{
  "id": 745324,
  "url": "https://hackerone.com/reports/745324",
  "title": "Account takeover via leaked session cookie",
  "state": "Closed",
  "substate": "resolved",
  "severity_rating": "high",
  "readable_substate": "Resolved",
  "created_at": "2019-11-24T13:08:59.542Z",
  "is_member_of_team?": null,
  "reporter": {
    "disabled": false,
    "username": "haxta4ok00",
    "url": "/haxta4ok00",
    "profile_picture_urls": {
      "small": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/3afcb5c896247e7ee8ada31b1c1eb8657e22241f911093acfe4ec7e97a3a959a"
    },
    "is_me?": false,
    "cleared": false,
    "hackerone_triager": false,
    "hacker_mediation": false
  },
  "team": {
    "id": 13,
    "url": "https://hackerone.com/security",
    "handle": "security",
    "profile_picture_urls": {
      "small": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/3afcb5c896247e7ee8ada31b1c1eb8657e22241f911093acfe4ec7e97a3a959a",
      "medium": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
    },
    "permissions": [],
    "submission_state": "open",
    "default_currency": "usd",
    "awards_miles": false,
    "offers_bounties": true,
    "state": "public_mode",
    "only_cleared_hackers": false,
    "profile": {
      "name": "HackerOne",
      "twitter_handle": "Hacker0x01",
      "website": "https://hackerone.com",
      "about": "Vulnerability disclosure should be safe, transparent, and rewarding."
    }
  },
  "has_bounty?": true,
  "in_validation?": false,
  "rejected_anc_report_that_can_be_sent_back_to_anc_triagers?": false,
  "can_view_team": true,
  "is_external_bug": false,
  "is_published": false,
  "is_participant": false,
  "stage": 4,
  "public": true,
  "visibility": "full",
  "cve_ids": [],
  "singular_disclosure_disabled": false,
  "disclosed_at": "2019-12-03T17:00:22.005Z",
  "bug_reporter_agreed_on_going_public_at": null,
  "team_member_agreed_on_going_public_at": "2019-12-03T17:00:12.269Z",
  "comments_closed?": false,
  "facebook_team?": false,
  "team_private?": false,
  "vulnerability_information": "**Summary:**\nYou are disclose for me you session\n**Description:**\nyou are gevi me your session on last report\nI am can use your session(sorry)\n███\n████████\n█████████\n\n## Impact\n\nHackerOneStaff Access, i can read all reports @security and more program",
  "vulnerability_information_html": "<p><strong>Summary:</strong><br>\nYou are disclose for me you session<br>\n<strong>Description:</strong><br>\nyou are gevi me your session on last report<br>\nI am can use your session(sorry)<br>\n███<br>\n████████<br>\n█████████</p>\n\n<h2 id=\"impact\">Impact</h2>\n\n<p>HackerOneStaff Access, i can read all reports <a href=\"/security\">@security</a> and more program</p>\n",
  "bounty_amount": "20000.0",
  "formatted_bounty": "$20,000",
  "weakness": {
    "id": 27,
    "name": "Improper Authentication - Generic"
  },
  "original_report_id": null,
  "original_report_url": null,
  "attachments": [],
  "allow_singular_disclosure_at": "2020-01-02T17:00:12.378Z",
  "allow_singular_disclosure_after": -14325911.759449996,
  "singular_disclosure_allowed": true,
  "vote_count": 1362,
  "voters": [
    "iv1",
    "physuru",
    "ri0-",
    "0xt4144t",
    "arif_y",
    "k0z3r0",
    "a_null",
    "jukra",
    "mvalle",
    "rupeshdubey",
    "and 1352 more..."
  ],
  "severity": {
    "rating": "high",
    "score": 8.3,
    "author_type": "Team",
    "metrics": {
      "attack_vector": "network",
      "attack_complexity": "high",
      "privileges_required": "none",
      "user_interaction": "required",
      "scope": "changed",
      "confidentiality": "high",
      "integrity": "high",
      "availability": "high"
    }
  },
  "structured_scope": {
    "databaseId": 3,
    "asset_type": "URL",
    "asset_identifier": "https://hackerone.com",
    "max_severity": "critical"
  },
  "abilities": {
    "assignable_team_members": [],
    "assignable_team_member_groups": []
  },
  "pentest_id": null,
  "can_edit_custom_fields_attributes": false,
  "activities": [
    {
      "id": 6390330,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ReportTitleUpdated",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-24T13:11:26.479Z",
      "updated_at": "2019-11-26T23:03:52.146Z",
      "additional_data": {
        "old_title": "██████████",
        "new_title": "█████████"
      },
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390338,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "████████\n█████",
      "markdown_message": "<p>████████<br>\n█████</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T13:13:46.613Z",
      "updated_at": "2019-11-26T21:38:00.674Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390601,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "i found what is you can edit private program ( for test ) I have not changed anything and not used , all for the sake of hacking",
      "markdown_message": "<p>i found what is you can edit private program ( for test ) I have not changed anything and not used , all for the sake of hacking</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T14:30:35.449Z",
      "updated_at": "2019-11-24T14:30:35.449Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390724,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugNeedsMoreInfo",
      "message": "In what report was the token disclosed?\n",
      "markdown_message": "<p>In what report was the token disclosed?</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:08:42.776Z",
      "updated_at": "2019-11-24T15:08:42.776Z",
      "actor": {
        "username": "ktistai",
        "cleared": false,
        "url": "/ktistai",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": true,
        "hackerone_employee": null
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390739,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugNew",
      "message": " █████ here, ██████████",
      "markdown_message": "<p>█████ here, ██████████</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:12:33.419Z",
      "updated_at": "2019-11-26T23:06:23.131Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390741,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "If you need Proof, I can write a message ███.",
      "markdown_message": "<p>If you need Proof, I can write a message ███.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:13:14.215Z",
      "updated_at": "2019-11-26T23:06:50.985Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390742,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugNeedsMoreInfo",
      "message": "Can you check if it's still working? ",
      "markdown_message": "<p>Can you check if it&#39;s still working? </p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:14:06.181Z",
      "updated_at": "2019-11-24T15:14:06.181Z",
      "actor": {
        "username": "ktistai",
        "cleared": false,
        "url": "/ktistai",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": true,
        "hackerone_employee": null
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390744,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugNew",
      "message": "Fixed, not working",
      "markdown_message": "<p>Fixed, not working</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:15:07.686Z",
      "updated_at": "2019-11-24T15:15:07.686Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390753,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "██████",
      "markdown_message": "<p>██████</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:20:39.111Z",
      "updated_at": "2019-11-26T23:05:52.866Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6390756,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "@haxta4ok00 \n\nI asked the appropriate people on how we deal with such reports and as soon as there will be more information, we will let you know. \n\nThanks, \n@ktistai",
      "markdown_message": "<p><a href=\"/haxta4ok00\">@haxta4ok00</a> </p>\n\n<p>I asked the appropriate people on how we deal with such reports and as soon as there will be more information, we will let you know. </p>\n\n<p>Thanks, <br>\n<a href=\"/ktistai\">@ktistai</a></p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T15:21:39.849Z",
      "updated_at": "2019-11-24T15:21:39.849Z",
      "actor": {
        "username": "ktistai",
        "cleared": false,
        "url": "/ktistai",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/322/520/01cd21dce301646646276fd9125cffd448fbffd6_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": true,
        "hackerone_employee": null
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391025,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 thanks for reporting this so quickly, we really appreciate it! We're currently looking into the report and appropriate mitigations. If we have any more questions for you we'll reach out to you here. ",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> thanks for reporting this so quickly, we really appreciate it! We&#39;re currently looking into the report and appropriate mitigations. If we have any more questions for you we&#39;ll reach out to you here. </p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T17:04:47.056Z",
      "updated_at": "2019-11-24T17:04:47.056Z",
      "actor": {
        "username": "zander",
        "cleared": false,
