lol: "In 2015 alone, 210 researchers received $936,000 with an average payout of $1,780."
Facebook rewarded a 10-year-old for finding Instagram security flaw
21–30 of 90 posts
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#22Any details on how it worked?
http://www.forbes.com/sites/thomasbrewster/2016/05/03/facebo...
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#23Earlier quoted context omitted.
Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.
Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
Realistically though if this an were to become big enough to promote an alternative then Instagram would be all over it and thus fix it within minutes.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#24Earlier quoted context omitted.
Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.
Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
Sounds great. Where do I invest?
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#25Earlier quoted context omitted.
I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!
A bug that allows unauthorized children to delete content from other user's accounts may point to other vulnerabilities, which could have even more value. IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...
If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does.
Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#26Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#27Earlier quoted context omitted.
What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…
Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#28Earlier quoted context omitted.
What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…
Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#29It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#30Earlier quoted context omitted.
Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
I see. So, the business plan here is: outbid Facebook to buy the rights to arrange the commission of, what, tens of thousands of felonies, in order to secure a marginal benefit for a competitor to the world's most popular photo sharing application, where those rights expire instantaneously as soon as one of the best security teams on the planet notices what's happening. Sounds great. Where do I invest?
Also, many people invest in even worse and more fraudulent schemes. Publicly traded companies have scammed entire states and nations, costing dozens of billions to trillions of dollars, all while NYSE investors trade their stock like cash.
Edit: If you can't deal in facts, deal in downmods and unsubstantiated platitudes.