Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

51–60 of 168 posts

Re: How I could have hacked any Facebook account

#51

This has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

Authy is really good. https://www.authy.com/

They need a Firefox extension but its allowed me to do 2FA on my personal and work accounts without fear of being totally locked out if I loose my phone.

Re: How I could have hacked any Facebook account

#52
post #43
post #35

Earlier quoted context omitted.

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target. That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

But what can you really do with the Facebook login of, say Obama? Not provoking WW3, that's for sure. The only thing you can realistically create is a PR kerfuffle for Facebook, but considering the way to spread it would be (wait for it) on Facebook itself, there's not much money is this.

Re: How I could have hacked any Facebook account

#53
post #35

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

> Hollywood plot, nothing more.

The first example that comes to mind, "an organised trade in confidential personal information"

https://en.wikipedia.org/wiki/News_International_phone_hacki...

Just because this isn't the typical mass vulnerability SQL injection or XSS attack on a major framework doesn't mean it's basically worthless ($15k or less).

The amount of damage that could be done to Facebook's reputation is enormous, not to mention the value of the information that could be stolen.

Re: How I could have hacked any Facebook account

#55
post #43

Earlier quoted context omitted.

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target. That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

But what can you really do with the Facebook login of, say Obama? Not provoking WW3, that's for sure. The only thing you can realistically create is a PR kerfuffle for Facebook, but considering the way to spread it would be (wait for it) on Facebook itself, there's not much money is this.

I think you are vastly underestimating the power of social engineering.

Re: How I could have hacked any Facebook account

#56
post #7
post #5

Earlier quoted context omitted.

Very disappointing comment. Everybody is free to choose to use facebook or not to use it. I chose not to use it, but I do not have the right or any moral obligation to stop others from using it. This guy did not have the right - and fortunately chose not to exercise it - to mess with other people's free choices in life. Besides that, the likely only effect any activity like you are suggesting would have had is that h…

Seeing as it's a brute-force per-account attack, a more accurate title would have been "How I could have hacked any Facebook account". Hacking "all of Facebook" would have been prohibitively resource-intensive for the hacker, and would likely have been caught and shut down before any real damage to the platform was done.

Ok, we changed the title to say "any" rather than "all".

Re: How I could have hacked any Facebook account

#57
post #44
post #16

Earlier quoted context omitted.

> job offer Really? For brute forcing an un-rate-limited endpoint? I doubt it.

I'm sure they might encourage him to interview, but he's not going to get a serious job offer just from this. There's essentially nothing technical or skillful going on here, other than the basic coding ability to do HTTP requests in a loop and the hunch to investigate if subdomains don't rate limit.

He was resourceful enough to find a security flaw of the highest severity in the only product of a $300 billion dollar company. A hole that was somehow missed by said company's own security auditors, who collectively are probably paid many millions of dollars per year entirely to look for such holes. So that's something.

But you're right, he might have just got lucky. The one fish in a school of 100,000 who finds the hole in the net probably isn't smarter than all the other fish. But that just strengthens the argument that companies should reward very generously for these exploits, because increasing the number of white-hats looking for them is a good way to ensure that they get found by one.

Re: How I could have hacked any Facebook account

#58
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

If I had a site with a billion users and said site had a vulnerability with significant repercussions on my business, BreakingBits, a "software security firm", would advise me not to meaningfully encourage outsiders to find and squash those vulnerabilities?

Uh... is this the advice you give your customers?

Re: How I could have hacked any Facebook account

#60
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

In other words, if you wanted to game the odds, you'd start by offering it on the black market, then if there were no takers after X number of days, offer it to Facebook?
Post reply on HN