        "url": "/zander",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/Uo6n4mYPr4yDiaaavu7F8GVK/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391569,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00,\n\nThank you for confirming you no longer have unauthorized access. As part of our investigation, we also want to make sure we have all the relevant information from you to ensure we’re capturing everything, even as we review our own logs / audit records. As such, we would appreciate your answers to a few questions to assist us.\n\n* Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.?\n  * If so, could you list these programs?\n\n* Did you provide any of this information to other people outside of your report submission?\n\n* Have you made mention of this issue to any other people at all?\n\n* Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?\n\n* Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?\n\n* Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?\n\n* Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?\n\nAgain, thank you so much for responsibly reporting this issue to us. We really do appreciate it, and we thank you for your assistance with our investigation.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a>,</p>\n\n<p>Thank you for confirming you no longer have unauthorized access. As part of our investigation, we also want to make sure we have all the relevant information from you to ensure we’re capturing everything, even as we review our own logs / audit records. As such, we would appreciate your answers to a few questions to assist us.</p>\n\n<ul>\n<li>\n<p>Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.?</p>\n\n<ul>\n<li>If so, could you list these programs?</li>\n</ul>\n</li>\n<li><p>Did you provide any of this information to other people outside of your report submission?</p></li>\n<li><p>Have you made mention of this issue to any other people at all?</p></li>\n<li><p>Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?</p></li>\n<li><p>Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?</p></li>\n<li><p>Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?</p></li>\n<li><p>Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?</p></li>\n</ul>\n\n<p>Again, thank you so much for responsibly reporting this issue to us. We really do appreciate it, and we thank you for your assistance with our investigation.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T21:22:33.820Z",
      "updated_at": "2019-11-24T21:22:33.820Z",
      "actor": {
        "username": "reed",
        "cleared": false,
        "url": "/reed",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391605,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": " Hi @reed \n\n* Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.? If so, could you list these programs?\n\n>No, only screenshots , Yes ███ and some programs to see the access rights of this account(I do not remember the name, sorry) (Exclusively for white hacks)\n\n* Did you provide any of this information to other people outside of your report submission?\n\n>No\n\n* Have you made mention of this issue to any other people at all?\n\n>No \n\n* Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?\n\n>No , Did not do any actions, did not add participants and did not pay remuneration. Only read-only .\n\n* Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?\n\n>Only was screenshots, I didn't export the reports. I don't quite understand how I can prove to you that I deleted all the screenshots ? I will of course remove them as you ask\n\n* Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?\n\n>Again. I do not know how to prove it to you, but they are not present, I did not make copies and export reports\n\n* Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?\n\n>On this moment until nope. But I wonder, ██████████?\n\nThanks for the answer and this report only white hacks \nSorry i bad speak english\nI hope you understand me\nThank you,haxta4ok00",
      "markdown_message": "<p>Hi <a href=\"/reed\">@reed</a> </p>\n\n<ul>\n<li>Are there things outside of the screenshots you provided that you looked at? Specifically, did you review any specific programs, reports, etc.? If so, could you list these programs?</li>\n</ul>\n\n<blockquote>\n<p>No, only screenshots , Yes ███ and some programs to see the access rights of this account(I do not remember the name, sorry) (Exclusively for white hacks)</p>\n</blockquote>\n\n<ul>\n<li>Did you provide any of this information to other people outside of your report submission?</li>\n</ul>\n\n<blockquote>\n<p>No</p>\n</blockquote>\n\n<ul>\n<li>Have you made mention of this issue to any other people at all?</li>\n</ul>\n\n<blockquote>\n<p>No </p>\n</blockquote>\n\n<ul>\n<li>Can you confirm if you took any actions at all outside of viewing data? As in, did you perform any actions (pay bounties, modify program details, add users, etc.)?</li>\n</ul>\n\n<blockquote>\n<p>No , Did not do any actions, did not add participants and did not pay remuneration. Only read-only .</p>\n</blockquote>\n\n<ul>\n<li>Can you please delete all screenshots, exports, etc. that you may have captured as part of your report submission and send us a confirmation in this report once complete?</li>\n</ul>\n\n<blockquote>\n<p>Only was screenshots, I didn&#39;t export the reports. I don&#39;t quite understand how I can prove to you that I deleted all the screenshots ? I will of course remove them as you ask</p>\n</blockquote>\n\n<ul>\n<li>Can you confirm that you have no other copies of vulnerability data that was stored on your computer, such as proxy logs, browser history, and any other screenshots or data exports?</li>\n</ul>\n\n<blockquote>\n<p>Again. I do not know how to prove it to you, but they are not present, I did not make copies and export reports</p>\n</blockquote>\n\n<ul>\n<li>Lastly, do you have any other questions we can answer for you or important information to share with us related to this report?</li>\n</ul>\n\n<blockquote>\n<p>On this moment until nope. But I wonder, ██████████?</p>\n</blockquote>\n\n<p>Thanks for the answer and this report only white hacks <br>\nSorry i bad speak english<br>\nI hope you understand me<br>\nThank you,haxta4ok00</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T21:53:21.608Z",
      "updated_at": "2019-11-26T23:08:18.238Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391652,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00,\n\nMuch appreciated for the responses. Especially thank you for confirming your removal of all screenshots and other data you may have downloaded as part of your report submission.\n\nWe can confirm that ██████ uses 2FA via SAML. That is, the built-in HackerOne 2FA functionality is not used, as our identity provider handles 2FA itself. Authentication to the HackerOne Platform is federated from our identity provider to HackerOne via SAML.\n\nAgain, thanks for reporting this to us. We'll be in touch soon on next steps.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a>,</p>\n\n<p>Much appreciated for the responses. Especially thank you for confirming your removal of all screenshots and other data you may have downloaded as part of your report submission.</p>\n\n<p>We can confirm that ██████ uses 2FA via SAML. That is, the built-in HackerOne 2FA functionality is not used, as our identity provider handles 2FA itself. Authentication to the HackerOne Platform is federated from our identity provider to HackerOne via SAML.</p>\n\n<p>Again, thanks for reporting this to us. We&#39;ll be in touch soon on next steps.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T22:33:44.797Z",
      "updated_at": "2019-11-26T23:09:01.122Z",
      "actor": {
        "username": "reed",
        "cleared": false,
        "url": "/reed",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391654,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @reed -- Thanks for answer",
      "markdown_message": "<p>Hi <a href=\"/reed\">@reed</a> -- Thanks for answer</p>\n",
      "automated_response": false,
      "created_at": "2019-11-24T22:35:06.445Z",
      "updated_at": "2019-11-24T22:35:06.445Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391736,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ChangedScope",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-24T23:59:19.098Z",
      "updated_at": "2019-11-24T23:59:19.098Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "old_scope": "None",
      "new_scope": "https://hackerone.com",
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391766,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ReportSeverityUpdated",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-25T00:22:42.098Z",
      "updated_at": "2019-11-25T00:22:42.098Z",
      "additional_data": {
        "old_severity": "Critical",
        "new_severity": "High (8.3)"
      },
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391767,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - thanks again for bringing this to our attention. We’re still actively working on this, primarily preparing communications to affected customers and a root cause analysis. As part of that, we’re updating the severity according to the impact of the vulnerability. At this point, we have not made a decision on the bounty amount, and it may be different from what our bounty table indicates. See below for our reasoning behind the corrected severity, which with the environmental score of the affected asset, brings the CVSS to 8.3 (High).\n\n**Attack Vector: Network** - The vulnerability was exploitable from anywhere in case the attacker had a copy of an active session cookie.\n\n**Attack Complexity: High** - The semi-feasible attack scenario is for a HackerOne employee to share an active session cookie. Carrying this out is beyond an attacker’s control, which is why the Attack Complexity to High.\n\n**Privileges Required: None** - The attacker does not need to be authenticated to exploit the vulnerability.\n\n**User Interaction: Required** - The victim needs to share the session cookie, making User Interaction Required for the vulnerability to be exploited.\n\n**Scope: Changed** - Due to the nature of the data that could’ve been accessed, systems other than hackerone.com may be accessible. Scope includes any customer assets because of the vulnerability information that could have been accessed.\n\n**Confidentiality: High** - Vulnerability information could be accessed when the attacker has an active session cookie of the HackerOne employee. Any security vulnerability that affects vulnerability information automatically bumps Confidentiality to High.\n\n**Integrity: High** - The HackerOne employee had sufficient privileges to make updates to programs they were managing, causing Impact to being set to High.\n\n**Availability: High** - Due to the HackerOne employee’s permissions, they could suspend submissions for a number of HackerOne customers. Although this technically doesn’t affect the availability of the platform, the team ended up going with a High impact because submissions are a business critical process on the platform.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - thanks again for bringing this to our attention. We’re still actively working on this, primarily preparing communications to affected customers and a root cause analysis. As part of that, we’re updating the severity according to the impact of the vulnerability. At this point, we have not made a decision on the bounty amount, and it may be different from what our bounty table indicates. See below for our reasoning behind the corrected severity, which with the environmental score of the affected asset, brings the CVSS to 8.3 (High).