Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

31–40 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#31
post #24

Earlier quoted context omitted.

I see. So, the business plan here is: outbid Facebook to buy the rights to arrange the commission of, what, tens of thousands of felonies, in order to secure a marginal benefit for a competitor to the world's most popular photo sharing application, where those rights expire instantaneously as soon as one of the best security teams on the planet notices what's happening. Sounds great. Where do I invest?

Best security teams on the planet? You are talking about Instagram? I've read multiple reports of their properties being completely owned in the last few months, just here. The fact that they are still up is a testament to the researchers who reported the errors to FB. Also, many people invest in even worse and more fraudulent schemes. Publicly traded companies have scammed entire states and nations, costing dozens o…

Yes, Facebook has one of the best security teams on the planet.

No, nobody is going to invest in this scheme.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#33
post #32
post #19

Awesome kid, but how was this risk only worth $10k to facebook? Needs a few more zeros behind it.

no idea why this is getting downvoted.

Because it's an extraordinarily silly comment. If Facebook hadn't paid $10,000 for this bug, the next bidder in line would have been unlikely to pay more than $50.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#34

Earlier quoted context omitted.

What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?

It depends on the information.

This only applies to the US, as the laws are probably difference elsewhere. The CFAA[1] is a very vague and broad law that aims to stop people from accessing systems, sending malicious data, etc. It is intentionally written in such a way to be forgiving to the victim since security is hard by default [citation needed]. So even if you found an exploit without using it yourself, you'll probably be charged with aiding and abetting or something similar.

[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#35
post #32
post #19

Awesome kid, but how was this risk only worth $10k to facebook? Needs a few more zeros behind it.

no idea why this is getting downvoted.

Perhaps it's because you're being unrealistic? A version of this comment seems to pop up in every bug bounty related thread.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#36
post #18
post #7

Earlier quoted context omitted.

I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!

Previous commenters on HN have thought differently https://news.ycombinator.com/item?id=10795785 ;)

It is the same commentator. It appears in this most recent comment he neglected to add a sarcasm indicator.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#37
Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services?

Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#38
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

A bird in the hand is better than two in the bush.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#39
post #33
post #32

Earlier quoted context omitted.

no idea why this is getting downvoted.

Because it's an extraordinarily silly comment. If Facebook hadn't paid $10,000 for this bug, the next bidder in line would have been unlikely to pay more than $50.

Vickrey auctions to the rescue.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#40

Earlier quoted context omitted.

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?

It depends on the information. This only applies to the US, as the laws are probably difference elsewhere. The CFAA[1] is a very vague and broad law that aims to stop people from accessing systems, sending malicious data, etc. It is intentionally written in such a way to be forgiving to the victim since security is hard by default [citation needed] . So even if you found an exploit without using it yourself, you'll p…

If you exchange money for an exploit that you know will be used to commit a specific crime, you are an accessory to that crime. The CFAA doesn't have much to do with it.

Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time.

The question isn't whether selling Facebook bugs to the black market is itself illegal. It's whether the DOJ could set up a sting to capitalize on the greed of people who would do that. Yes, they could.

It's not not legally risky, either, especially in the case of bugs like these, where you've been given permission to attack Facebook's servers only in conjunction with their bounty program --- your civil liability to a website that doesn't run a bounty, if you sold a bug you found in their site and it was used in some way to harm them, could be astronomical.

Post reply on HN