Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

51–60 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#52
post #13

Earlier quoted context omitted.

Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.

Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...

"Weird, some of my comments disappeared. Well, I guess it's time to completely reboot my social media profile on a new service!"

- no one, ever

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#53
post #11

Any details on how it worked?

"The problem lay in a private application programming interface (the slice of code allowing certain outside access) that wasn’t properly checking the person deleting the comment was the same one who posted it, the spokesperson added." http://www.forbes.com/sites/thomasbrewster/2016/05/03/facebo...

I'm hoping the bug was a little more complicated than just "we forgot to check." That's a pretty dumb mistake to make...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#55
post #48

Anyone else see this headline and thought, "Some government gave them a 10-year-old?"

Haha yes, that's exactly how I interpreted it. Removing the "with $10,000" from the actual headline made this a bit ambiguous.

A ten year old with $10,000. ;) That's more money than most kids that age have to their name.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#56

Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services? Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?

[deleted]

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#58
post #25

Earlier quoted context omitted.

A bug that allows unauthorized children to delete content from other user's accounts may point to other vulnerabilities, which could have even more value. IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...

There are no Facebook vulnerabilities that have a value any higher than what Facebook is going to pay for them. If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does. Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?

Well the NSA tapped into Google's internal datacenter traffic to steal user information. So some vulnerabilities like that might be useful to them.

https://cms-images.idgesg.net/images/article/2014/06/googles...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#59
post #28

Earlier quoted context omitted.

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?

Easy. All the sting operation has to do is make it clear to the seller what the "buyer" "intends" to do with the bug. It doesn't even have to be overt: they could simply say "we are looking to pay $10,000 for a bug that would enable us to download all the private photographs from Justin Bieber's Facebook account".

[deleted]

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#60

Meanwhile, Apple remains one of the only big tech companies to not have a bug bounty program.

what about cisco, oracle, juniper, fireeye, palo alto, etc.? There are more companies who don't than do, hopefully it changes in the near future though.
Post reply on HN