Facebook rewarded a 10-year-old for finding Instagram security flaw
11–20 of 90 posts
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#12It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#13Earlier quoted context omitted.
>> "Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me." The same reasons people don't steal from shops or commit other crimes: 1. Morals 2. Risk of getting caught and subsequent punishment
3. Nobody wants to buy Facebook bugs besides Facebook.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#14Earlier quoted context omitted.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!
IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#15Earlier quoted context omitted.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…
On what basis could law enforcement act undercover to trap sellers?
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#16It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Long story short, companies offer guaranteed set-size rewards as a counterpoint to the black market's potential highly variant payouts.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#17Earlier quoted context omitted.
3. Nobody wants to buy Facebook bugs besides Facebook.
Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.
If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram.
Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model...
[0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#18Earlier quoted context omitted.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!