Live data from Hacker News

Facebook exploit – Confirm website visitor identities

tomanthony.co.uk

1–10 of 61 posts

Re: Facebook exploit – Confirm website visitor identities

#4

Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?

I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out.

But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).

Re: Facebook exploit – Confirm website visitor identities

#5

Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?

It's common in the bug bounty community to write about how you found the bug and how the reporting process went.

Re: Facebook exploit – Confirm website visitor identities

#6
I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back:

> The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your continued bug hunting.

That always kind of rubbed me the wrong way. I found a similar bug in Facebook [1], though it used image size instead of the script tag. Like the OP, I was given $1000. It definitely made me feel a lot more favorable towards Facebook's security team.

[1] http://patorjk.com/blog/2013/03/01/facebook-user-identificat...

Re: Facebook exploit – Confirm website visitor identities

#9

Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?

I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).

Being charitable here, it may be that this exploit showed a breakage in their internal API security process, or an edge case previously unhandled. Perhaps FB had to run an internal audit to find any other endpoints effected by this bug. Buggy endpoints then need to get fixed, tickets get sent out, but with a low priority because this is a low priority bug, and voilà, 6-9 months.

Re: Facebook exploit – Confirm website visitor identities

#10

Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?

> are we looking for something else here?

No. But some people, myself included, are interested in this sort of thing.

It's also interesting to see the timescales of the fix. Posts like this demonstrate that the system worked, albeit perhaps a bit slower than we'd like to imagine.

Whilst the reports of bug hunting apparently within the scope of the bug bounty resulting in a legal team responding with a false dichotomy between an NDA or prosecution are particularly juicy, it's also nice to hear about the cases where that isn't the outcome.

Post reply on HN