Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

121–130 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#121
post #112

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

What does it mean to be a moral philosopher 'by trade'?

employed (by a university) as a moral philosopher. Interestingly the institute they work for is ethically dubuous (because of how it's funded, not the teaching content)

Re: I Hacked into Facebook's Legal Department Admin Panel

#122
post #85
post #66

Earlier quoted context omitted.

> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…

It’s that second part. “I’m going to do x if you don’t y.” He’s under no obligation to disclose. But the second part is coercion. x itself might also constitute a crime.

Using an "if" doesn't mean coercion if first action is legitimate

- I'm going to refuse your offer if you don't propose something better.

- I'm going to work on it if you don't want to

- I'm going to eat the cake if don't like it

Re: I Hacked into Facebook's Legal Department Admin Panel

#123
post #70

$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.

If you're OK commiting blatantly illegal acts for money you could just go rob a bank, too.

Can someone name this fallacy for me? It sounds like the slippery slope fallacy, but I'm not sure.

Re: I Hacked into Facebook's Legal Department Admin Panel

#124

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

Here in Australia the state funds most medical care. In this case the blackmail vector, if we use that interpretation is the taxation system.

Re: I Hacked into Facebook's Legal Department Admin Panel

#125

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

So, what is your proposed solution for people who find security vulnerabilities in systems? Keep in mind these vulns are worth money in the black market.

I suspect that decent bug bounties, and therefore engendering more competition between white hat and black hat activities is probably the best way to go.

Re: I Hacked into Facebook's Legal Department Admin Panel

#126

Earlier quoted context omitted.

I suppose the illegal part would be the student threatening to disclose the vulnerability to others if you didn't pay. That seems like crossing the line into blackmail and being an accomplice of whoever he discloses to. But the student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. I can see the difficulty though, I guess you'd need to have…

>> student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situatio…

Sounds like a standard Catch-22.

Re: I Hacked into Facebook's Legal Department Admin Panel

#127
post #107
post #65

Earlier quoted context omitted.

2%? You have an interesting idea of the world's population. Just think about what that means. It means 2 out of 100 people can hack into Facebook's Legal Department Admin Panel. I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps. If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 peopl…

Not quite. The US alone graduates 2 million Computer Science students of various stripes every year. It's been graduating (smaller numbers) of them for over 40-50 years now. There are now second and third generation comp sci. workers and graduates. So let's say 1% of 1 million/year are up to this, I suspect it's rather more, but I can't be bothered to do the curve on past graduation rates, and figure out what the wor…

I think you might have looked at the wrong statistic when googling this. According to this site[0] (which is one of the first hits for "computer science graduates per year"), there are 2 million computer science people in the workforce _in total_, which seems far more realistic. Actual number of graduates per year seems to be 65000.

With your numbers (assuming linear growth) after those 40 years, about one third of the total US workforce would now be CS graduates.

[0]: https://datausa.io/profile/cip/computer-science-110701

Re: I Hacked into Facebook's Legal Department Admin Panel

#128

First pentester I found with 12k followers on Instagram: https://www.instagram.com/al_shwele/ but 8 on GitHub: https://github.com/Alaa-abdulridha Instagram keeps surprising me...

The majority of the accounts following him have 0 posts, very low amount of followers and follow thousands of other people. They are most likely bought or collected via an online bot tool. Further quantitative evidence: His posts have a very low amount of likes and comments.

I see this often on twitter. Some account with dozens of thousands of followers, if not more, and very little reaction to their tweet (less than 10 per tweet). It’s obvious to the trained eyes that they just bought followers. I can’t be mad honestly, it’s pretty cheap to signal that you’re a big deal by doing this.

Re: I Hacked into Facebook's Legal Department Admin Panel

#129
post #70

$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.

I always see posts like this, but I’m wondering at what amount of money would people feel like it’s fair?

Re: I Hacked into Facebook's Legal Department Admin Panel

#130

How is this possible? Even in my 1 weekend web apps I ensure password reset tokens are secured against their user and token type, but Facebook, a $720,000,000,000 company, can't do it for their ADMIN site?

There’s fundamentally no difference between a large corp with thousands of employees (who can either use best practice and the secure rails given to them or go wild in their implementations) and a one person company.
Post reply on HN