So good on Facebook (this once).
ETA: it was paypal http://seclists.org/fulldisclosure/2013/May/163
51–60 of 90 posts
So good on Facebook (this once).
ETA: it was paypal http://seclists.org/fulldisclosure/2013/May/163
Earlier quoted context omitted.
Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.
Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
- no one, ever
Any details on how it worked?
"The problem lay in a private application programming interface (the slice of code allowing certain outside access) that wasn’t properly checking the person deleting the comment was the same one who posted it, the spokesperson added." http://www.forbes.com/sites/thomasbrewster/2016/05/03/facebo...
Anyone else see this headline and thought, "Some government gave them a 10-year-old?"
Anyone else see this headline and thought, "Some government gave them a 10-year-old?"
Haha yes, that's exactly how I interpreted it. Removing the "with $10,000" from the actual headline made this a bit ambiguous.
Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services? Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?
Anyone else see this headline and thought, "Some government gave them a 10-year-old?"
Earlier quoted context omitted.
A bug that allows unauthorized children to delete content from other user's accounts may point to other vulnerabilities, which could have even more value. IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...
There are no Facebook vulnerabilities that have a value any higher than what Facebook is going to pay for them. If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does. Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?
https://cms-images.idgesg.net/images/article/2014/06/googles...
Earlier quoted context omitted.
Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?
Easy. All the sting operation has to do is make it clear to the seller what the "buyer" "intends" to do with the bug. It doesn't even have to be overt: they could simply say "we are looking to pay $10,000 for a bug that would enable us to download all the private photographs from Justin Bieber's Facebook account".
Meanwhile, Apple remains one of the only big tech companies to not have a bug bounty program.