Live data from Hacker News

Facebook exploit – Confirm website visitor identities

tomanthony.co.uk

21–30 of 61 posts

Re: Facebook exploit – Confirm website visitor identities

#21
post #19

I once (2009) found a similar bug that allowed leaking the ID and personal info of a FB user when their browser loaded a seemingly innocent tag (so it could be embedded in a forum post, for example). Sadly, it was before FB had a bug bounty program, so I didn't receive anything after I contacted them and they fixed the issue. I wrote about it here: http://blog.quaji.com/2009/07/facebook-personal-info-leak.ht...

Using a Facebook exploit for anything less than causing as much damage to Facebook as possible is a sign of severe moral impotence. Siding with Facebook and selling out for their bug bounty bribe is bad enough, but to do it for free deserves some sort of punishment.

Re: Facebook exploit – Confirm website visitor identities

#23
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

How much did Google offer for a security bug (if they would have accepted it)?

A bug by the same author (referenced in the article) that allowed anyone to undetectably upload a sitemap to any other person's website (and appear at the top of search results by claiming to be associated with the website) only got $5000, when it could have easily been sold for tens of thousands to blackhat SEO companies. So the answer is probably "way less than street value but still nonzero"

http://www.tomanthony.co.uk/blog/google-xml-sitemap-auth-byp...

Re: Facebook exploit – Confirm website visitor identities

#24

Is there something in here we're missing? Someone finds exploit, gets the bounty, facebook fixes and we have a timeline. Sounds like the system worked... are we looking for something else here?

I don't think there's much to see here...it is a cool bug though that doesn't require a super high level understanding of security to figure out. But a 6-9 month time to fix seems really long (also I would have thought a $1000 bug bounty is low for this type of exploit...but then again I'm not in this space too much to know the average rewards).

The thing to also keep in mind is that the bug bounty teams are typically centralized and not embedded within the product teams of the services being reported on. They certainly get prioritized attention, but there are still layers of communication to report the issue, follow up with devs or reporter if there are questions or difficulties reproducing the issue, prioritize the issue, fix the bug and deploy to prod.

Not to say that’s the way it is at Facebook, just what I’ve seen in the past.

Re: Facebook exploit – Confirm website visitor identities

#25
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

How much did Google offer for a security bug (if they would have accepted it)?

https://www.google.com/about/appsecurity/reward-program/inde...

Looks like up to $30k per bug.

Re: Facebook exploit – Confirm website visitor identities

#26
post #16
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

$1000 bounty for this seems really low.

Why? There's no market for this bug. Nobody else will buy it. If you found an equivalent bug in, say, Grubhub, nobody would think it was worth much more than a token bounty. Is it just because Facebook is a big company and can afford to pay more for every bug, or is there a particular reason you think this bug is super valuable?

Re: Facebook exploit – Confirm website visitor identities

#27

Earlier quoted context omitted.

How much did Google offer for a security bug (if they would have accepted it)?

A bug by the same author (referenced in the article) that allowed anyone to undetectably upload a sitemap to any other person's website (and appear at the top of search results by claiming to be associated with the website) only got $5000, when it could have easily been sold for tens of thousands to blackhat SEO companies. So the answer is probably "way less than street value but still nonzero" http://www.tomanthony.…

That's a really good bug! But $5k sounds pretty reasonable, since the only alternative market for it comes with pretty obscene legal risk (unlike an RCE, which will have a whole variety of white- and grey- market buyers, an SEO bug seller knows exactly what their buyer is doing with their work).

Re: Facebook exploit – Confirm website visitor identities

#28
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

When you disclose hacks on the Pareto Network the market values it instead of arbitrary panels.

This is better for researchers because they don't have to risk liability by weaponizing an exploit, and they also don't get lowballed by the companies who have arbitrary policies and arbitrary payouts that aren't compatible with responsible disclosure.

Re: Facebook exploit – Confirm website visitor identities

#29
post #26
post #16

Earlier quoted context omitted.

$1000 bounty for this seems really low.

Why? There's no market for this bug. Nobody else will buy it. If you found an equivalent bug in, say, Grubhub, nobody would think it was worth much more than a token bounty. Is it just because Facebook is a big company and can afford to pay more for every bug, or is there a particular reason you think this bug is super valuable?

[deleted]

Re: Facebook exploit – Confirm website visitor identities

#30
post #26
post #16

Earlier quoted context omitted.

$1000 bounty for this seems really low.

Why? There's no market for this bug. Nobody else will buy it. If you found an equivalent bug in, say, Grubhub, nobody would think it was worth much more than a token bounty. Is it just because Facebook is a big company and can afford to pay more for every bug, or is there a particular reason you think this bug is super valuable?

TFA: "In addition, the most sinister exploiters (e.g. a repressive regime) of such a bug would likely have a list of people they cared about identifying (which they could also narrow down based on your location and other factors)."

Wouldn't such orgs (or their vendors) pay at least $1k to find the people they want? I don't know what the right formula is to calculate bounty vs. expected black market value, but you only said nobody would buy it at all.

Post reply on HN