Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

101–110 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#101

$7500? Why are these bug bounties so piddling? How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?

Except going to the black market is not legal and Facebook already knows of the exploit, so... People have been imprisoned for less.

Re: I Hacked into Facebook's Legal Department Admin Panel

#102
post #84

How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....

I think it depends on team dynamics. On a team I was on (Fortune 100 company), a techlead would just buddy up with a very junior one, and have them rubber stamp their code review. The techlead almost committed a bug similar to one in this post- I had to step in and leave a review comment to prevent this vulnerability. I almost wanted to have it shipped to get back at at these code review buddies, but decided against it as I valued not having a vulnerability more.

Re: I Hacked into Facebook's Legal Department Admin Panel

#103
post #43
post #39

Earlier quoted context omitted.

Describing that work as "being naked in front of a webcam" is like calling software development "typing at a computer". You can make any job sounds trivial and downplay its value by describing it in a way that removes the skill and effort involved. I'm not sure why you feel the need to imply some else's work isn't valuable to make the point that this work should be more valuable.

ok, I'll bite. What kind of skill to you need to have, besides being born attractive, to succeed in such business?

Besides the obvious falsehood that being attractive is being 'born attractive', onlyfans and such sites are full of very attractive people who suck at marketing, customer engagement, etc, who essentially make beer money being naked (with the hope that things will spike up 'real soon now').

The people at the top have a lot of hard-work, skill, and "being born attractive". Sex work is work.

Re: I Hacked into Facebook's Legal Department Admin Panel

#104
post #57
post #45

Earlier quoted context omitted.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

It was always thus. In fact, until the ‘60s, a girl had to rely on her beauty and personality to eat and survive , i.e. by marrying. I have a daughter and, while obviously I’d prefer she didn’t end up on onlyfans, I really don’t want to limit what she should do or what talent she should leverage to reach happiness and/or prosperity.

> It was always thus. In fact, until the ‘60s, a girl had to rely on her beauty and personality to eat and survive, i.e. by marrying.

The way this is framed today by people is soo disgusting.

1) Women did work before 1960.

2) Two incomes are better than one. Married couples are better off financially. Many women worked part time while the children were at school or in the evenings when the husband was back at home. I know this because my grandmother did and many of her friends.

3) A married couple typically provides the best environment for raising children. Most people want children.

4) Most people were dirt poor in the past in the western world by today's standards.

Re: I Hacked into Facebook's Legal Department Admin Panel

#105
post #66

Earlier quoted context omitted.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

I suppose the illegal part would be the student threatening to disclose the vulnerability to others if you didn't pay. That seems like crossing the line into blackmail and being an accomplice of whoever he discloses to. But the student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. I can see the difficulty though, I guess you'd need to have…

>> student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay.

Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situation?

Re: I Hacked into Facebook's Legal Department Admin Panel

#106
post #66

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

There’s no harm in making a demand. It’s adding “or else” that would get you in trouble. In this case that would be extortion.

Re: I Hacked into Facebook's Legal Department Admin Panel

#107
post #65

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

2%? You have an interesting idea of the world's population. Just think about what that means. It means 2 out of 100 people can hack into Facebook's Legal Department Admin Panel. I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps. If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 peopl…

Not quite. The US alone graduates 2 million Computer Science students of various stripes every year. It's been graduating (smaller numbers) of them for over 40-50 years now. There are now second and third generation comp sci. workers and graduates.

So let's say 1% of 1 million/year are up to this, I suspect it's rather more, but I can't be bothered to do the curve on past graduation rates, and figure out what the world wide figure is... you've easily got a couple of million people world wide.

When I think it's going to get really interesting is in another 10 years or so when there start to be significant numbers of bored retired former developers. At any rate the market rate probably isn't that bad.

Re: I Hacked into Facebook's Legal Department Admin Panel

#109
post #75

Earlier quoted context omitted.

> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…

>Thank god for that. Blog posts like the one this thread is about are really valuable to those of us interested in the work of others. I can see how what I said could be interpreted as 'folks that blog about their work are narcissists'. That wasn't my intent. The headline is a bit clickbaity but the explanation is a good walkthrough. This isn't the far end of the spectrum that I had in mind. Watching twitter or worki…

I worked for several bug bounty programs; showboating didn't really seem to be a major issue.

Re: I Hacked into Facebook's Legal Department Admin Panel

#110

Earlier quoted context omitted.

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required. Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilit…

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

>> Which is essentially market driven blackmail as far as I can see.

Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

Post reply on HN