</p>\n\n<p><strong>Attack Vector: Network</strong> - The vulnerability was exploitable from anywhere in case the attacker had a copy of an active session cookie.</p>\n\n<p><strong>Attack Complexity: High</strong> - The semi-feasible attack scenario is for a HackerOne employee to share an active session cookie. Carrying this out is beyond an attacker’s control, which is why the Attack Complexity to High.</p>\n\n<p><strong>Privileges Required: None</strong> - The attacker does not need to be authenticated to exploit the vulnerability.</p>\n\n<p><strong>User Interaction: Required</strong> - The victim needs to share the session cookie, making User Interaction Required for the vulnerability to be exploited.</p>\n\n<p><strong>Scope: Changed</strong> - Due to the nature of the data that could’ve been accessed, systems other than hackerone.com may be accessible. Scope includes any customer assets because of the vulnerability information that could have been accessed.</p>\n\n<p><strong>Confidentiality: High</strong> - Vulnerability information could be accessed when the attacker has an active session cookie of the HackerOne employee. Any security vulnerability that affects vulnerability information automatically bumps Confidentiality to High.</p>\n\n<p><strong>Integrity: High</strong> - The HackerOne employee had sufficient privileges to make updates to programs they were managing, causing Impact to being set to High.</p>\n\n<p><strong>Availability: High</strong> - Due to the HackerOne employee’s permissions, they could suspend submissions for a number of HackerOne customers. Although this technically doesn’t affect the availability of the platform, the team ended up going with a High impact because submissions are a business critical process on the platform.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T00:22:55.702Z",
      "updated_at": "2019-11-25T00:22:55.702Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391773,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert -- You may be right about CVSS, but aren't actions on behalf of H1Staff critical. For example, read reports, add members to private programs, send bounties, etc.?",
      "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- You may be right about CVSS, but aren&#39;t actions on behalf of H1Staff critical. For example, read reports, add members to private programs, send bounties, etc.?</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T00:30:31.231Z",
      "updated_at": "2019-11-25T00:30:31.231Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391778,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - yup, but that's subjective. We've updated CVSS to capture the objective measurement of impact of the vulnerability. The business impact, which is subjective to some extend, will be discussed when we decide on a bounty amount. Thanks for your understanding and patience!",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - yup, but that&#39;s subjective. We&#39;ve updated CVSS to capture the objective measurement of impact of the vulnerability. The business impact, which is subjective to some extend, will be discussed when we decide on a bounty amount. Thanks for your understanding and patience!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T00:37:03.130Z",
      "updated_at": "2019-11-25T00:37:03.130Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391782,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "@jobert Thanks for the answer",
      "markdown_message": "<p><a href=\"/jobert\">@jobert</a> Thanks for the answer</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T00:38:13.689Z",
      "updated_at": "2019-11-25T00:38:13.689Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6391827,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ReportTitleUpdated",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-25T01:00:19.901Z",
      "updated_at": "2019-11-26T23:03:31.310Z",
      "additional_data": {
        "old_title": "█████████",
        "new_title": "Account takeover via leaked session token"
      },
      "actor": {
        "username": "bencode",
        "cleared": false,
        "url": "/bencode",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/013/117/ddaa1da4e004e1234c6857c42f9bfa8df85b5ccf_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6401007,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugTriaged",
      "message": "Hi @haxta4ok00 - we're moving this to triaged so it's easier for us to track. Last night, we've sent customer notifications about the data that was accessed by you. We'll keep you posted throughout the process. Thanks for being so responsive throughout the process so far, it's much appreciated.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - we&#39;re moving this to triaged so it&#39;s easier for us to track. Last night, we&#39;ve sent customer notifications about the data that was accessed by you. We&#39;ll keep you posted throughout the process. Thanks for being so responsive throughout the process so far, it&#39;s much appreciated.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T17:25:07.923Z",
      "updated_at": "2019-11-25T17:25:07.923Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6401164,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert-- thanks for the answer",
      "markdown_message": "<p>Hi <a href=\"/jobert--\">@jobert--</a> thanks for the answer</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T17:52:59.114Z",
      "updated_at": "2019-11-25T17:52:59.114Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6402403,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - something came up that we hadn't asked you yet. We didn't find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us? Thanks!",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - something came up that we hadn&#39;t asked you yet. We didn&#39;t find it necessary for you to have opened all the reports and pages in order to validate you had access to the account. Would you mind explaining why you did so to us? Thanks!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T18:57:35.495Z",
      "updated_at": "2019-11-25T18:57:35.495Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6402721,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert -- I did it to show the impact. I didn't mean any harm by it.I reported it to you at once. I was not sure that after the token substitution I would own all the rights.\n\nI apologize if I did anything wrong. But it was just a white hack",
      "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- I did it to show the impact. I didn&#39;t mean any harm by it.I reported it to you at once. I was not sure that after the token substitution I would own all the rights.</p>\n\n<p>I apologize if I did anything wrong. But it was just a white hack</p>\n",
      "automated_response": false,
      "created_at": "2019-11-25T19:21:04.094Z",
      "updated_at": "2019-11-25T19:21:04.094Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6405556,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ReportTitleUpdated",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-25T23:51:15.792Z",
      "updated_at": "2019-11-25T23:51:15.792Z",
      "additional_data": {
        "old_title": "Account takeover via leaked session token",
        "new_title": "Account takeover via leaked session cookie"
      },
      "actor": {
        "username": "reed",
        "cleared": false,
        "url": "/reed",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/003/132/66d7eadcea16b878bb67bfd697b9542250a801a7_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6411489,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jober , @reed , @bencode , @zander -- May I add one remark for you?",
      "markdown_message": "<p>Hi <a href=\"/jober\">@jober</a> , <a href=\"/reed\">@reed</a> , <a href=\"/bencode\">@bencode</a> , <a href=\"/zander\">@zander</a> -- May I add one remark for you?</p>\n",
      "automated_response": false,
      "created_at": "2019-11-26T13:32:57.293Z",
      "updated_at": "2019-11-26T13:32:57.293Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6414341,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - of course, go for it! No need to ask.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - of course, go for it! No need to ask.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-26T17:55:22.496Z",
      "updated_at": "2019-11-26T17:55:22.496Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6414443,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert -- thanks for the answer!\n\n* Three years ago I mentioned such an attack, but it was theoretical and I was not listened to( here #163381 I wrote `in theory find this in the future`). If this will help the I am systemic moderator on one of forums on security. And we protected ourselves from such attacks by binding the session to the IP address at the entrance. We also made basic authorization for access to private sections. Perhaps this will help you.\n\n* I understand, that saw data which should not was see, but this was only hack interest in white purposes, I wanted to watch and show you to prejudice consequence of this can lead ( I've always been taught to write the full impact that can be) . It was a happy white hacking for me.\n\n* Please do not scold █████ he's one of the best staff that help to hackerone\n\nAnd sorry if I that the poorly translated, hope you me will understand. Thanks @jobert again.",
      "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- thanks for the answer!</p>\n\n<ul>\n<li><p>Three years ago I mentioned such an attack, but it was theoretical and I was not listened to( here <a href=\"/reports/163381\">#163381</a> I wrote <code>in theory find this in the future</code>). If this will help the I am systemic moderator on one of forums on security. And we protected ourselves from such attacks by binding the session to the IP address at the entrance. We also made basic authorization for access to private sections. Perhaps this will help you.</p></li>\n<li><p>I understand, that saw data which should not was see, but this was only hack interest in white purposes, I wanted to watch and show you to prejudice consequence of this can lead ( I&#39;ve always been taught to write the full impact that can be) . It was a happy white hacking for me.</p></li>\n<li><p>Please do not scold █████ he&#39;s one of the best staff that help to hackerone</p></li>\n</ul>\n\n<p>And sorry if I that the poorly translated, hope you me will understand. Thanks <a href=\"/jobert\">@jobert</a> again.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-26T18:12:12.946Z",
