Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

161–168 of 168 posts

Re: How I could have hacked any Facebook account

#161

Earlier quoted context omitted.

Don't move the goalposts. I'm not saying there aren't black hats that target Facebook. I'm saying none of them will pay $15000, or even $500, for this or any other Fb bug.

"Don't move the goalposts. I'm not saying there aren't black hats that target Facebook." Actually, you didn't limited yourself to "black hats that target Facebook", you put "he's right" tag on a pretty broad range of remarks! One of them was about the Facebook's super team of security experts (which I answered to, so I'm not sure what goal post moving you've seen, BTW), and another remark was "he would not even be ab…

I would say you were paying $500 for a vanity bug, and not be especially surprised.

What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs.

You might find someone in --- another part of the world, let's say --- who would offer you a couple thousand for that bug. You should know, if you're ever in a position to make that deal, that the person who is buying it from you is willing to kill your whole family to make a point, because that is the reason they are buying the bug from you.

But you aren't going to find that person, any more than you're going to easily find someone to sell a portable antiaircraft missile to.

Re: How I could have hacked any Facebook account

#162

Earlier quoted context omitted.

"Don't move the goalposts. I'm not saying there aren't black hats that target Facebook." Actually, you didn't limited yourself to "black hats that target Facebook", you put "he's right" tag on a pretty broad range of remarks! One of them was about the Facebook's super team of security experts (which I answered to, so I'm not sure what goal post moving you've seen, BTW), and another remark was "he would not even be ab…

I would say you were paying $500 for a vanity bug, and not be especially surprised. What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs. You might find someone in --- another part of the world, let's say --- who would offer you a couple thousand for that bug. You should know, if you're ever in a position to make that deal, that the person who is buying…

"I would say you were paying $500 for a vanity bug"

No, it would be just an (admittedly shady) business investment.

"What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs."

You either didn't read my post or you are deliberately ignoring it. dsacco was wrong on so many aspects and so were you when supported him, as for what you're doing now... I'm not sure what to make of it!

Re: How I could have hacked any Facebook account

#163

Earlier quoted context omitted.

I would say you were paying $500 for a vanity bug, and not be especially surprised. What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs. You might find someone in --- another part of the world, let's say --- who would offer you a couple thousand for that bug. You should know, if you're ever in a position to make that deal, that the person who is buying…

"I would say you were paying $500 for a vanity bug" No, it would be just an (admittedly shady) business investment. "What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs." You either didn't read my post or you are deliberately ignoring it. dsacco was wrong on so many aspects and so were you when supported him, as for what you're doing now... I'm not sur…

I'm sorry, but I don't see anything in this comment that is responsive to anything I've written or that introduces any new argument for me to respond to.

Re: How I could have hacked any Facebook account

#164

This has me thinking about another possible attack. Say I don't want to hack all of Facebook or a specific account. What if I used a botnet to reset passwords and then use the six attempts randomly on each account I reset. Sure I'd only get a small percentage but, I would easily start hacking FB accounts. It's things like this that make me use 2FA as much as possible on personal data.

Facebook likely makes the challenge harder if there is no history on the device you are trying to reset your password on.

Re: How I could have hacked any Facebook account

#165
post #110
post #93

Earlier quoted context omitted.

The info is useful, but not sellable? The two seem deeply intertwined. If I can prove usefulness, I can sell it. Actually, you say the info has "a use"... does that not directly imply worth?

The info might be useful to someone, but not to the people who are buying vulnerabilities on the black market. Imagine going to a tech trade show and setting up a stand for your lumber business. What you're selling has value and is useful, just not to the people you're trying to sell it to.

Let's assume the position of a spammer or ~0-day blackhatter... access to the accounts of the most popular website in the world are not of interest? (You could post a URL and have millions of people click it because they trust the poster.)

Re: How I could have hacked any Facebook account

#166
post #99

Earlier quoted context omitted.

Is that a retort or simply an unrelated observation? Edit: My intent was to understand your perspective (and argue...), but this comment goes over my head, and it seems as though it was a thinly veiled insult.

Not an insult. https://news.ycombinator.com/item?id=11251104

If you could have been more direct, I would have been more receptive to learning, rather than confusion and feeling excluded.

Re: How I could have hacked any Facebook account

#167

Earlier quoted context omitted.

"I would say you were paying $500 for a vanity bug" No, it would be just an (admittedly shady) business investment. "What 'dsacco is saying is essentially factual. The places that buy vulnerabilities don't buy Fb account takeover bugs." You either didn't read my post or you are deliberately ignoring it. dsacco was wrong on so many aspects and so were you when supported him, as for what you're doing now... I'm not sur…

I'm sorry, but I don't see anything in this comment that is responsive to anything I've written or that introduces any new argument for me to respond to.

> I don't see anything in this comment [...] for me to respond to

Yet you did it anyway! :)

Actually, he did begin by responding something useful to what you've written.

Re: How I could have hacked any Facebook account

#168

Earlier quoted context omitted.

Unless your name is Kevin Mitnick. Then you set up a business and play middlemen in selling them to anybody who wants to pony up for it. "When we have a client that wants a zero-day vulnerability for whatever reason, we don’t ask, and in fact they wouldn’t tell us,” Mitnick tells WIRED in an interview. “Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.” h…

How is this legal?

Why wouldn't it be? Someone looks at a program that they bought and paid for, and sees that it has a mistake. They didn't write the software or put the mistake there. How can it be a crime for them to become aware of behavior in someone else's program?

Attacking others who use the software is an entirely different story of course.

Post reply on HN