Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

41–50 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#41
post #9

Earlier quoted context omitted.

He's 10. Who is he going to sell this to? $10,000 is probably a gigantic amount of money to him.

its a lot money to most people.

Of course, but it might be worth $100-200k if sold to a third party.

Edit: looks like I was wrong!

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#42
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

If you had this exploit, how would you have monetized it? Do you know who to talk to? Do you know where to go on the darkweb to find the people who know the people who have the money to actually pay you for this? Do you know how to negotiate with them to actually guarantee payment? Do you know how much an exploit which can only delete content -- not generate false content, or access ACL'd content -- is actually worth…

Companies like Facebook offer rewards as an incentive to get people to report bugs to them rather than to blog posts. The next highest bidder anywhere in the world for bugs like these is ε.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#43
post #9

Earlier quoted context omitted.

its a lot money to most people.

Of course, but it might be worth $100-200k if sold to a third party. Edit: looks like I was wrong!

No, it would be worth much less than $10,000 to anyone else.

There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#45
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

Don't underestimate the value of money that's guaranteed instead of a hypothetical possibility, now instead of maybe sometime, yours free and clear instead of legally dodgy, that you can boast to friends and future potential employers about instead of hiding as a shameful secret.

I agree, except I'm pretty sure Facebook and other bug bounty programs don't guarantee payment.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#46
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

Don't underestimate the professional value of disclosing a vulnerability to the company And I don't solely Mean the value of the publicity and the exposure of being public about the disclosure. The security community is surprisingly small. Getting a one off splash story in a rag like Business Insider is nothing compared to building a back and forth with Someone like Alex Stamos.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#47

Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services? Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?

In this case, seeing as COPPA is a US law and the kid in question is from Finland (and thus likely under Facebook's EU subsidiary), I'm guessing not.
Post reply on HN