Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

71–80 of 168 posts

Re: How I could have hacked any Facebook account

#71
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

this doesn't make any sense, most vulnerability you find on products are "game over" vulnerabilities. It's common. If you would give a billion dollars to every such findings in an audit then you would be pretty quickly calling bankruptcy.

Also, I can personally live for a year on that kind of money. But that's another issue.

On the other hand, that is maybe what they would have payed for a real audit of a few days/weeks and it's not even sure the vulnerability would have been found (especially considering the size of Facebook). So yeah maybe they also deserve more.

I'm mixed.

Re: How I could have hacked any Facebook account

#72
post #35

Earlier quoted context omitted.

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

Your claim was about the severity of the bug. It all really depends on how fast FB can service the requests and how long it takes for them to notice and shut it down. Push your priority list off to a worldwide farm and watch the accounts pop out. How long until FB would have it shut down and the affected accounts locked out?

The problem is that there's no half life. The bug dies instantaneously once discovered. It's not like 3/4 of the Internet runs "old Facebook" because they forgot to update it.

Re: How I could have hacked any Facebook account

#73
post #71
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

this doesn't make any sense, most vulnerability you find on products are "game over" vulnerabilities. It's common. If you would give a billion dollars to every such findings in an audit then you would be pretty quickly calling bankruptcy. Also, I can personally live for a year on that kind of money. But that's another issue. On the other hand, that is maybe what they would have payed for a real audit of a few days/we…

David is right about this, too. A $50,000 pentest of any major web property is likely to find multiple sev:hi vulnerabilities. By the logic the grandparent comment uses, those audits should cost more like $1.5MM.

Re: How I could have hacked any Facebook account

#74
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

>Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook? FB is publicly traded at very high volume. You can make very large bets on its movement without being noticed. A hack of 10 celebrity facebook pages could probably drop the stock 5% in one day. You'd probably be able to make at least 20 to 1 on your money using options. The rig…

If that were as straightforward as you claim, there would be a black market for all sorts of serverside vulnerabilities that might swing stock prices. But there isn't. One of two things is probably happening:

1. It is way less easy to predictably and profitably swing Facebook's stock than simply by hacking 10 celebrity pages.

2. For whatever reason, including the fact that crime rings premised on manipulating stocks have an annoying tendency to get caught, nobody is running this "hack Company X while sorting their stock" scam, and so even if it's possible to accomplish, the market doesn't value it.

Re: How I could have hacked any Facebook account

#75
post #35

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

You know what people put into Facebook chats?

Obligatory quote from Kanye's newest album 'The Life of Pablo':

" I had a cousin that stole my laptop that I was fuckin' bitches on

Paid that nigga 250 thousand just to get it from him "

Re: How I could have hacked any Facebook account

#76
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

> Facebook is not a high value target, relatively speaking.

I think you got this wrong, Facebook is not the target, their users are. Which reminded me of "If a service on the Internet is free, you are the product"

Re: How I could have hacked any Facebook account

#77
post #75
post #35

Earlier quoted context omitted.

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

You know what people put into Facebook chats? Obligatory quote from Kanye's newest album 'The Life of Pablo': " I had a cousin that stole my laptop that I was fuckin' bitches on Paid that nigga 250 thousand just to get it from him "

You know what people put into Instant Bloomberg chats?

Go try to sell an IBB bug.

Re: How I could have hacked any Facebook account

#78
post #66

Earlier quoted context omitted.

In other words, if you wanted to game the odds, you'd start by offering it on the black market, then if there were no takers after X number of days, offer it to Facebook?

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html

Re: How I could have hacked any Facebook account

#79
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I assume it made its way into the wrong hands (not by the OP) and the amount of damage appears to be zero.

Re: How I could have hacked any Facebook account

#80
post #72

Earlier quoted context omitted.

Your claim was about the severity of the bug. It all really depends on how fast FB can service the requests and how long it takes for them to notice and shut it down. Push your priority list off to a worldwide farm and watch the accounts pop out. How long until FB would have it shut down and the affected accounts locked out?

The problem is that there's no half life. The bug dies instantaneously once discovered. It's not like 3/4 of the Internet runs "old Facebook" because they forgot to update it.

Sure, but in the time before the accounts are locked out all of their data may have been exfiltrated and mirrored around the world.

It won't matter if everyone can get the latest version of Facebook if no one is willing to use it anymore.

Post reply on HN