Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

71–80 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#71
post #43

Earlier quoted context omitted.

Of course, but it might be worth $100-200k if sold to a third party. Edit: looks like I was wrong!

No, it would be worth much less than $10,000 to anyone else. There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.

So you're saying client-side remote code execution bugs are the hardest to reliably weaponize? Do I understand correctly? I figured those bugs would be the easiest to weaponize.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#73
post #62
post #58

Earlier quoted context omitted.

Well the NSA tapped into Google's internal datacenter traffic to steal user information. So some vulnerabilities like that might be useful to them. https://cms-images.idgesg.net/images/article/2014/06/googles...

I'm having trouble connecting your first sentence to your second. It sounds a little like saying "so, the US army has M109 Howitzers, so maybe they'd be interested in this 3D-printed zip gun I just made."

I'm not talking about the vulnerability that this kid found. I'm talking about vulnerabilities that would allow access deep into the Facebook infrastructure. I think there are in fact some vulnerabilities the NSA would be willing to pay more than $10k for if it would allow them long term access to a lot of sensitive Facebook data.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#74
post #43

Earlier quoted context omitted.

No, it would be worth much less than $10,000 to anyone else. There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.

So you're saying client-side remote code execution bugs are the hardest to reliably weaponize? Do I understand correctly? I figured those bugs would be the easiest to weaponize.

We mean different things, and it's me being imprecise. Substitute "generate" for "weaponize".

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#75
post #40

Earlier quoted context omitted.

It depends on the information. This only applies to the US, as the laws are probably difference elsewhere. The CFAA[1] is a very vague and broad law that aims to stop people from accessing systems, sending malicious data, etc. It is intentionally written in such a way to be forgiving to the victim since security is hard by default [citation needed] . So even if you found an exploit without using it yourself, you'll p…

If you exchange money for an exploit that you know will be used to commit a specific crime, you are an accessory to that crime. The CFAA doesn't have much to do with it. Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time. The question isn't whether selling Facebook bugs to the black mar…

I see you around HN all the time. Clicked your profile.

> Formerly: founder @ Matasano

Neat! Matasano is what got me into crypto - though my pursuit has since been limited.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#76

Meanwhile, Apple remains one of the only big tech companies to not have a bug bounty program.

You've forgotten the biggest of them all: Amazon [1].

[1]: I consider them the biggest of them all considering how much of the web is powered by AWS (just imagine if you found an exploit to give you full access to all of AWS), but that's just my opinion.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#77
post #63

$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to Static site content Source code SSL key pairs iOS and Android app signing keys iOS push notification keys Email server credentials Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys http://exfiltrated.com/research-Instagram-RCE.php

Because he broke the rules: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#78
post #40

Earlier quoted context omitted.

If you exchange money for an exploit that you know will be used to commit a specific crime, you are an accessory to that crime. The CFAA doesn't have much to do with it. Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time. The question isn't whether selling Facebook bugs to the black mar…

I see you around HN all the time. Clicked your profile. > Formerly: founder @ Matasano Neat! Matasano is what got me into crypto - though my pursuit has since been limited.

Indeed, it is I, Sardo Numspaa!

I'm glad you liked the crypto stuff we did!

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#79
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

That, and it's great that Facebook offers an incentive to bug hunting, rather than treating the researchers like criminals, as some companies are known to do. I don't care for a lot of what Facebook does and how they do it, but this in particular is awesome of them.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#80
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

I don't think it's that simple of a decision, or one that could be generalised to all cases. What if you found an exploit that let you break a widespread form of DRM, access normally paywalled information, or gain control of a device that you rightfully own but the manufacturer locked down against you? It really depends on your moral/philosophical stance, but all the money in the world wouldn't make me report any of those. That's why the idea of someone so young already thinking of becoming a "security researcher" bugs (no pun intended) me, because they all seem to inevitably end up proponents of "security that oppresses" in some form or another.

Related: https://en.wikipedia.org/wiki/Hacker_ethic

Post reply on HN