Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

31–40 of 168 posts

Re: How I could have hacked any Facebook account

#31
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

The point is, it's possible that if he was a black hat, he could have gotten much more for it on the black market. Even if it could only be used once or a few times.

Bounties should not only be higher than what you can get on the black market. They should be high enough to make security experts spend their time trying to win them. Given probability of finding a bug with such impact, it is just not worth the time of any decent white hat (in terms of financial gain, sure it's nice to brag about it and that I believe is the biggest motivation).

Money wise, for Facebook, it makes zero difference if they pay him that much or 5 times more.

Re: How I could have hacked any Facebook account

#32
post #9

How do companies evaluate the severity and impact of the vulnerability? I don't work in security, but it seems like this is worth more than $15,000.

Companies evaluate severity based on impact. There are different tiers of vulnerability.

A vulnerability that affects a particular website is significantly less valuable than one that affects many websites.

Companies like Google and Facebook actually overpay for vulnerabilities because 1) they're flush with cash and can, 2) it's excellent for goodwill in the industry, 3) it's an excellent recruiting tool and 4) it augments an already strong internal security program.

If you hypothetically tried to go to the black market with this vulnerability you wouldn't even find a buyer. When Facebook patches this, it's useless, and you'd have to derive more than whatever you paid for. At this point it's a betting game - do you think you can earn back $100,000 using this exploit before Facebook catches wind of it?

Conversely, vulnerabilities that are very highly valued tend to affect large numbers of websites in a format that is not easily patched. For example, many websites don't update WordPress often, which means that a vulnerability in WordPress is going to instantly get a CVE and a widespread push for awareness. Even so, it will be actionable for years.

Re: How I could have hacked any Facebook account

#33
post #31
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

The point is, it's possible that if he was a black hat, he could have gotten much more for it on the black market. Even if it could only be used once or a few times. Bounties should not only be higher than what you can get on the black market. They should be high enough to make security experts spend their time trying to win them. Given probability of finding a bug with such impact, it is just not worth the time of a…

>> The point is, it's possible that if he was a black hat, he could have gotten much more for it on the black market. Even if it could only be used once or a few times.

This is precisely my point. No, he couldn't have. I outlined why in the comment you responded to.

>> Money wise, for Facebook, it makes zero difference if they pay him that much or 5 times more.

Leaving aside the fact that it obviously doesn't literally make "zero difference," should companies decide to pay more for things simply because they can afford to?

Re: How I could have hacked any Facebook account

#34
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"?

For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts.

You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having every US Government FB account simultaneously posting ISIS propaganda?

The PR for any number of scenarios like those would be an absolute nightmare for Facebook.

Re: How I could have hacked any Facebook account

#35
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world.

In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server.

Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target.

The idea that TMZ would pay a significant amount of money for this is a Hollywood plot, nothing more. Vulnerabilities are not valued highly just because you can come up with a contrived scenario in which it would be valuable to someone for some reason.

This is a market, and like any other market there are buyers and sellers who dictate supply and demand.

Re: How I could have hacked any Facebook account

#37
post #20

Earlier quoted context omitted.

Looks like Burp Suite. Sweet web proxy tool -- https://portswigger.net/burp/ Free for 14 days I think.

Awesome! Thanks for the link. It looks like they have a limited free forever version as well, gonna have to play with this.

hmm yea my memory might have adjusted it to a trial period -- looks like many of the most useful features are crippled in the free version.

Re: How I could have hacked any Facebook account

#38

This has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

When setting up Google Authenticator for One Time Passcodes, you are also given a seed which can be used to resteup the app from another device.

Re: How I could have hacked any Facebook account

#39
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

yeah seriously, #2 is spot on. The moment you start brute forcing your way, network traffic gives you in and the security team will start blocking you. By the time they find out you may have found out 1,2,3.. few accounts.. This is no way worth lots of $$ in bounty, let alone the 100k job offer, that's a joke.

Re: How I could have hacked any Facebook account

#40
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

This would be extremely lucrative for a media outlet. You would need way less than 5 exploited high-profile celebrity accounts to surpass the $15,000 that were awarded in profit.
Post reply on HN