      "updated_at": "2019-11-26T23:12:12.074Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6414854,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - thanks for that, it's much appreciated. No need to worry about ██████████ this was a human error that could've happened to anyone. There won't be any consequences for them. This became a bigger incident due to the amount of data that you accessed, not because it happened in the first place.\n\nAs for your first remark: yesterday we've released an update that limits HackerOne employees and HackerOne Security Analyst sessions to the IP address that they've started the session with. This would've prevented the incident. We're postponing the rollout to all users due to people having legitimate use cases for using multiple IP addresses (e.g. ISPs with DHCP). We're also planning to roll out a number of smaller changes, such as warning the user when a comment seems to contain sensitive information and clarification in our policy about what to do when someone gains access to other people their account.\n\nWe'll keep you posted!",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - thanks for that, it&#39;s much appreciated. No need to worry about ██████████ this was a human error that could&#39;ve happened to anyone. There won&#39;t be any consequences for them. This became a bigger incident due to the amount of data that you accessed, not because it happened in the first place.</p>\n\n<p>As for your first remark: yesterday we&#39;ve released an update that limits HackerOne employees and HackerOne Security Analyst sessions to the IP address that they&#39;ve started the session with. This would&#39;ve prevented the incident. We&#39;re postponing the rollout to all users due to people having legitimate use cases for using multiple IP addresses (e.g. ISPs with DHCP). We&#39;re also planning to roll out a number of smaller changes, such as warning the user when a comment seems to contain sensitive information and clarification in our policy about what to do when someone gains access to other people their account.</p>\n\n<p>We&#39;ll keep you posted!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-26T19:02:42.541Z",
      "updated_at": "2019-11-26T23:11:55.373Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6414896,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hey @jobert -- Thanks for the answer!\n\n> No need to worry about ████ this was a human error that could've happened to anyone.\n\nNice!\n\n>As for your first remark: yesterday we've released an update that limits HackerOne employees and HackerOne Security Analyst sessions to the IP address that they've started the session with. This would've prevented the incident\n\nNice, good idea",
      "markdown_message": "<p>Hey <a href=\"/jobert\">@jobert</a> -- Thanks for the answer!</p>\n\n<blockquote>\n<p>No need to worry about ████ this was a human error that could&#39;ve happened to anyone.</p>\n</blockquote>\n\n<p>Nice!</p>\n\n<blockquote>\n<p>As for your first remark: yesterday we&#39;ve released an update that limits HackerOne employees and HackerOne Security Analyst sessions to the IP address that they&#39;ve started the session with. This would&#39;ve prevented the incident</p>\n</blockquote>\n\n<p>Nice, good idea</p>\n",
      "automated_response": false,
      "created_at": "2019-11-26T19:08:58.761Z",
      "updated_at": "2019-11-26T23:11:55.369Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6416693,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ReportVulnerabilityTypesUpdated",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-11-26T23:26:27.292Z",
      "updated_at": "2019-11-26T23:26:27.292Z",
      "additional_data": {
        "added_weaknesses": [
          {
            "id": 27,
            "name": "Improper Authentication - Generic"
          }
        ],
        "removed_weaknesses": []
      },
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6417746,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BountyAwarded",
      "message": "Hi @haxta4ok00 -- we’ve decided to award $20,000 for making us aware of the disclosed session cookie! In a couple of hours, the Root Cause Analysis (RCA) will be shared with the affected customers. The RCA will be posted to this report as a summary early next week.\n\nDuring our Incident Response process, we noticed that a few reports were accessed after you submitted the report to us. Although we understand why you did so, we’d like to stress that this behavior may disqualify you from a bounty in the future. In this particular case, we correlated the page views that were made after the submission with your comments providing more information to us to substantiate your claims. It also seemed that no information was withheld by you in this report.\n\nTo make it clear on how we believe these situations should be handled by hackers, [we’ve added a clarifying section to our policy](https://hackerone.com/security/policy_versions?change=3624684). We urge you to review this section, which will reduce the blast radius going forward. We’d like for you to continue to be a valuable member of the community and our top hacker, but for that, we require you to be mindful of the access that particular vulnerabilities give you. Being responsible and understanding the potential consequences of your actions is very important in this field. We hope you understand and will take this into consideration going forward.\n\nWe’re planning to publicly disclose this report on December 3, 2019 at 9:00am PST.\n\nWe look forward to receiving more security vulnerabilities from you in the future. Good luck and happy hacking!",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> -- we’ve decided to award $20,000 for making us aware of the disclosed session cookie! In a couple of hours, the Root Cause Analysis (RCA) will be shared with the affected customers. The RCA will be posted to this report as a summary early next week.</p>\n\n<p>During our Incident Response process, we noticed that a few reports were accessed after you submitted the report to us. Although we understand why you did so, we’d like to stress that this behavior may disqualify you from a bounty in the future. In this particular case, we correlated the page views that were made after the submission with your comments providing more information to us to substantiate your claims. It also seemed that no information was withheld by you in this report.</p>\n\n<p>To make it clear on how we believe these situations should be handled by hackers, <a href=\"https://hackerone.com/security/policy_versions?change=3624684\">we’ve added a clarifying section to our policy</a>. We urge you to review this section, which will reduce the blast radius going forward. We’d like for you to continue to be a valuable member of the community and our top hacker, but for that, we require you to be mindful of the access that particular vulnerabilities give you. Being responsible and understanding the potential consequences of your actions is very important in this field. We hope you understand and will take this into consideration going forward.</p>\n\n<p>We’re planning to publicly disclose this report on December 3, 2019 at 9:00am PST.</p>\n\n<p>We look forward to receiving more security vulnerabilities from you in the future. Good luck and happy hacking!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-27T05:46:27.982Z",
      "updated_at": "2019-11-27T05:46:27.982Z",
      "actor": {
        "url": "/security",
        "ibb": false,
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "profile": {
          "name": "HackerOne"
        }
      },
      "bounty_amount": "20000.0",
      "bounty_currency": "usd",
      "bonus_amount": "0.0",
      "genius_execution_id": null,
      "team_handle": "security",
      "collaborator": {
        "username": "haxta4ok00",
        "url": "/haxta4ok00"
      }
    },
    {
      "id": 6417747,
      "is_internal": false,
      "editable": false,
      "type": "Activities::SwagAwarded",
      "message": "We're throwing in some swag, too. Thanks, @haxta4ok00!",
      "markdown_message": "<p>We&#39;re throwing in some swag, too. Thanks, <a href=\"/haxta4ok00\">@haxta4ok00</a>!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-27T05:46:54.641Z",
      "updated_at": "2019-11-27T05:46:54.641Z",
      "actor": {
        "url": "/security",
        "ibb": false,
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/000/013/fa942b9b1cbf4faf37482bf68458e1195aab9c02_original.png/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "profile": {
          "name": "HackerOne"
        }
      },
      "reporter": {
        "username": "haxta4ok00",
        "url": "/haxta4ok00"
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6417756,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert -- Thanks for the bounty! This is a very large sum for me. \n\nMy PayPal has in my country a certain limit per month, if I can not get the whole amount at once, it will be possible to divide it into several parts in the future?\nThansk!",
      "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- Thanks for the bounty! This is a very large sum for me. </p>\n\n<p>My PayPal has in my country a certain limit per month, if I can not get the whole amount at once, it will be possible to divide it into several parts in the future?<br>\nThansk!</p>\n",
      "automated_response": false,
      "created_at": "2019-11-27T05:53:23.213Z",
      "updated_at": "2019-11-27T05:53:23.213Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6417763,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @haxta4ok00 - yes, e-mail support@hackerone.com so we can sort that out! Please reference this ticket to give them the right context.",
      "markdown_message": "<p>Hi <a href=\"/haxta4ok00\">@haxta4ok00</a> - yes, e-mail <a title=\"support@hackerone.com\" href=\"mailto:support@hackerone.com\" rel=\"nofollow noopener noreferrer\">support@hackerone.com</a> so we can sort that out! Please reference this ticket to give them the right context.</p>\n",
