A non-vulnerability like this is a good example of how easy it is to get press for $important_company + security.
Top of hackernews at the moment and fingers crossed there wont be a wave of articles about this in the coming days from tech press who don't fully understand the issue but know clicks when they see them.
(Wrote about this on reddit but I think it is pending approval, reposting here)
Hi - I work on the security team at Uber. I am this guy: techcrunch.com/2016/03/22/uber-launches-bug-bounty-program-that-pays-hackers-to-find-security-issues/
Yesterday we changed the language on our bug bounty page and I wanted to apologize for the confusion this caused. Since we launched our public bug bounty program on Tuesday, we have been reacting to the types of issues sent in and learning how to better define what we are looking for. This change was part of that, and not an effort to prevent anyone from earning bounties. The reason we clarified is so security researchers, whose time is valuable, wouldn't spend time on lower-risk issues like microsites that are unlikely to get a reward.
To Sean’s points about microsites, a microsite is usually a blog type site that rarely contains Uber user data and lives outside the Uber network. As such, even in cases where microsites are vulnerable, they pose a mild security risk to Uber which is why we clarified in our policy page to say that we do not reward them “except in extraordinary circumstances”. Sean also mentions that they are lower in severity: https://twitter.com/seanmeals/status/712975867236974592. Although the intent around microsites didn’t change, the language did. I apologize for this and we could have done better.
To the specific issue raised in your post, we have made it public: https://hackerone.com/reports/124975. As you mention, the payload does not fire so this is not a security concern.
A successful bug bounty rests on researchers trusting us to run it well, which we take very seriously. All the members of team running this program are part of the security community and many of us (mjb(1), jordan(2), rob(3)) actively submit to other bug bounty programs or perform security research as a hobby. We have awarded nearly a hundred issues via our pilot bug bounty program so far and we are excited to payout more in the future.
Our aim is to build a program by researchers, for researchers. I want to personally thank you for taking the time to submit your issue -- and any future issues. You can always see the scope and rules of our bug bounty program at https://hackerone.com/uber and you can feel free to mention my name in any reports to HackerOne to get my attention about an issue.
Maybe you know this, maybe you do not but these are all a nod to http://insecure.org/stf/smashstack.html which itself did not directly involve profit. It's a security thing.
I just feel bad for amazon people I meet, the 2 year cliff and high pressure oncall simply isn't a thing at the other tech companies. At least for me and ive worked at a few of them (plural of anicdote isn't data but still) Life seems strictly worse at amazon.
One wrinkle - Doesn't this poll ignores anyone under 18? Facebook lets you sign up only once you have turned 13. Internet users between the ages of 13 to 18 are unaccounted for.
Because google cannot make as much money off of an account named LispNerd3k vs your real name.
From an advertising pov G+ wants to have as much information about you as possible to best target ads. This is basically a good thing as you see more of what you want and they get more clickthrough and can sell ads for more. When you type something into google search, google can make an educated guess about who you are based on your query, geo information and past searches. A primary goal of G+ is to associate the G+ information you are voluntarily filling out (real name, address, hobbies, etc) with the rest of googles ad network making it leaps better.
That is why google thinks social networking is important, and why g+ doesn't need to "win" vs facebook for it to have a net positive effect on google. Even mild G+ adoption makes googles whole network of ads much more intelligent.
I am not a business strategy person but this explanation makes sense to me so take it as a guess/opinion.
Noble intentions but please don't do this in the future. Working in security (not at google) I promise we are trying to fix it as fast as possible already :)
You may also get cash+prizes if you submit as you did but don't release it publicly.
When I was 7 or so I used to love arcades with my focus being on games which got me tickets redeemable for candy. One day I noticed the counting of arcade tickets was done by weighing them on a scale so one day I ran my stack of tickets under the water fountain. Depending on how well I wrung them out I would get 2-3x the tickets. I am glad I found the world of computer security where I get to look for stuff like this all day.
I feel this was somewhere between outright cheating and possible cleverness, probably leaning more towards cheating.
Its a biography but a biography I derived a lot of philosophy from - The Years of Lyndon Johnson by Robert Caro. Here is a blurb that wikipedia lists as the theme:
Throughout his books, Caro examines the acquisition and use of political power in American democracy, from the perspective both of those who wield it and those who are at its mercy. In an interview with Kurt Vonnegut, he once said: "I was never interested in writing biography just to show the life of a great man," saying he wanted instead "to use biography as a means of illuminating the times and the great forces that shape the times particularly political power."
I agree with that theme and enjoyed the description of how power is wielded in democracies and all the gory details of getting elected, how issues help/hurt a candidate and just how nimble a fish you must be as a presidential wannabe in Americas 1950s democracy.