Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.
This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…
How I could have hacked any Facebook account
41–50 of 168 posts
Re: How I could have hacked any Facebook account
#42Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.
During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…
Re: How I could have hacked any Facebook account
#43Earlier quoted context omitted.
What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…
Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…
That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.
Re: How I could have hacked any Facebook account
#44Earlier quoted context omitted.
$15k and a likely open FB job offer
> job offer Really? For brute forcing an un-rate-limited endpoint? I doubt it.
Re: How I could have hacked any Facebook account
#45Earlier quoted context omitted.
What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…
Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…
It all really depends on how fast FB can service the requests and how long it takes for them to notice and shut it down. Push your priority list off to a worldwide farm and watch the accounts pop out.
How long until FB would have it shut down and the affected accounts locked out?
Re: How I could have hacked any Facebook account
#46Hacker News: Where comments can be six paragraphs long and say absolutely nothing.
Re: How I could have hacked any Facebook account
#47Earlier quoted context omitted.
2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.
There are ways around this for some things but, probably not with services like Facebook. For example with Amazon I use 2FA with a cellphone. As a backup I use a hardware token and an Admin account. If my cellphone gets stolen I pull the 2FA card out of my wallet.
Re: How I could have hacked any Facebook account
#48If in any twisted, unrealistic, straight out of Homeland scenario where anyone high profile enough would make use of this "vulnerability" and successfully create a media "splash", and assuming Facebook security team is on top of their game, this would get patched in a week tops. Keeping an eye on average number of requests coming to their API end points, especially sensitive ones, is part of their job, not a nice-to-have. I'd even think this would actually get patched within 24 hours (since the fix isn't really that difficult). I have absolutely no care or sympathy for Facebook but yeah, 15K is a lot for something like this. It's a nice catch, that's all.
Re: How I could have hacked any Facebook account
#49Earlier quoted context omitted.
2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.
When setting up Google Authenticator for One Time Passcodes, you are also given a seed which can be used to resteup the app from another device.
Re: How I could have hacked any Facebook account
#50This has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.
2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.
They need a Firefox extension but its allowed me to do 2FA on my personal and work accounts without fear of being totally locked out if I loose my phone.