Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

71–80 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#71
post #45

Earlier quoted context omitted.

>but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad. >some of the only fans users makes in a month what a plain SE would make in a year I'm sure if you could think of a way to make software engineers as appealing as naked women, you'd probably find yourself a pretty great job paying well over the people on onlyfans.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

>who was my counselor, runs several projects trying to make SE and CS more attractive to girls.

This is a good thing. Sorry if my above comment was dismissive and callous. Honestly, it is kind of sad as a society, that's what ends up being valued more highly.

>knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers.

That's not really anything new. Such things have always existed.

To be honest, my comment was mainly in reference to the business model itself. It's hard to compare a salary or wage with lots of money from donations or subscriptions.

I'm sure there's people on onlyfans that make barely anything and there's lots of software engineers with high paying jobs.

>Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenager she'll be interested in STEM.

I dunno, teach her self respect and explain the value in success using ones talents and abilities as opposed to exploiting their appearance or bodies.

There's always been the option for girls to do the second one. I'm glad your teacher and people like her are trying hard to give girls more options like the first.

Re: I Hacked into Facebook's Legal Department Admin Panel

#72
post #70

$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.

How do you know if this is happening or not?

Re: I Hacked into Facebook's Legal Department Admin Panel

#73
post #48
post #33

Earlier quoted context omitted.

A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…

Didn’t say it was easy to monetize. I do recall a bust, some time ago, of a ring that used prerelease (?) announcement pdfs already placed on publicly accessible servers (?) as a source of insider alpha. (‘?’ because I’m on my third whiskey and about to turn in :)

Yeah, the response is purely in context of the mentions of "black market" value higher up the thread. Being able to turn potential gain for someone into actual money for you is the key issue.

Re: I Hacked into Facebook's Legal Department Admin Panel

#74
post #66

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

Unless litigating students is something your startup is interested in, I’d recommend ignoring that line of thinking and just hiring a good pen tester for a few months.

Re: I Hacked into Facebook's Legal Department Admin Panel

#75
post #42

Earlier quoted context omitted.

Totally agree with your perspective here. There's security research and there's bug prospecting. Both have streaks of narcissists and showboaters but the latter seems to be thick with them. (edit: to clarify b/c this can easily be interpreted otherwise, I'm not calling the writer of this article either of those. The headline is a bit of cheap clickbait but the article is a good walkthrough of their mindset)

> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…

>Thank god for that. Blog posts like the one this thread is about are really valuable to those of us interested in the work of others.

I can see how what I said could be interpreted as 'folks that blog about their work are narcissists'. That wasn't my intent. The headline is a bit clickbaity but the explanation is a good walkthrough. This isn't the far end of the spectrum that I had in mind. Watching twitter or working for a bug bounty program is a better way to get exposed to that set.

Re: I Hacked into Facebook's Legal Department Admin Panel

#76
post #45

Earlier quoted context omitted.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

So... that's just not how any of that works. Do you really think most of the women you know are choosing to be on onlyfans and are making huge money off it? Hint, no. Not a choice most would make and most accounts there are not making anykind of money like that. But you seem really upset about all this. To be clear, what you are mad about is how there are lots of men willing to pay to see naked and sexual content onl…

not at all. sex workers will exists forever. I guess my beef is how easy it is for young girls to become one now. Are you struggling with calculus? Is physics giving you a hard time? Well, let me tell you about only fans...

Joke apart, the appeal were already there. making money from the comfort of your bed. Seeing the how much money you can make thought, that's what really broke my back.

Re: I Hacked into Facebook's Legal Department Admin Panel

#77
post #33
post #19

Earlier quoted context omitted.

Isn’t legal involved in most business moves? Getting a wind of those ahead of a public announcement surely must be worth something ;)

A "market" needs a bit more than "is worth something". What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a…

In other words, how much would Pepsi pay for the secret recipe to Coke?

Re: I Hacked into Facebook's Legal Department Admin Panel

#78
post #66

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required.

Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilities.

Re: I Hacked into Facebook's Legal Department Admin Panel

#79
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

In the US, yes. Unauthorized access and computer trespass is often felonious. People have gone to prison for logging into an email account by guessing the password.

Re: I Hacked into Facebook's Legal Department Admin Panel

#80
post #66

Earlier quoted context omitted.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required. Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilit…

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.
Post reply on HN