaming PC for mid-range gaming and streaming Cherry-picked hardware and hand-built by Overclockers UK’s…

32 mins ago