      "automated_response": false,
      "created_at": "2019-11-27T05:59:07.406Z",
      "updated_at": "2019-11-27T05:59:07.406Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6417766,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @jobert -- ohh, ok, thank you for the answer, and one more request.\n\nCould you check two more of my reports, thank you?",
      "markdown_message": "<p>Hi <a href=\"/jobert\">@jobert</a> -- ohh, ok, thank you for the answer, and one more request.</p>\n\n<p>Could you check two more of my reports, thank you?</p>\n",
      "automated_response": false,
      "created_at": "2019-11-27T06:02:45.100Z",
      "updated_at": "2019-11-27T06:02:45.100Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6452536,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "> Could you check two more of my reports, thank you?\n\nYep, we'll get back to you in the other reports.",
      "markdown_message": "<blockquote>\n<p>Could you check two more of my reports, thank you?</p>\n</blockquote>\n\n<p>Yep, we&#39;ll get back to you in the other reports.</p>\n",
      "automated_response": false,
      "created_at": "2019-12-02T23:47:44.756Z",
      "updated_at": "2019-12-02T23:47:44.756Z",
      "actor": {
        "username": "bencode",
        "cleared": false,
        "url": "/bencode",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/013/117/ddaa1da4e004e1234c6857c42f9bfa8df85b5ccf_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6452986,
      "is_internal": false,
      "editable": false,
      "type": "Activities::Comment",
      "message": "Hi @bencode -- Thanks for the answer!",
      "markdown_message": "<p>Hi <a href=\"/bencode\">@bencode</a> -- Thanks for the answer!</p>\n",
      "automated_response": false,
      "created_at": "2019-12-03T03:27:45.628Z",
      "updated_at": "2019-12-03T03:27:45.628Z",
      "actor": {
        "username": "haxta4ok00",
        "cleared": false,
        "url": "/haxta4ok00",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/000/049/175/8449afdd3403f4de00b34719ee09823bad1c0a06_original.jpg/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": false
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6459862,
      "is_internal": false,
      "editable": false,
      "type": "Activities::BugResolved",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-12-03T17:00:00.942Z",
      "updated_at": "2019-12-03T17:00:00.942Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "reporter": {
        "username": "haxta4ok00",
        "url": "/haxta4ok00"
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6459865,
      "is_internal": false,
      "editable": false,
      "type": "Activities::AgreedOnGoingPublic",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-12-03T17:00:12.298Z",
      "updated_at": "2019-12-03T17:00:12.298Z",
      "first_to_agree": true,
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    },
    {
      "id": 6459866,
      "is_internal": false,
      "editable": false,
      "type": "Activities::ManuallyDisclosed",
      "message": "",
      "markdown_message": "",
      "automated_response": false,
      "created_at": "2019-12-03T17:00:21.921Z",
      "updated_at": "2019-12-03T17:00:21.921Z",
      "actor": {
        "username": "jobert",
        "cleared": true,
        "url": "/jobert",
        "profile_picture_urls": {
          "medium": "https://profile-photos.hackerone-user-content.com/variants/ht4b9SmcYNqmpbyCFXd7cxHB/eb31823a4cc9f6b6bb4db930ffdf512533928a68a4255fb50a83180281a60da5"
        },
        "hackerone_triager": false,
        "hackerone_employee": true
      },
      "genius_execution_id": null,
      "team_handle": "security"
    }
  ],
  "activity_page_count": 1,
  "activity_page_number": 1,
  "summaries": [
    {
      "id": 19060,
      "category": "team",
      "content": "# Incident Report | 2019-11-24 Account Takeover via Disclosed Session Cookie\n*Last updated: 2019-11-27*\n\n## Issue Summary\nOn November 24, 2019 at 13:08 UTC, HackerOne was notified through the HackerOne Bug Bounty Program by a HackerOne community member (“hacker”) that they had accessed a HackerOne Security Analyst’s HackerOne account. A session cookie was disclosed due to a human error, which led to the hacker being able to access the account. The session cookie was revoked at 15:11 UTC, blocking all unauthorized access to the account.\n\nThe technical investigation finished at 21:27 UTC, concluding that there was no malicious intent and that all copies of potentially sensitive information were deleted.\n\n## Timeline\n\n| Date | Time (UTC)| Action |\n|---|---|---|\n| 2019-11-24 | 12:48 | HackerOne Security Analyst’s session cookie was posted on a HackerOne report. |\n| 2019-11-24 | 13:08 | HackerOne received a report through its bug bounty program that the session cookie could be used to access sensitive information. |\n| 2019-11-24 | 15:08 | A HackerOne Security Analyst began triaging the report.  |\n| 2019-11-24 | 15:11 | The session cookie was revoked. |\n| 2019-11-24 | 16:07 | HackerOne’s Incident Response team started an investigation. |\n| 2019-11-24 | 21:27 | HackerOne concluded technical investigation. |\n| 2019-11-25 | 08:49 | Impacted customers were alerted that their information was viewable to the hacker who submitted the vulnerability. |\n| 2019-11-26 | 01:58 | A change was deployed restricting HackerOne employee and HackerOne Security Analyst sessions to only be accessible from the originating IP address. This mitigates similar incidents in the future. |\n\n## Root Cause\nHackerOne triages incoming reports for HackerOne’s own bug bounty program. On November 24, 2019, a Security Analyst tried to reproduce a submission to HackerOne’s program, which failed. The Security Analyst replied to the hacker, accidentally including one of their own valid session cookies.\n\n*Why was a cookie included?*\nWhen a Security Analyst fails to reproduce a potentially valid security vulnerability, they go back and forth with the hacker to better understand the report. During this dialogue, Security Analysts may include steps they’ve taken in their response to the report, including HTTP requests that they made to reproduce. In this particular case, parts of a cURL command, copied from a browser console, were not removed before posting it to the report, disclosing the session cookie.\n\n*Why was the hacker able to access the account?*\nSession cookies are tied to a particular application, in this case hackerone.com. The application won’t block access when a session cookie gets reused in another location. This was a known risk. As many of HackerOne’s users work from mobile connections and through proxies, blocking access would degrade the user experience for those users. Due to the entropy of session cookies and in-depth defenses such as HackerOne’s strict [Content Security Policy](https://en.wikipedia.org/wiki/Content_Security_Policy), HackerOne had not prioritized any additional defenses that limit a session cookie’s ability to be used in a separate browser.\n\n*Why does a session cookie grant access to reports?*\nHackerOne offers a number of additional tools on the platform for Security Analysts to work through security reports. In a normal situation, the Security Analysts go through multi-factor Single Sign-On (SSO) to obtain a valid session cookie for their work. Because a live session cookie was obtained, all platform features were available, which therefore granted access to a number of customers’ reports. This was limited to the customer programs that this particular Security Analyst supports.\n\n*Why were reports exposed for programs that don’t use HackerOne Triage?*\nHackerOne offers an optional service called [Human-Augmented Signal](https://docs.hackerone.com/programs/human-augmented-signal.html) (HAS). HackerOne Security Analysts have access to a separate HAS Inbox on their account where reports can be inspected before they’re forwarded to the customer. A number of reports from this particular Inbox were accessed.\n\n*Why did it take two hours to notice the report?*\nHackerOne aims to reply within 24 hours to any submission, including over the weekend. For high and critical severity vulnerabilities, HackerOne tries to respond within a couple of hours. The report to HackerOne’s bug bounty program was submitted on Sunday morning at 05:00am PST (where the majority of HackerOne’s security team resides). For critical submissions, HackerOne’s security team automatically receives a notification on Slack. This works during business hours but is unreliable over the weekend. Security Analysts who work over the weekend noticed the report two hours after the submission, after which they immediately followed Incident Response procedures.\n\n## Resolution and Recovery\n\nThe session cookie was revoked by HackerOne on November 24, 2019 at 15:11 UTC, two hours after it was shared, three minutes after the report was opened for triage. Revoking the session cookie rendered it useless to anyone using it. The subsequent investigation focused on affected customers, vulnerability data, intent, communication, and preventative measures, which concluded on November 26, 2019.\n\nHackerOne audited existing comments to see if other session cookies were leaked in the past. This did not yield any results.\n\nThe severity of the report was determined to be high based on HackerOne’s environmental score for the selected asset and CVSS 3.0 base metrics (*CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/CR:H/IR:H/AR:H*). The minimum bounty award for a high severity vulnerability (based on CVSS) on hackerone.com is currently set to $7,500. A $7,500 reward for disclosing this to HackerOne would mean that HackerOne would award the same amount regardless of which user’s account was compromised. The team looked into the amount of sensitive information that could have been accessed by the account and took that under advisement when deciding on the bounty amount. This led to the decision to treat the submission as a critical vulnerability and award a $20,000 bounty.\n\n## Vulnerability Impact on Data\n\nSensitive information of multiple objects was exposed. During the timeframe the hacker had access, three different features were used to access sensitive information. By default, all inboxes only download the minimal amount of data, such as title, state, severity, and assignee, so the user can view the user interface. Vulnerability information is only disclosed when the user selects a report from the user interface.