Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

131–140 of 168 posts

Re: How I could have hacked any Facebook account

#131
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

> Make no mistake, Facebook has probably done this math very carefully when choosing a bounty.

Having worked at several similar companies, I'm guessing it went like this:

"How much should bounty be? Is $5K good?"

"Wow, that's nothing. At least make it something meaningful like 25 grand."

"Yeah....that's gonna be tough. How about split the difference? $15K"

"Sure."

Re: How I could have hacked any Facebook account

#132
A whole $15k? This could have cost them hundreds of thousands if not millions in lawsuits. That's a pretty crappy incentive, I'd imagine a lot less moral security researchers getting exponentially more money out of something like this by just selling the 0day.

I wonder why the reward is so low. This is literally the amount a code monkey gets paid after 3-5 months of work with minimal skills.

Re: How I could have hacked any Facebook account

#133
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

You forget to normalise by the uncertainty of payment in the blackhat case and the probability of repercussions.

Not to mention the possibility of selling the same thing to multiple black hat buyers.

Re: How I could have hacked any Facebook account

#134

Earlier quoted context omitted.

Unless your name is Kevin Mitnick. Then you set up a business and play middlemen in selling them to anybody who wants to pony up for it. "When we have a client that wants a zero-day vulnerability for whatever reason, we don’t ask, and in fact they wouldn’t tell us,” Mitnick tells WIRED in an interview. “Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.” h…

How is this legal?

Because he's selling to governments, who operate under the "it's not illegal when we do it" principle.

Re: How I could have hacked any Facebook account

#135
post #66

Earlier quoted context omitted.

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

This comment states: > Facebook's security team is one of the strongest and most sophisticated of any company If that is true, how come they didn't catch this relatively obvious glitch discussed here.

[deleted]

Re: How I could have hacked any Facebook account

#136
post #122

Earlier quoted context omitted.

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

Not really - a Facebook attack can be proven without revealing the details. eg. The buyer could ask "give me a list of the friends of " or "make a fake posting with authored by ".

Problem with that us the buyer could be FB Sec. Now they have a targeted account to watch and find the vuln. themselves. Better option is to find a random famous person and do the sane thing.

Re: How I could have hacked any Facebook account

#137
post #122

Earlier quoted context omitted.

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

Not really - a Facebook attack can be proven without revealing the details. eg. The buyer could ask "give me a list of the friends of " or "make a fake posting with authored by ".

Problem with that us the buyer could be FB Sec. Now they have a targeted account to watch and find the vuln. themselves. Better option is to find a random famous person and do the sane thing.

Re: How I could have hacked any Facebook account

#138
post #122

Earlier quoted context omitted.

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is…

Not really - a Facebook attack can be proven without revealing the details. eg. The buyer could ask "give me a list of the friends of " or "make a fake posting with authored by ".

Problem with that us the buyer could be FB Sec. Now they have a targeted account to watch and find the vuln. themselves. Better option is to find a random famous person and do the sane thing.

Re: How I could have hacked any Facebook account

#139
post #35

Earlier quoted context omitted.

What are you talking about? Facebook is not a "high value target" and "this bug would not cause Facebook much damage"? For example, if you wanted to monetize it, I have to imagine TMZ (or someone even less scrupulous) would pay a lot of money for dumps of A-list celeb and athlete Facebook accounts. You don't think Facebook having "The Fappening Part 2" on their hands is worth more than $15k to prevent? Or having ever…

Your comment does not reflect how vulnerability sales work in the real world. In the real world, vulnerabilities are sold to blackhat groups who want to make a profit by attacking as many websites as possible. Generally, these websites will have valuable credit card or other information that can be stolen from a compromised server. Compromised user accounts (not even the server! just users!) on a single website do no…

Step one: short a million on Apple shares

Step two: hack into Tim Cook's account (no idea if he uses FB)

Step three: publish rant about Apple rotten ideoligies/he quits

Step four: see APPL lose value for a day until this shit is sorted

Step five: profit

Or something like that

Re: How I could have hacked any Facebook account

#140
post #66

Earlier quoted context omitted.

It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets. https://news.ycombinator.com/item?id=11249173

This comment states: > Facebook's security team is one of the strongest and most sophisticated of any company If that is true, how come they didn't catch this relatively obvious glitch discussed here.

No team can catch all the bugs.

As for 'obvious', hindsight, yada yada.

Post reply on HN