Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

81–90 of 168 posts

Re: How I could have hacked any Facebook account

#81
post #69
post #43

Earlier quoted context omitted.

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target. That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

He's not wrong, you're just misunderstanding him. He's not saying there aren't "valuable" or "interesting" Facebook accounts. He's saying that there aren't enough Facebook accounts with immediate drop-in value to an existing and lucrative criminal enterprise to create a competitive market for Facebook bugs.

I would agree, being that I cannot immediately detail how these Facebook accounts might be useful, but any information is useful, especially credentials.

(Valuable != "immediate drop-in value")? So, he's saying the accounts aren't valuable, but they have value? The subtlety is lost on me...

Re: How I could have hacked any Facebook account

#82
post #66

Earlier quoted context omitted.

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html

Like Dylan says, people will pay for web server software bugs, if the software is widely installed, because you can make money by building and grooming a fleet of compromised servers. There is a way to do it, and that way works.

There is not a good, reliable way to make money from Facebook account takeover. You can conceive of them speculatively, but that is not the same thing as knowing you can execute, or, better, already having a business process in place that is already executing, just waiting for a new bug.

Re: How I could have hacked any Facebook account

#83

Earlier quoted context omitted.

There are ways around this for some things but, probably not with services like Facebook. For example with Amazon I use 2FA with a cellphone. As a backup I use a hardware token and an Admin account. If my cellphone gets stolen I pull the 2FA card out of my wallet.

Provided that nobody steals your wallet and you don't lose that card.

In that case you use the backup codes that you had printed and put in a safe a register a new 2FA token.

Re: How I could have hacked any Facebook account

#84
post #7

Earlier quoted context omitted.

Seeing as it's a brute-force per-account attack, a more accurate title would have been "How I could have hacked any Facebook account". Hacking "all of Facebook" would have been prohibitively resource-intensive for the hacker, and would likely have been caught and shut down before any real damage to the platform was done.

This alone would be enough to permanently cripple Facebook in the eyes of the public if applied "correctly." The iCloud/Fappening totally wasn't a big deal either, right? /s

Apple wasn't brought down by the fappening.

Re: How I could have hacked any Facebook account

#85
post #43

Earlier quoted context omitted.

>Compromised user accounts (not even the server! just users!) on a single website do not constitute a valuable target. That statement is just plain wrong. With over a billion Facebook users, surely some of them are high-value targets.

But what can you really do with the Facebook login of, say Obama? Not provoking WW3, that's for sure. The only thing you can realistically create is a PR kerfuffle for Facebook, but considering the way to spread it would be (wait for it) on Facebook itself, there's not much money is this.

You simply log into the Bloomberg/AP/NYTimes account, post some fake economic or political news, and then call in some options you purchased the week before.

If done intelligently, this is incredibly difficult to trace. There is risk (rather than a straight-up sale), but the expected returns are probably an order of magnitude higher.

Re: How I could have hacked any Facebook account

#86
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

> Facebook is not a high value target, relatively speaking. I think you got this wrong, Facebook is not the target, their users are. Which reminded me of "If a service on the Internet is free, you are the product"

This quote is as lame as irrelevant it is.

Re: How I could have hacked any Facebook account

#87
post #81
post #69

Earlier quoted context omitted.

He's not wrong, you're just misunderstanding him. He's not saying there aren't "valuable" or "interesting" Facebook accounts. He's saying that there aren't enough Facebook accounts with immediate drop-in value to an existing and lucrative criminal enterprise to create a competitive market for Facebook bugs.

I would agree, being that I cannot immediately detail how these Facebook accounts might be useful, but any information is useful, especially credentials. (Valuable != "immediate drop-in value")? So, he's saying the accounts aren't valuable, but they have value? The subtlety is lost on me...

Lots of things have utility but no liquidity.

Re: How I could have hacked any Facebook account

#88
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I do security audits and agree completely. My biggest issue is that the researcher is working for free. If nothing is found you just burnt a few weeks, if something is found the payout is usually only a couple grand.

If people enjoy doing it, or it makes sense in their currency or situation, awesome. The payouts don't get me excited though.

That's the market though. People who think it's too cheap don't play the game, people who think it's good money do.

Re: How I could have hacked any Facebook account

#89
post #82

Earlier quoted context omitted.

Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html

Like Dylan says, people will pay for web server software bugs, if the software is widely installed, because you can make money by building and grooming a fleet of compromised servers. There is a way to do it, and that way works. There is not a good, reliable way to make money from Facebook account takeover. You can conceive of them speculatively, but that is not the same thing as knowing you can execute, or, better,…

Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck".

I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.

Re: How I could have hacked any Facebook account

#90

Earlier quoted context omitted.

But what can you really do with the Facebook login of, say Obama? Not provoking WW3, that's for sure. The only thing you can realistically create is a PR kerfuffle for Facebook, but considering the way to spread it would be (wait for it) on Facebook itself, there's not much money is this.

You simply log into the Bloomberg/AP/NYTimes account, post some fake economic or political news, and then call in some options you purchased the week before. If done intelligently, this is incredibly difficult to trace. There is risk (rather than a straight-up sale), but the expected returns are probably an order of magnitude higher.

Given that the risk is you go to jail, I'm not so sure.
Post reply on HN