TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

HackerOne breach lets outside hacker read customers’ private bug reports

14 pointsby migueldemouraover 5 years ago

2 comments

AshwinDurairajover 5 years ago
I think this is a disproportionately negative title compared to what actually happened, and solely for one word, &quot;breach&quot;.<p>My opinion is that it conveys something more serious than a bug. Thousands of secrets have been leaked on Github&#x2F;Bitbucket, and we don&#x27;t need to report every single one as a &quot;breach&quot;.<p>For instance many AWS credentials have been reported as being leaked on HackerOne, but I don&#x27;t see Ars writing an article for each one saying &quot;X company breach let&#x27;s outside hacker have full access to X&#x27;s infrastructure&quot;
rvnxover 5 years ago
The breach is here: <a href="https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;745324" rel="nofollow">https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;745324</a><p>TL;DR: One user reported a bug to sign-in using cURL. HackerOne replied with admin credentials (session) to show that login works.<p>Nobody noticed. One guy logged in, downloaded a significant amount of sensitive data (private exploits!) and then told HackerOne. They give 20&#x27;000 USD to say nothing about it.<p>End of story.