Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

11–20 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#12
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

People do. There is an entire underground markets for exploits, hacked user databases/emails, Amazon AWS keys etc.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#13
post #8

Earlier quoted context omitted.

>> "Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me." The same reasons people don't steal from shops or commit other crimes: 1. Morals 2. Risk of getting caught and subsequent punishment

3. Nobody wants to buy Facebook bugs besides Facebook.

Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#14
post #7
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!

A bug that allows unauthorized children to delete content from other user's accounts may point to other vulnerabilities, which could have even more value.

IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#15
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing?

On what basis could law enforcement act undercover to trap sellers?

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#16
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

If you had this exploit, how would you have monetized it? Do you know who to talk to? Do you know where to go on the darkweb to find the people who know the people who have the money to actually pay you for this? Do you know how to negotiate with them to actually guarantee payment? Do you know how much an exploit which can only delete content -- not generate false content, or access ACL'd content -- is actually worth?

Long story short, companies offer guaranteed set-size rewards as a counterpoint to the black market's potential highly variant payouts.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#17
post #13
post #8

Earlier quoted context omitted.

3. Nobody wants to buy Facebook bugs besides Facebook.

Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.

Presumably an Instagram rival could find it useful.

If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram.

Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model...

[0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#18
post #7
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!

Previous commenters on HN have thought differently https://news.ycombinator.com/item?id=10795785 ;)
Post reply on HN