\n\nIn an effort to simplify what data was accessed, HackerOne mapped the access of features to the information disclosed as follows:\n\n - If the hacker accessed their report via HAS Inbox, Triage Inbox, or Inbox features, the *report titles and limited metadata were viewable*\n - If the hacker used the Report View feature, the *report contents were viewable*\n\nBelow is an overview of the features and the data that was exposed in each of them. \n\n### Human-Augmented Signal (HAS) Inbox\n\nThis Inbox is used by a number of Security Analysts to block or forward submissions that are flagged by HackerOne’s backend of having a high-likelihood being noise. When the hacker accessed the page, the default view loaded up to 25 reports to show the user interface. Reports are sorted by oldest report first. The following information was loaded and displayed:\n\n| Information | Note |\n|---|---|\n| latest_activity_at | ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report. |\n| created_at | ISO 8601 formatted date/time when the report was submitted.|\n| title | The title of the report. |\n| state | Indicates whether the report is open or closed.|\n| substate | Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate). |\n| assignee (group name, username) | The group’s name or user’s username who is currently assigned to the report. |\n|reporter (username) | The reporter’s username.|\n| program (handle, name) | The program’s handle and name the report was submitted to. |\n\n### Triage Inbox\n\nThis is the Security Analyst’s main Inbox to interact with reports. When the hacker accessed the page, the default view loaded up to 100 reports to show the user interface. Reports are sorted by oldest report first. The following information was loaded and displayed:\n\n| Information | Note |\n|---|---|\n|title| The title of the report.|\n|substate|Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).|\n| assignee (group name, username) | The group’s name or user’s username who is currently assigned to the report.|\n|triage blockers (reasons, blocked by) | An object that contains the reason why a report is currently blocked on something other than the Security Analysts. |\n| program (handle, triage notes) | The program’s handle and name the report was submitted to.|\n\n### Inbox\n\nThis is the main Inbox hackers and customers use to interact with reports they’ve submitted and received. When the hacker accessed the page, the default view loaded up to 25 reports to show the user interface. Reports are sorted depending on the view that was selected. The following information was loaded and displayed:\n\n| Information | Note |\n|---|---|\n| latest_activity_at | ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report.|\n|created_at | ISO 8601 formatted date/time when the report was submitted. |\n| title | The title of the report.|\n| state | Indicates whether the report is open or closed. |\n|substate | Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).|\n|reference | Any issue tracker reference that was set on the report.|\n|reference_url|The full URL to any issue tracker’s task when set.|\n|severity_rating|Indicates the report’s severity (null, none, low, medium, high, critical).|\n|assignee (group name, username)|The group’s name or user’s username who is currently assigned to the report.|\n|reporter (username)|The reporter’s username.|\n|program (handle, name)|The program’s handle and name the report was submitted to.|\n|custom_field_attributes (name)|All custom field attributes that reports can be filtered on.|\n|assets (identifier)|All asset identifiers that reports can be filtered on.|\n|groups (name)|All team member groups associated with the program the report was submitted to.|\n|members (name, username)|All team members associated with the program the report was submitted to.|\n\n### Report View\n\nReports are viewable in all of the inboxes in order to help customers, security analysts, and hackers communicate over a vulnerability. Only a single report can be viewed in the same window at any given time. When the hacker viewed the report, the following information was loaded and displayed:\n\n| Information | Note |\n|---|---|\n| vulnerability_information|The initial description of the vulnerability provided by the reporter.|\n|comments (text, internal and to the reporter)|The comments between the reporter and the security team as well as internal comments.|\n|latest_activity_at|ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report.|\n|created_at|ISO 8601 formatted date/time when the report was submitted.|\n|title|The title of the report.|\n|state|Indicates whether the report is open or closed.|\n|substate|Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).|\n|reference|Any issue tracker reference that was set on the report.|\n|reference_url|The full URL to any issue tracker’s task when set.|\n|severity_rating|Indicates the report’s severity (null, none, low, medium, high, critical).|\n|assignee (group name, username)|The group’s name or user’s username who is currently assigned to the report.|\n|reporter (username)|The reporter’s username.|\n|program (handle, name)|The program’s handle and name the report was submitted to.|\n|custom_field_attributes (name)|All custom field attributes that reports can be filtered on.|\n|assets (identifier)|All asset identifiers that reports can be filtered on.|\n|groups (name)|All team member groups associated with the program the report was submitted to.|\n|members (name, username)|All team members associated with the program the report was submitted to.|\n|weakness|The category of vulnerability.|\n\n**Data access was limited to the access the HackerOne Security Analyst had, which does not cover HackerOne’s entire customer base. If your data was accessed during this incident, you have received a separate notification from HackerOne.**\n\n## Preventative Measures\n\nAs part of HackerOne Incident Response process, HackerOne is conducting an internal review and analysis of the incident. HackerOne is taking the following actions to address the underlying causes of issues and to help prevent future occurrence:\n\n### Short-term (completed)\n\nThese are the short term actions identified. All items have already been addressed and deployed to hackerone.com.\n\n#### Bind Sessions to IP Addresses\nThe session cookie is able to be reused on different devices. A short term mitigation of this vulnerability is to bind the user’s session to the IP address used at initial sign-in. If an attempt is made to utilize the session from a different IP address, the session is terminated.\n\nThis change was rolled out for HackerOne employees (including all HackerOne Security Analysts) on November 25, 2019.\n\n#### Block Sessions from Restricted Countries\nHackerOne restricts its employees from accessing resources from specific countries. To mitigate account takeovers, the user sessions are prevented from being used from specific restricted list of countries.\n\nThis change was rolled out for HackerOne employees (including all HackerOne Security Analysts) on November 26, 2019.\n\n#### Page on Critical Reports\nIn order to further reduce the time to notify the security team, the team has decided to move from a Slack notification to paging the on-call security person when a critical report gets submitted to the bug bounty program.\n\nThis change was implemented on November 25, 2019.\n\n#### Update Program Policy regarding Sensitive Information Access\nHackerOne has updated their bug bounty program policy to include specific actions on when a hacker may have access to a HackerOne account, sensitive keys, or sensitive data.\n\nThis change was [implemented on November 26, 2019](https://hackerone.com/security/policy_versions?change=3624684).\n\n### Mid-term (next three months)\n\n#### Detect & Redact Sensitive Data in Comments\nWhen a user is making a comment, detect possible sensitive information, such as session cookies and authentication tokens, and block submission of the comment until confirmation. Additionally, offer the user the ability to redact the sensitive from the comment automatically.\n\nThis change was implemented on December 2, 2019.\n\n#### Add Additional Logging Context\n\nWhile HackerOne was able to determine which reports were access based on the executed GraphQL queries, HackerOne is planning to improve their logging of information around data access. This will support Incident Response capabilities and allow the incident response to be performed faster.\n\n#### Bind Sessions to Devices\n\nA limitation of binding to IPs is that they change for legitimate reasons and will unauthenticate the user, creating a poor user experience. Additionally, IP addresses do not uniquely identify a user (such as with NAT), allowing malicious users to utilize the session, even if it is IP bound. To improve usability and security, HackerOne will investigate binding the session to a specific device that the user is using. Sessions bound to the device will only be usable on that device and using the session elsewhere will terminate the session.\n\n#### Improve Education for Employees\n\nIn addition to HackerOne’s current employee education programs, HackerOne will expand the security training for those who handle vulnerability reports. The training will include additional details on how to share technical reproductions and specifically avoid sharing keys, tokens, and session information.\n\n### Long-term (next twelve months)\n\n#### Overhaul Security Analyst Permission Model\nThe HackerOne Security Analysts have access to HackerOne customers’ sensitive data in order to triage incoming vulnerability reports. HackerOne has identified that HackerOne can restrict security analyst access in programs, as well as overhaul the allocation of security analysts to a more restrictive list of programs to keep these users to the least privilege required. \n\n#### Improve Education for Hackers\n\nAs the community grows, HackerOne needs to ensure that HackerOne is reinforcing the best practices in bug bounty hunting. The HackerOne Community team will look to increase hacker education around delivering proof of critical severity vulnerabilities in case sensitive information has been accessed by the hacker.\n",
