Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

61–70 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#61

Earlier quoted context omitted.

"The problem lay in a private application programming interface (the slice of code allowing certain outside access) that wasn’t properly checking the person deleting the comment was the same one who posted it, the spokesperson added." http://www.forbes.com/sites/thomasbrewster/2016/05/03/facebo...

I'm hoping the bug was a little more complicated than just "we forgot to check." That's a pretty dumb mistake to make...

Do you see how the PS3 security system was thwarted?[1]

1: http://www.engadget.com/2010/12/29/hackers-obtain-ps3-privat...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#62
post #58
post #25

Earlier quoted context omitted.

There are no Facebook vulnerabilities that have a value any higher than what Facebook is going to pay for them. If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does. Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?

Well the NSA tapped into Google's internal datacenter traffic to steal user information. So some vulnerabilities like that might be useful to them. https://cms-images.idgesg.net/images/article/2014/06/googles...

I'm having trouble connecting your first sentence to your second. It sounds a little like saying "so, the US army has M109 Howitzers, so maybe they'd be interested in this 3D-printed zip gun I just made."

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#63
$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to

Static site content

Source code

SSL key pairs

iOS and Android app signing keys

iOS push notification keys

Email server credentials

Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys

http://exfiltrated.com/research-Instagram-RCE.php

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#64
post #7
post #3

Earlier quoted context omitted.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!

> I know, right? $10,000! Facebook is worth billions!

But is causing monetary loss to Facebook, specifically, worth much to anybody? Anybody who would take the risk of committing a crime to do so?

This bug deletes content on Instagram. Unless you are the most underhanded of Instagram competitors, or just want to cause wanton Instagram picture destruction, I don't see why you as a third party would pay for it. Also, since I assume FB has backups, this is at most a relatively sophisticated DOS attack. Now, if you could insert data then you have stage 1 of a APT deployment platform, which is a whole other story.

Also, you underestimate the lifetime potential earnings won of "I discovered an attack on one of the 2-3 most popular internet platforms on earth at 13 and practiced textbook responsible disclosure with it". Beyond that, selling bugs to the highest bidder is very hard to justify, ethically speaking, and a lot of people put a high price on their integrity.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#65
post #45

Earlier quoted context omitted.

Don't underestimate the value of money that's guaranteed instead of a hypothetical possibility, now instead of maybe sometime, yours free and clear instead of legally dodgy, that you can boast to friends and future potential employers about instead of hiding as a shameful secret.

I agree, except I'm pretty sure Facebook and other bug bounty programs don't guarantee payment.

True, but they usually do by the time they say that you will be paid.

I think the argument that a black market sale of an exploit won't necessarily be as clear cut is still valid.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#66
post #55

Earlier quoted context omitted.

Haha yes, that's exactly how I interpreted it. Removing the "with $10,000" from the actual headline made this a bit ambiguous.

A ten year old with $10,000. ;) That's more money than most kids that age have to their name.

In straight cash USD, that's more money than most people in the world have to their name.

[Edit: straight cash == completely liquid assets]

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#67
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn't be available...

They fixed the issue pretty fast, but what bugs me is that I didn't get a thank you. I wasn't looking to gain anything, but I figure telling someone that their site is exposed warrants some gratitude.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#68
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn…

That's why I:

- Stopped reporting anything that is not an issue in the source code of an open source project. I do so in their mailing lists or issue tracker.

- Began to treat random internet bug reports with kindness and gratitude.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#69
post #66
post #55

Earlier quoted context omitted.

A ten year old with $10,000. ;) That's more money than most kids that age have to their name.

In straight cash USD, that's more money than most people in the world have to their name. [Edit: straight cash == completely liquid assets]

Agreed. Even most USians.

(I was just playing on the idea of FB getting a kid and saying getting one w/cash was even better!)

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#70
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

If I find a wallet on the ground, I try to return it to the owner even if there's no reward and even if I'm not legally obligated to do so. I'd want someone who finds my wallet to do the same.
Post reply on HN