Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

101–110 of 168 posts

Re: How I could have hacked any Facebook account

#102
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

where do people even go to start to sell an exploit? how does that kind of stuff work?

Re: How I could have hacked any Facebook account

#103
post #82

Earlier quoted context omitted.

Like Dylan says, people will pay for web server software bugs, if the software is widely installed, because you can make money by building and grooming a fleet of compromised servers. There is a way to do it, and that way works. There is not a good, reliable way to make money from Facebook account takeover. You can conceive of them speculatively, but that is not the same thing as knowing you can execute, or, better,…

Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck". I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.

>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun*

I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account.

You'd have to have a real vendetta against someone to value ruining their life at $15k.

Re: How I could have hacked any Facebook account

#104

Earlier quoted context omitted.

But what can you really do with the Facebook login of, say Obama? Not provoking WW3, that's for sure. The only thing you can realistically create is a PR kerfuffle for Facebook, but considering the way to spread it would be (wait for it) on Facebook itself, there's not much money is this.

You simply log into the Bloomberg/AP/NYTimes account, post some fake economic or political news, and then call in some options you purchased the week before. If done intelligently, this is incredibly difficult to trace. There is risk (rather than a straight-up sale), but the expected returns are probably an order of magnitude higher.

>You simply log into the Bloomberg/AP/NYTimes account, post some fake economic or political news, and then call in some options you purchased the week before.

It would likely be far cheaper and easier to execute something like this via social engineering than using an actual exploit. I'm reminded of the time Twitter user @m had his handle stolen because Apple gave up some personal info.

Given that there are likely 100s if not 1000s of FB users who may have access to Bloomberg/AP/NYTimes official page, figuring out in an automated fashion of who can be easily socially engineered isn't likely worth 15k.

Re: How I could have hacked any Facebook account

#105
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I think it's designed to be enough to convince would-be hackers to reveal the bug, but not enough to incentivise large amounts of people to sit around all day every day trying to break Facebook for bounties.

Re: How I could have hacked any Facebook account

#106
post #99
post #95

Earlier quoted context omitted.

That's an especially ironic argument to try to make on this particular site.

Is that a retort or simply an unrelated observation? Edit: My intent was to understand your perspective (and argue...), but this comment goes over my head, and it seems as though it was a thinly veiled insult.

What I'm understanding here is, that while it might be profitable to someone to have an exploit on hand that they can use, the actual work that goes into turning a profit from the exploit may be me costly enough that its not worth pursuing.

Not sure if you read Cryptonomicon, but there's a part there where Randy Waterhouse finds a crap load of gold in the middle of a jungle and then rationalizes that there's no easy way to get it out of there, making it worthless at that moment. That gold has value, but no liquidity.

Re: How I could have hacked any Facebook account

#107
post #99
post #95

Earlier quoted context omitted.

That's an especially ironic argument to try to make on this particular site.

Is that a retort or simply an unrelated observation? Edit: My intent was to understand your perspective (and argue...), but this comment goes over my head, and it seems as though it was a thinly veiled insult.

This is a forum focused on the startup community. The difference between the merely-useful and the truly-marketable has been discussed ad nauseum on these pages, as that difference makes and breaks many startups.

Re: How I could have hacked any Facebook account

#108

Earlier quoted context omitted.

Authy is really good. https://www.authy.com/ They need a Firefox extension but its allowed me to do 2FA on my personal and work accounts without fear of being totally locked out if I loose my phone.

Don't Authy store some of your secrets server-side?

You can choose to store some, yes, but it's encrypted by your backup password. At least that's my understanding of it.

Re: How I could have hacked any Facebook account

#110
post #93
post #87

Earlier quoted context omitted.

Lots of things have utility but no liquidity.

The info is useful, but not sellable? The two seem deeply intertwined. If I can prove usefulness, I can sell it. Actually, you say the info has "a use"... does that not directly imply worth?

The info might be useful to someone, but not to the people who are buying vulnerabilities on the black market.

Imagine going to a tech trade show and setting up a stand for your lumber business. What you're selling has value and is useful, just not to the people you're trying to sell it to.

Post reply on HN