      "can_view?": true,
      "can_edit?": false,
      "content_html": "<h1 id=\"incident-report-2019-11-24-account-takeover-via-disclosed-session-cookie\">Incident Report | 2019-11-24 Account Takeover via Disclosed Session Cookie</h1>\n\n<p><em>Last updated: 2019-11-27</em></p>\n\n<h2 id=\"issue-summary\">Issue Summary</h2>\n\n<p>On November 24, 2019 at 13:08 UTC, HackerOne was notified through the HackerOne Bug Bounty Program by a HackerOne community member (“hacker”) that they had accessed a HackerOne Security Analyst’s HackerOne account. A session cookie was disclosed due to a human error, which led to the hacker being able to access the account. The session cookie was revoked at 15:11 UTC, blocking all unauthorized access to the account.</p>\n\n<p>The technical investigation finished at 21:27 UTC, concluding that there was no malicious intent and that all copies of potentially sensitive information were deleted.</p>\n\n<h2 id=\"timeline\">Timeline</h2>\n\n<table>\n<thead>\n<tr>\n<th>Date</th>\n<th>Time (UTC)</th>\n<th>Action</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>2019-11-24</td>\n<td>12:48</td>\n<td>HackerOne Security Analyst’s session cookie was posted on a HackerOne report.</td>\n</tr>\n<tr>\n<td>2019-11-24</td>\n<td>13:08</td>\n<td>HackerOne received a report through its bug bounty program that the session cookie could be used to access sensitive information.</td>\n</tr>\n<tr>\n<td>2019-11-24</td>\n<td>15:08</td>\n<td>A HackerOne Security Analyst began triaging the report.</td>\n</tr>\n<tr>\n<td>2019-11-24</td>\n<td>15:11</td>\n<td>The session cookie was revoked.</td>\n</tr>\n<tr>\n<td>2019-11-24</td>\n<td>16:07</td>\n<td>HackerOne’s Incident Response team started an investigation.</td>\n</tr>\n<tr>\n<td>2019-11-24</td>\n<td>21:27</td>\n<td>HackerOne concluded technical investigation.</td>\n</tr>\n<tr>\n<td>2019-11-25</td>\n<td>08:49</td>\n<td>Impacted customers were alerted that their information was viewable to the hacker who submitted the vulnerability.</td>\n</tr>\n<tr>\n<td>2019-11-26</td>\n<td>01:58</td>\n<td>A change was deployed restricting HackerOne employee and HackerOne Security Analyst sessions to only be accessible from the originating IP address. This mitigates similar incidents in the future.</td>\n</tr>\n</tbody>\n</table>\n\n<h2 id=\"root-cause\">Root Cause</h2>\n\n<p>HackerOne triages incoming reports for HackerOne’s own bug bounty program. On November 24, 2019, a Security Analyst tried to reproduce a submission to HackerOne’s program, which failed. The Security Analyst replied to the hacker, accidentally including one of their own valid session cookies.</p>\n\n<p><em>Why was a cookie included?</em><br>\nWhen a Security Analyst fails to reproduce a potentially valid security vulnerability, they go back and forth with the hacker to better understand the report. During this dialogue, Security Analysts may include steps they’ve taken in their response to the report, including HTTP requests that they made to reproduce. In this particular case, parts of a cURL command, copied from a browser console, were not removed before posting it to the report, disclosing the session cookie.</p>\n\n<p><em>Why was the hacker able to access the account?</em><br>\nSession cookies are tied to a particular application, in this case hackerone.com. The application won’t block access when a session cookie gets reused in another location. This was a known risk. As many of HackerOne’s users work from mobile connections and through proxies, blocking access would degrade the user experience for those users. Due to the entropy of session cookies and in-depth defenses such as HackerOne’s strict <a href=\"/redirect?signature=17022ee5660e6175e2a4a132fb87db58de8b3863&amp;url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FContent_Security_Policy\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><span>Content Security Policy</span><i class=\"icon-external-link\"></i></a>, HackerOne had not prioritized any additional defenses that limit a session cookie’s ability to be used in a separate browser.</p>\n\n<p><em>Why does a session cookie grant access to reports?</em><br>\nHackerOne offers a number of additional tools on the platform for Security Analysts to work through security reports. In a normal situation, the Security Analysts go through multi-factor Single Sign-On (SSO) to obtain a valid session cookie for their work. Because a live session cookie was obtained, all platform features were available, which therefore granted access to a number of customers’ reports. This was limited to the customer programs that this particular Security Analyst supports.</p>\n\n<p><em>Why were reports exposed for programs that don’t use HackerOne Triage?</em><br>\nHackerOne offers an optional service called <a href=\"https://docs.hackerone.com/programs/human-augmented-signal.html\">Human-Augmented Signal</a> (HAS). HackerOne Security Analysts have access to a separate HAS Inbox on their account where reports can be inspected before they’re forwarded to the customer. A number of reports from this particular Inbox were accessed.</p>\n\n<p><em>Why did it take two hours to notice the report?</em><br>\nHackerOne aims to reply within 24 hours to any submission, including over the weekend. For high and critical severity vulnerabilities, HackerOne tries to respond within a couple of hours. The report to HackerOne’s bug bounty program was submitted on Sunday morning at 05:00am PST (where the majority of HackerOne’s security team resides). For critical submissions, HackerOne’s security team automatically receives a notification on Slack. This works during business hours but is unreliable over the weekend. Security Analysts who work over the weekend noticed the report two hours after the submission, after which they immediately followed Incident Response procedures.</p>\n\n<h2 id=\"resolution-and-recovery\">Resolution and Recovery</h2>\n\n<p>The session cookie was revoked by HackerOne on November 24, 2019 at 15:11 UTC, two hours after it was shared, three minutes after the report was opened for triage. Revoking the session cookie rendered it useless to anyone using it. The subsequent investigation focused on affected customers, vulnerability data, intent, communication, and preventative measures, which concluded on November 26, 2019.</p>\n\n<p>HackerOne audited existing comments to see if other session cookies were leaked in the past. This did not yield any results.</p>\n\n<p>The severity of the report was determined to be high based on HackerOne’s environmental score for the selected asset and CVSS 3.0 base metrics (<em>CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/CR:H/IR:H/AR:H</em>). The minimum bounty award for a high severity vulnerability (based on CVSS) on hackerone.com is currently set to $7,500. A $7,500 reward for disclosing this to HackerOne would mean that HackerOne would award the same amount regardless of which user’s account was compromised. The team looked into the amount of sensitive information that could have been accessed by the account and took that under advisement when deciding on the bounty amount. This led to the decision to treat the submission as a critical vulnerability and award a $20,000 bounty.</p>\n\n<h2 id=\"vulnerability-impact-on-data\">Vulnerability Impact on Data</h2>\n\n<p>Sensitive information of multiple objects was exposed. During the timeframe the hacker had access, three different features were used to access sensitive information. By default, all inboxes only download the minimal amount of data, such as title, state, severity, and assignee, so the user can view the user interface. Vulnerability information is only disclosed when the user selects a report from the user interface.</p>\n\n<p>In an effort to simplify what data was accessed, HackerOne mapped the access of features to the information disclosed as follows:</p>\n\n<ul>\n<li>If the hacker accessed their report via HAS Inbox, Triage Inbox, or Inbox features, the <em>report titles and limited metadata were viewable</em>\n</li>\n<li>If the hacker used the Report View feature, the <em>report contents were viewable</em>\n</li>\n</ul>\n\n<p>Below is an overview of the features and the data that was exposed in each of them. </p>\n\n<h3 id=\"human-augmented-signal-has-inbox\">Human-Augmented Signal (HAS) Inbox</h3>\n\n<p>This Inbox is used by a number of Security Analysts to block or forward submissions that are flagged by HackerOne’s backend of having a high-likelihood being noise. When the hacker accessed the page, the default view loaded up to 25 reports to show the user interface. Reports are sorted by oldest report first. The following information was loaded and displayed:</p>\n\n<table>\n<thead>\n<tr>\n<th>Information</th>\n<th>Note</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>latest_activity_at</td>\n<td>ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report.</td>\n</tr>\n<tr>\n<td>created_at</td>\n<td>ISO 8601 formatted date/time when the report was submitted.</td>\n</tr>\n<tr>\n<td>title</td>\n<td>The title of the report.</td>\n</tr>\n<tr>\n<td>state</td>\n<td>Indicates whether the report is open or closed.</td>\n</tr>\n<tr>\n<td>substate</td>\n<td>Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).</td>\n</tr>\n<tr>\n<td>assignee (group name, username)</td>\n<td>The group’s name or user’s username who is currently assigned to the report.</td>\n</tr>\n<tr>\n<td>reporter (username)</td>\n<td>The reporter’s username.</td>\n</tr>\n<tr>\n<td>program (handle, name)</td>\n<td>The program’s handle and name the report was submitted to.</td>\n</tr>\n</tbody>\n</table>\n\n<h3 id=\"triage-inbox\">Triage Inbox</h3>\n\n<p>This is the Security Analyst’s main Inbox to interact with reports. When the hacker accessed the page, the default view loaded up to 100 reports to show the user interface. Reports are sorted by oldest report first. The following information was loaded and displayed:</p>\n\n<table>\n<thead>\n<tr>\n<th>Information</th>\n<th>Note</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>title</td>\n<td>The title of the report.</td>\n</tr>\n<tr>\n<td>substate</td>\n<td>Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).</td>\n</tr>\n<tr>\n<td>assignee (group name, username)</td>\n<td>The group’s name or user’s username who is currently assigned to the report.