Earlier quoted context omitted.
Of course, but it might be worth $100-200k if sold to a third party. Edit: looks like I was wrong!
No, it would be worth much less than $10,000 to anyone else. There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.
Facebook rewarded a 10-year-old for finding Instagram security flaw
71–80 of 90 posts
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#72Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#73Earlier quoted context omitted.
Well the NSA tapped into Google's internal datacenter traffic to steal user information. So some vulnerabilities like that might be useful to them. https://cms-images.idgesg.net/images/article/2014/06/googles...
I'm having trouble connecting your first sentence to your second. It sounds a little like saying "so, the US army has M109 Howitzers, so maybe they'd be interested in this 3D-printed zip gun I just made."
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#74Earlier quoted context omitted.
No, it would be worth much less than $10,000 to anyone else. There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.
So you're saying client-side remote code execution bugs are the hardest to reliably weaponize? Do I understand correctly? I figured those bugs would be the easiest to weaponize.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#75Earlier quoted context omitted.
It depends on the information. This only applies to the US, as the laws are probably difference elsewhere. The CFAA[1] is a very vague and broad law that aims to stop people from accessing systems, sending malicious data, etc. It is intentionally written in such a way to be forgiving to the victim since security is hard by default [citation needed] . So even if you found an exploit without using it yourself, you'll p…
If you exchange money for an exploit that you know will be used to commit a specific crime, you are an accessory to that crime. The CFAA doesn't have much to do with it. Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time. The question isn't whether selling Facebook bugs to the black mar…
> Formerly: founder @ Matasano
Neat! Matasano is what got me into crypto - though my pursuit has since been limited.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#76Meanwhile, Apple remains one of the only big tech companies to not have a bug bounty program.
[1]: I consider them the biggest of them all considering how much of the web is powered by AWS (just imagine if you found an exploit to give you full access to all of AWS), but that's just my opinion.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#77$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to Static site content Source code SSL key pairs iOS and Android app signing keys iOS push notification keys Email server credentials Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys http://exfiltrated.com/research-Instagram-RCE.php
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#78Earlier quoted context omitted.
If you exchange money for an exploit that you know will be used to commit a specific crime, you are an accessory to that crime. The CFAA doesn't have much to do with it. Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time. The question isn't whether selling Facebook bugs to the black mar…
I see you around HN all the time. Clicked your profile. > Formerly: founder @ Matasano Neat! Matasano is what got me into crypto - though my pursuit has since been limited.
I'm glad you liked the crypto stuff we did!
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#79It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#80It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.