Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

121–130 of 168 posts

Re: How I could have hacked any Facebook account

#121
post #44

Earlier quoted context omitted.

I'm sure they might encourage him to interview, but he's not going to get a serious job offer just from this. There's essentially nothing technical or skillful going on here, other than the basic coding ability to do HTTP requests in a loop and the hunch to investigate if subdomains don't rate limit.

He was resourceful enough to find a security flaw of the highest severity in the only product of a $300 billion dollar company. A hole that was somehow missed by said company's own security auditors, who collectively are probably paid many millions of dollars per year entirely to look for such holes. So that's something. But you're right, he might have just got lucky. The one fish in a school of 100,000 who finds the…

He's found quite a few different bugs:

https://hackerone.com/anand786 https://www.facebook.com/whitehat/thanks (listed 2015, 2014, 2013)

Re: How I could have hacked any Facebook account

#122
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

Not really - a Facebook attack can be proven without revealing the details. eg. The buyer could ask "give me a list of the friends of " or "make a fake posting with authored by ".

Re: How I could have hacked any Facebook account

#123
post #38

Earlier quoted context omitted.

When setting up Google Authenticator for One Time Passcodes, you are also given a seed which can be used to resteup the app from another device.

Provided you don't lose that seed. If I end up homeless will lose all my stuff and limited to library access. You have to plan for the worst case scenarios with 2FA when things go bad.

Well at a certain point getting locked out stops being 2FA's fault and is simply due to the user's lack of responsibility.

Re: How I could have hacked any Facebook account

#124
post #66

Earlier quoted context omitted.

In other words, if you wanted to game the odds, you'd start by offering it on the black market, then if there were no takers after X number of days, offer it to Facebook?

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

This comment states:

> Facebook's security team is one of the strongest and most sophisticated of any company

If that is true, how come they didn't catch this relatively obvious glitch discussed here.

Re: How I could have hacked any Facebook account

#125

Earlier quoted context omitted.

where do people even go to start to sell an exploit? how does that kind of stuff work?

same place as silk road.

Not sure if this is a good idea. Probably lots of undercover three-letter government agents lurking there.

Re: How I could have hacked any Facebook account

#126

Earlier quoted context omitted.

Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck". I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.

>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun* I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account. You'd have to have a real vendetta against someone to value ruining their life at $15k.

> You'd have to have a real vendetta against someone to value ruining their life at $15k.

15k is actually cheap when compared with the costs of a private eye, a biker gang or a contract killer.

Re: How I could have hacked any Facebook account

#127
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

Even if you aren't able to receive some sort of sample proof of work (which is probably not the case with this exploit), you can still mitigate the risk by ensuring the seller has high status in the marketplace and/or is willing to use escrow (or preferably multi-sig) to ensure funds are only released upon receipt.

Re: How I could have hacked any Facebook account

#129
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

3-way signed keys with 2 min necessary for accessing the BTC wallet. If memory is not playing tricks on me, you can do that with BTC. You can make a client-> seller transaction if everything is normal, else the third party can arbiter the transaction.
Post reply on HN