Live data from Hacker News

Facebook exploit – Confirm website visitor identities

tomanthony.co.uk

51–60 of 61 posts

Re: Facebook exploit – Confirm website visitor identities

#51
post #42

Earlier quoted context omitted.

A bug by the same author (referenced in the article) that allowed anyone to undetectably upload a sitemap to any other person's website (and appear at the top of search results by claiming to be associated with the website) only got $5000, when it could have easily been sold for tens of thousands to blackhat SEO companies. So the answer is probably "way less than street value but still nonzero" http://www.tomanthony.…

Bug bounties don't exist to prevent people from selling exploits on the black market. Those who were going to do so will do it anyways, and companies don't want a scenario where they have to bid against other buyers for such reports. They simply exist as a small incentive for folks who would have otherwise done nothing.

I don't understand your reasoning. If you are a black hat and you can get more money for the bug from the company than from selling it on the black market, why would you sell it on the black market?

Re: Facebook exploit – Confirm website visitor identities

#53
post #51
post #42

Earlier quoted context omitted.

Bug bounties don't exist to prevent people from selling exploits on the black market. Those who were going to do so will do it anyways, and companies don't want a scenario where they have to bid against other buyers for such reports. They simply exist as a small incentive for folks who would have otherwise done nothing.

I don't understand your reasoning. If you are a black hat and you can get more money for the bug from the company than from selling it on the black market, why would you sell it on the black market?

Because maybe I can report it once to the company and make X amount of money, but if the black market price is X / 2, I can potentially sell it many times and make significantly more than X.

Re: Facebook exploit – Confirm website visitor identities

#54
post #53
post #51

Earlier quoted context omitted.

I don't understand your reasoning. If you are a black hat and you can get more money for the bug from the company than from selling it on the black market, why would you sell it on the black market?

Because maybe I can report it once to the company and make X amount of money, but if the black market price is X / 2, I can potentially sell it many times and make significantly more than X.

What I mean by black market price is total amount of money that you can make on that bug selling it on the black market.

Re: Facebook exploit – Confirm website visitor identities

#55
post #47
post #46

Earlier quoted context omitted.

If you participate in a bug bounty program you already decided you will not sell it on The Market. As such you should be payed for your effort and time at least. Otherwise you sell it to whoever pays more (on The Market). If you read how much effort is put into just reporting the bug, that will come close to a half month at least. Is $1000 half a security research's salary?

That is a strange way of thinking about it. Should not Facebook instead incentivize the kind of bug they are interested in, rather than caring how long time it took to find?

They should evaluate fairly how much damage that bug would produce if used by bad actors and pay a percent of that. This is how I see it. Otherwise they are just relying on someone's passion and ethic to stay safe.

Re: Facebook exploit – Confirm website visitor identities

#56
post #6

I found an exploit like this in Google+ back in 2013 that worked in basically the same fashion (script tag and onload/onerror handlers) to identify users, and to tell if they were apart of certain groups. Google fixed the issue, but later wrote back: > The panel has determined your report did not meet the threshold for a reward or credit in our Hall of Fame. Thank you for reporting this issue and good luck with your…

OP here. I had exact same experience (and was aware of your story!). I also found a similar Google bug which didn't receive a bounty [1]. [1] http://www.tomanthony.co.uk/blog/confirm-google-users-email/

Kind of a bummer Google again didn't give a bounty for this type of issue, but also kind of interesting that we had the same experience. Also cool to hear you'd heard of my story before :).

Re: Facebook exploit – Confirm website visitor identities

#57
post #27

Earlier quoted context omitted.

That's a really good bug! But $5k sounds pretty reasonable, since the only alternative market for it comes with pretty obscene legal risk (unlike an RCE, which will have a whole variety of white- and grey- market buyers, an SEO bug seller knows exactly what their buyer is doing with their work).

OP here. Really interesting to get your take on that. From my (far less security educated) POV the Google XML bug felt less risky from a monetisation angle. I guess the difference is between exploiting it yourself vs selling it. There was a clear path to monetisation that didn't require selling the exploit on the black market, and which could well fly under the radar (from my reasonably well educated SEO POV). Howeve…

The logic I'd use is that selling a bug with full knowledge of the specific criminal or tortious activity it will be put to use in is more dangerous than selling a bug that has a relatively diverse market of buyers and for which you'd have strong plausible deniability (not to mention a network of gray-market middlemen insulating you from any actual knowledge of offenses). My mental model of this is Stephen Watt --- but I only know the surface level of what was reported in that case.

Generally just my logic would be: selling bugs for which there's an established market is safer than selling one-off bugs to idiosyncratic buyers.

Re: Facebook exploit – Confirm website visitor identities

#58
post #55
post #47

Earlier quoted context omitted.

That is a strange way of thinking about it. Should not Facebook instead incentivize the kind of bug they are interested in, rather than caring how long time it took to find?

They should evaluate fairly how much damage that bug would produce if used by bad actors and pay a percent of that. This is how I see it. Otherwise they are just relying on someone's passion and ethic to stay safe.

That's essentially what they are doing. You just dispute the percentage they assign.

Re: Facebook exploit – Confirm website visitor identities

#59
post #51
post #42

Earlier quoted context omitted.

Bug bounties don't exist to prevent people from selling exploits on the black market. Those who were going to do so will do it anyways, and companies don't want a scenario where they have to bid against other buyers for such reports. They simply exist as a small incentive for folks who would have otherwise done nothing.

I don't understand your reasoning. If you are a black hat and you can get more money for the bug from the company than from selling it on the black market, why would you sell it on the black market?

That's not what I said. A black hat can still try and sell it to the company, but (1) it won't be through the bug bounty process and (2) they are likely not going to pay "market price", whatever that is.

Re: Facebook exploit – Confirm website visitor identities

#60
post #57

Earlier quoted context omitted.

OP here. Really interesting to get your take on that. From my (far less security educated) POV the Google XML bug felt less risky from a monetisation angle. I guess the difference is between exploiting it yourself vs selling it. There was a clear path to monetisation that didn't require selling the exploit on the black market, and which could well fly under the radar (from my reasonably well educated SEO POV). Howeve…

The logic I'd use is that selling a bug with full knowledge of the specific criminal or tortious activity it will be put to use in is more dangerous than selling a bug that has a relatively diverse market of buyers and for which you'd have strong plausible deniability (not to mention a network of gray-market middlemen insulating you from any actual knowledge of offenses). My mental model of this is Stephen Watt --- b…

That makes absolute sense to me, and I agree.

However, it doesn't cover the aspect that some bugs are directly monetizable without needing to be sold (as was the case with my Google XML Sitemap exploit).

Of course, there is a risk to directly monetizing such a bug too, but the risk calculation is then different.

Post reply on HN