Live data from Hacker News

Facebook exploit – Confirm website visitor identities

tomanthony.co.uk

11–20 of 61 posts

Re: Facebook exploit – Confirm website visitor identities

#12
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

How much did Google offer for a security bug (if they would have accepted it)?

Re: Facebook exploit – Confirm website visitor identities

#13

Earlier quoted context omitted.

I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).

Being charitable here, it may be that this exploit showed a breakage in their internal API security process, or an edge case previously unhandled. Perhaps FB had to run an internal audit to find any other endpoints effected by this bug. Buggy endpoints then need to get fixed, tickets get sent out, but with a low priority because this is a low priority bug, and voilà, 6-9 months.

One could also question whether they used the lure of a bounty to keep someone quiet while they let customers (aka advertisers) continue to benefit for an extra 9 months at the expense of the users.

I guess you'd have to consider Facebook's track record in terms of how charitable vs. cynical you want to be in interpreting their actions.

Re: Facebook exploit – Confirm website visitor identities

#14
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

How much did Google offer for a security bug (if they would have accepted it)?

It very much depends on the bug.

Re: Facebook exploit – Confirm website visitor identities

#16
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

$1000 bounty for this seems really low.

Re: Facebook exploit – Confirm website visitor identities

#17
post #13

Earlier quoted context omitted.

Being charitable here, it may be that this exploit showed a breakage in their internal API security process, or an edge case previously unhandled. Perhaps FB had to run an internal audit to find any other endpoints effected by this bug. Buggy endpoints then need to get fixed, tickets get sent out, but with a low priority because this is a low priority bug, and voilà, 6-9 months.

One could also question whether they used the lure of a bounty to keep someone quiet while they let customers (aka advertisers) continue to benefit for an extra 9 months at the expense of the users. I guess you'd have to consider Facebook's track record in terms of how charitable vs. cynical you want to be in interpreting their actions.

Couldn't facebook just provide some secret service for identifying users behind the scenes that regular devs can not access?

Re: Facebook exploit – Confirm website visitor identities

#19
I once (2009) found a similar bug that allowed leaking the ID and personal info of a FB user when their browser loaded a seemingly innocent tag (so it could be embedded in a forum post, for example).

Sadly, it was before FB had a bug bounty program, so I didn't receive anything after I contacted them and they fixed the issue. I wrote about it here: http://blog.quaji.com/2009/07/facebook-personal-info-leak.ht...

Re: Facebook exploit – Confirm website visitor identities

#20
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

[deleted]
Post reply on HN