</td>\n</tr>\n<tr>\n<td>triage blockers (reasons, blocked by)</td>\n<td>An object that contains the reason why a report is currently blocked on something other than the Security Analysts.</td>\n</tr>\n<tr>\n<td>program (handle, triage notes)</td>\n<td>The program’s handle and name the report was submitted to.</td>\n</tr>\n</tbody>\n</table>\n\n<h3 id=\"inbox\">Inbox</h3>\n\n<p>This is the main Inbox hackers and customers use to interact with reports they’ve submitted and received. When the hacker accessed the page, the default view loaded up to 25 reports to show the user interface. Reports are sorted depending on the view that was selected. The following information was loaded and displayed:</p>\n\n<table>\n<thead>\n<tr>\n<th>Information</th>\n<th>Note</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>latest_activity_at</td>\n<td>ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report.</td>\n</tr>\n<tr>\n<td>created_at</td>\n<td>ISO 8601 formatted date/time when the report was submitted.</td>\n</tr>\n<tr>\n<td>title</td>\n<td>The title of the report.</td>\n</tr>\n<tr>\n<td>state</td>\n<td>Indicates whether the report is open or closed.</td>\n</tr>\n<tr>\n<td>substate</td>\n<td>Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).</td>\n</tr>\n<tr>\n<td>reference</td>\n<td>Any issue tracker reference that was set on the report.</td>\n</tr>\n<tr>\n<td>reference_url</td>\n<td>The full URL to any issue tracker’s task when set.</td>\n</tr>\n<tr>\n<td>severity_rating</td>\n<td>Indicates the report’s severity (null, none, low, medium, high, critical).</td>\n</tr>\n<tr>\n<td>assignee (group name, username)</td>\n<td>The group’s name or user’s username who is currently assigned to the report.</td>\n</tr>\n<tr>\n<td>reporter (username)</td>\n<td>The reporter’s username.</td>\n</tr>\n<tr>\n<td>program (handle, name)</td>\n<td>The program’s handle and name the report was submitted to.</td>\n</tr>\n<tr>\n<td>custom_field_attributes (name)</td>\n<td>All custom field attributes that reports can be filtered on.</td>\n</tr>\n<tr>\n<td>assets (identifier)</td>\n<td>All asset identifiers that reports can be filtered on.</td>\n</tr>\n<tr>\n<td>groups (name)</td>\n<td>All team member groups associated with the program the report was submitted to.</td>\n</tr>\n<tr>\n<td>members (name, username)</td>\n<td>All team members associated with the program the report was submitted to.</td>\n</tr>\n</tbody>\n</table>\n\n<h3 id=\"report-view\">Report View</h3>\n\n<p>Reports are viewable in all of the inboxes in order to help customers, security analysts, and hackers communicate over a vulnerability. Only a single report can be viewed in the same window at any given time. When the hacker viewed the report, the following information was loaded and displayed:</p>\n\n<table>\n<thead>\n<tr>\n<th>Information</th>\n<th>Note</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>vulnerability_information</td>\n<td>The initial description of the vulnerability provided by the reporter.</td>\n</tr>\n<tr>\n<td>comments (text, internal and to the reporter)</td>\n<td>The comments between the reporter and the security team as well as internal comments.</td>\n</tr>\n<tr>\n<td>latest_activity_at</td>\n<td>ISO 8601 formatted date/time when the last activity (internal or external) was posted to the report.</td>\n</tr>\n<tr>\n<td>created_at</td>\n<td>ISO 8601 formatted date/time when the report was submitted.</td>\n</tr>\n<tr>\n<td>title</td>\n<td>The title of the report.</td>\n</tr>\n<tr>\n<td>state</td>\n<td>Indicates whether the report is open or closed.</td>\n</tr>\n<tr>\n<td>substate</td>\n<td>Indicates the report’s state (new, triaged, needs-more-info, resolved, informative, spam, not-applicable, duplicate).</td>\n</tr>\n<tr>\n<td>reference</td>\n<td>Any issue tracker reference that was set on the report.</td>\n</tr>\n<tr>\n<td>reference_url</td>\n<td>The full URL to any issue tracker’s task when set.</td>\n</tr>\n<tr>\n<td>severity_rating</td>\n<td>Indicates the report’s severity (null, none, low, medium, high, critical).</td>\n</tr>\n<tr>\n<td>assignee (group name, username)</td>\n<td>The group’s name or user’s username who is currently assigned to the report.</td>\n</tr>\n<tr>\n<td>reporter (username)</td>\n<td>The reporter’s username.</td>\n</tr>\n<tr>\n<td>program (handle, name)</td>\n<td>The program’s handle and name the report was submitted to.</td>\n</tr>\n<tr>\n<td>custom_field_attributes (name)</td>\n<td>All custom field attributes that reports can be filtered on.</td>\n</tr>\n<tr>\n<td>assets (identifier)</td>\n<td>All asset identifiers that reports can be filtered on.</td>\n</tr>\n<tr>\n<td>groups (name)</td>\n<td>All team member groups associated with the program the report was submitted to.</td>\n</tr>\n<tr>\n<td>members (name, username)</td>\n<td>All team members associated with the program the report was submitted to.</td>\n</tr>\n<tr>\n<td>weakness</td>\n<td>The category of vulnerability.</td>\n</tr>\n</tbody>\n</table>\n\n<p><strong>Data access was limited to the access the HackerOne Security Analyst had, which does not cover HackerOne’s entire customer base. If your data was accessed during this incident, you have received a separate notification from HackerOne.</strong></p>\n\n<h2 id=\"preventative-measures\">Preventative Measures</h2>\n\n<p>As part of HackerOne Incident Response process, HackerOne is conducting an internal review and analysis of the incident. HackerOne is taking the following actions to address the underlying causes of issues and to help prevent future occurrence:</p>\n\n<h3 id=\"short-term-completed\">Short-term (completed)</h3>\n\n<p>These are the short term actions identified. All items have already been addressed and deployed to hackerone.com.</p>\n\n<h4 id=\"bind-sessions-to-ip-addresses\">Bind Sessions to IP Addresses</h4>\n\n<p>The session cookie is able to be reused on different devices. A short term mitigation of this vulnerability is to bind the user’s session to the IP address used at initial sign-in. If an attempt is made to utilize the session from a different IP address, the session is terminated.</p>\n\n<p>This change was rolled out for HackerOne employees (including all HackerOne Security Analysts) on November 25, 2019.</p>\n\n<h4 id=\"block-sessions-from-restricted-countries\">Block Sessions from Restricted Countries</h4>\n\n<p>HackerOne restricts its employees from accessing resources from specific countries. To mitigate account takeovers, the user sessions are prevented from being used from specific restricted list of countries.</p>\n\n<p>This change was rolled out for HackerOne employees (including all HackerOne Security Analysts) on November 26, 2019.</p>\n\n<h4 id=\"page-on-critical-reports\">Page on Critical Reports</h4>\n\n<p>In order to further reduce the time to notify the security team, the team has decided to move from a Slack notification to paging the on-call security person when a critical report gets submitted to the bug bounty program.</p>\n\n<p>This change was implemented on November 25, 2019.</p>\n\n<h4 id=\"update-program-policy-regarding-sensitive-information-access\">Update Program Policy regarding Sensitive Information Access</h4>\n\n<p>HackerOne has updated their bug bounty program policy to include specific actions on when a hacker may have access to a HackerOne account, sensitive keys, or sensitive data.</p>\n\n<p>This change was <a href=\"https://hackerone.com/security/policy_versions?change=3624684\">implemented on November 26, 2019</a>.</p>\n\n<h3 id=\"mid-term-next-three-months\">Mid-term (next three months)</h3>\n\n<h4 id=\"detect\">Detect &amp; Redact Sensitive Data in Comments</h4>\n\n<p>When a user is making a comment, detect possible sensitive information, such as session cookies and authentication tokens, and block submission of the comment until confirmation. Additionally, offer the user the ability to redact the sensitive from the comment automatically.</p>\n\n<p>This change was implemented on December 2, 2019.</p>\n\n<h4 id=\"add-additional-logging-context\">Add Additional Logging Context</h4>\n\n<p>While HackerOne was able to determine which reports were access based on the executed GraphQL queries, HackerOne is planning to improve their logging of information around data access. This will support Incident Response capabilities and allow the incident response to be performed faster.</p>\n\n<h4 id=\"bind-sessions-to-devices\">Bind Sessions to Devices</h4>\n\n<p>A limitation of binding to IPs is that they change for legitimate reasons and will unauthenticate the user, creating a poor user experience. Additionally, IP addresses do not uniquely identify a user (such as with NAT), allowing malicious users to utilize the session, even if it is IP bound. To improve usability and security, HackerOne will investigate binding the session to a specific device that the user is using. Sessions bound to the device will only be usable on that device and using the session elsewhere will terminate the session.</p>\n\n<h4 id=\"improve-education-for-employees\">Improve Education for Employees</h4>\n\n<p>In addition to HackerOne’s current employee education programs, HackerOne will expand the security training for those who handle vulnerability reports. The training will include additional details on how to share technical reproductions and specifically avoid sharing keys, tokens, and session information.</p>\n\n<h3 id=\"long-term-next-twelve-months\">Long-term (next twelve months)</h3>\n\n<h4 id=\"overhaul-security-analyst-permission-model\">Overhaul Security Analyst Permission Model</h4>\n\n<p>The HackerOne Security Analysts have access to HackerOne customers’ sensitive data in order to triage incoming vulnerability reports. HackerOne has identified that HackerOne can restrict security analyst access in programs, as well as overhaul the allocation of security analysts to a more restrictive list of programs to keep these users to the least privilege required. </p>\n\n<h4 id=\"improve-education-for-hackers\">Improve Education for Hackers</h4>\n\n<p>As the community grows, HackerOne needs to ensure that HackerOne is reinforcing the best practices in bug bounty hunting. The HackerOne Community team will look to increase hacker education around delivering proof of critical severity vulnerabilities in case sensitive information has been accessed by the hacker.</p>\n"
    },
    {
      "category": "researcher",
      "can_view?": true,
      "can_create?": false
    }
  ]
}
