Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

91–100 of 168 posts

Re: How I could have hacked any Facebook account

#91

Earlier quoted context omitted.

You simply log into the Bloomberg/AP/NYTimes account, post some fake economic or political news, and then call in some options you purchased the week before. If done intelligently, this is incredibly difficult to trace. There is risk (rather than a straight-up sale), but the expected returns are probably an order of magnitude higher.

Given that the risk is you go to jail, I'm not so sure.

I thought most blackhat activities already implied the threat of jail-time...

Re: How I could have hacked any Facebook account

#92
post #66

Earlier quoted context omitted.

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html

Footnote on the graphic: *All payout amounts are chosen at the discretion of ZERODIUM and are subject to change or cancellation without notice.

Translation: "Show us what you got and then we'll screw you over."

Sounds like you're less likely to get screwed by an escrow service found on TOR.

Re: How I could have hacked any Facebook account

#93
post #87
post #81

Earlier quoted context omitted.

I would agree, being that I cannot immediately detail how these Facebook accounts might be useful, but any information is useful, especially credentials. (Valuable != "immediate drop-in value")? So, he's saying the accounts aren't valuable, but they have value? The subtlety is lost on me...

Lots of things have utility but no liquidity.

The info is useful, but not sellable? The two seem deeply intertwined. If I can prove usefulness, I can sell it.

Actually, you say the info has "a use"... does that not directly imply worth?

Re: How I could have hacked any Facebook account

#94
post #68

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

He's right, and you are indeed recapitulating a discussion that has happened a zillion times on HN before. At some point (maybe I haven't read far enough down on the thread), The Grugq will chime in and confirm it, just in case you were doubting it. This isn't specific to Facebook; it's a common misapprehension of how bugs are valued for all SaaS companies. People don't pay top dollar for speculative bugs. I'm sure t…

The bizarre part here is that Facebook is competing against a market that the security researcher is not allowed to participate in by law.

Facebook sets the price, not the market. That's why the speculative value of a bug should be relevant, not the practical value. If this guy were allowed to openly market his bug to all parties, it would be guaranteed to be worth much more than $15k.

The price to Facebook is totally arbitrary. They could pay this guy $10 and it would still be fair under your position, because it's better than the alternative of committing a felony by finding someone to outbid Facebook.

Re: How I could have hacked any Facebook account

#95
post #93
post #87

Earlier quoted context omitted.

Lots of things have utility but no liquidity.

The info is useful, but not sellable? The two seem deeply intertwined. If I can prove usefulness, I can sell it. Actually, you say the info has "a use"... does that not directly imply worth?

That's an especially ironic argument to try to make on this particular site.

Re: How I could have hacked any Facebook account

#96

    beta.facebook.com and mbasic.beta.facebook.com 
Certificate Transparency has an interesting impact on some of the less-public servers.

https://crt.sh/?q=%25.facebook.com

A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.

Re: How I could have hacked any Facebook account

#97

beta.facebook.com and mbasic.beta.facebook.com Certificate Transparency has an interesting impact on some of the less-public servers. https://crt.sh/?q=%25.facebook.com A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.

I'm surprised an organisation as large as Facebook don't have their own CA, and just don't issue the semi-secret stuff off the record.

Re: How I could have hacked any Facebook account

#98

Earlier quoted context omitted.

2FA is nice unless you lose your cell phone or it gets stolen. If you ever lose your job or go homeless and can't afford a cell phone then you are locked out of your accounts. I am disabled and struggling if I miss payments I go homeless or can't pay my bills and things get shut off. For me 2FA might not work if I am down on my luck.

Authy is really good. https://www.authy.com/ They need a Firefox extension but its allowed me to do 2FA on my personal and work accounts without fear of being totally locked out if I loose my phone.

Don't Authy store some of your secrets server-side?

Re: How I could have hacked any Facebook account

#99
post #95
post #93

Earlier quoted context omitted.

The info is useful, but not sellable? The two seem deeply intertwined. If I can prove usefulness, I can sell it. Actually, you say the info has "a use"... does that not directly imply worth?

That's an especially ironic argument to try to make on this particular site.

Is that a retort or simply an unrelated observation?

Edit: My intent was to understand your perspective (and argue...), but this comment goes over my head, and it seems as though it was a thinly veiled insult.

Post reply on HN