Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

151–160 of 168 posts

Re: How I could have hacked any Facebook account

#151
post #88
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

I do security audits and agree completely. My biggest issue is that the researcher is working for free. If nothing is found you just burnt a few weeks, if something is found the payout is usually only a couple grand. If people enjoy doing it, or it makes sense in their currency or situation, awesome. The payouts don't get me excited though. That's the market though. People who think it's too cheap don't play the game…

In my country, getting paid 15k dollars would mean more than a years worth of sallary of a big infosec company. So it makes complete sense to go in for bug bounties, even if it's "low" payout, or if you spend a lot of time to get one.

Like you said, that's our market, but when working on a global scale, you have to consider pretty much everyone.

Re: How I could have hacked any Facebook account

#152

Earlier quoted context omitted.

How is this legal?

Because he's selling to governments, who operate under the "it's not illegal when we do it" principle.

What if it's the Chinese government that's buying, would it suddenly turn illegal?

Re: How I could have hacked any Facebook account

#153
post #121

Earlier quoted context omitted.

He was resourceful enough to find a security flaw of the highest severity in the only product of a $300 billion dollar company. A hole that was somehow missed by said company's own security auditors, who collectively are probably paid many millions of dollars per year entirely to look for such holes. So that's something. But you're right, he might have just got lucky. The one fish in a school of 100,000 who finds the…

He's found quite a few different bugs: https://hackerone.com/anand786 https://www.facebook.com/whitehat/thanks (listed 2015, 2014, 2013)

Over 20k in bounties in the last year listed, this 15k bounty, and multiple unlisted amounts from Yahoo. I don't think he cares about a job offer from FB too much.

Re: How I could have hacked any Facebook account

#154
post #99
post #95

Earlier quoted context omitted.

That's an especially ironic argument to try to make on this particular site.

Is that a retort or simply an unrelated observation? Edit: My intent was to understand your perspective (and argue...), but this comment goes over my head, and it seems as though it was a thinly veiled insult.

Not an insult. https://news.ycombinator.com/item?id=11251104

Re: How I could have hacked any Facebook account

#155
post #68

Earlier quoted context omitted.

He's right, and you are indeed recapitulating a discussion that has happened a zillion times on HN before. At some point (maybe I haven't read far enough down on the thread), The Grugq will chime in and confirm it, just in case you were doubting it. This isn't specific to Facebook; it's a common misapprehension of how bugs are valued for all SaaS companies. People don't pay top dollar for speculative bugs. I'm sure t…

The bizarre part here is that Facebook is competing against a market that the security researcher is not allowed to participate in by law. Facebook sets the price, not the market. That's why the speculative value of a bug should be relevant, not the practical value. If this guy were allowed to openly market his bug to all parties, it would be guaranteed to be worth much more than $15k. The price to Facebook is totall…

That's almost true. If Fb bid only $10, you could see bidding simply for the right to (a) announce the bug or (b) post a hash and lord it over Fb. There's a vanity value for some of these bugs that probably goes into the hundreds of dollars.

But the rest of your point? Yep. Sounds about right. Though I don't think it's quite fair to say that "Fb sets the price, not the market", since Fb is the market for these bugs.

Re: How I could have hacked any Facebook account

#156
post #27
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

>Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook?

I can absolutely think of a situation that would make access to one person's facebook account worth way more than $20,000. Say, an unethical high-profile divorce lawyer fishing for information that would help during a multi-million dollar case. Or a political activist trying to dig up dirt on a candidate.

Re: How I could have hacked any Facebook account

#157
post #27

Earlier quoted context omitted.

This has been discussed many, many times on HN before. This bug would not cause Facebook much damage; in fact, Facebook and Google tend to overpay rewards for bugs for the purposes of goodwill and recruiting. Let's examine the facts: 1. A Facebook vulnerability is dangerous to Facebook. A WordPress vulnerability is dangerous to a quarter of the internet. Facebook is not a high value target, relatively speaking. 2. A…

>Say they buy it for $20,000. Do you really think someone will derive $20,000 of profit from this before it's caught and patched by Facebook? I can absolutely think of a situation that would make access to one person's facebook account worth way more than $20,000. Say, an unethical high-profile divorce lawyer fishing for information that would help during a multi-million dollar case. Or a political activist trying to…

Or some advertising on several very popular accounts ...

Re: How I could have hacked any Facebook account

#158

Earlier quoted context omitted.

You may choose (like you actually do) to make-believe whatever you wish about the exploits' worthlessness, but you may also assume that there already were a lot of black hats out there that provided "service" relying on the recently covered security weakness. Also, about the "Facebook's security team is one of the strongest and most sophisticated of any company" mantra, even a mediocre strategist after knowing at lea…

Don't move the goalposts. I'm not saying there aren't black hats that target Facebook. I'm saying none of them will pay $15000, or even $500, for this or any other Fb bug.

"Don't move the goalposts. I'm not saying there aren't black hats that target Facebook."

Actually, you didn't limited yourself to "black hats that target Facebook", you put "he's right" tag on a pretty broad range of remarks! One of them was about the Facebook's super team of security experts (which I answered to, so I'm not sure what goal post moving you've seen, BTW), and another remark was "he would not even be able to find a seller, let alone one who would pay a lot" which I'm not sure I understand from which angle are you looking at things by concluding that "he's right". Let me elaborate a little bit. That bug had enough potential to power an account hacking service derived cash flow for unspecified number of black hats, as the way anyone in possession of something valuable would first and foremost try to use and only secondly - to sell, you know? In such context his remark doesn't even come to make much sense, so I'm not sure how "he's right" in your view.

I've read again dsacco's post and I see another nonsensical remark: "The total impact of the bug would be negligible." How do you judge the impact of the said bug? Would say, disrupting somewhere the digital social connections between some political figures and their mass of followers so they'd loose contact for a while (exactly when it maters) count as "negligible"? Let's stop talking about pranks around TMZ, let's talk about the most lucrative possible cases here. And all this in itself becomes possible because Facebook is a high value target (another fact dismissed by dsacco, whom you consider to be "right").

Finally, about "none of them will pay $15000, or even $500, for this or any other Fb bug" - if right now, it would so happen for me to be willing to pay for a Facebook account hijacking method those $500 (which BTW is a tempting figure), what value would this conviction of yours still hold?

Re: How I could have hacked any Facebook account

#159

beta.facebook.com and mbasic.beta.facebook.com Certificate Transparency has an interesting impact on some of the less-public servers. https://crt.sh/?q=%25.facebook.com A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.

I'm surprised by the amount of certificate fragmentation these companies have. Why would they use so many different certificate types and vendors? Twitter is even worse: https://crt.sh/?q=%25.twitter.com

Re: How I could have hacked any Facebook account

#160

Earlier quoted context omitted.

Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck". I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.

>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun* I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account. You'd have to have a real vendetta against someone to value ruining their life at $15k.

> You'd have to have a real vendetta against someone to value ruining their life at $15k.

You're thinking about it wrong. There is no opportunity cost in their worldview, just lulz to be had at the expense of people they deem worthy of ruination.

(I never said the people that live in the intersection of trolls and blackhats are great at financial or career planning, after all.)

Post reply on HN