Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

131–140 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#131
post #84

How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....

I assume project handed from one person to another, one of them kept notes outside the code, maybe got fired.

Or an intranet app originally and devs not expecting it to be exposed to the internet?

But i’d bet it wasn’t a mishap but an assumption gone wrong (or stale).

Re: I Hacked into Facebook's Legal Department Admin Panel

#133
post #112

Earlier quoted context omitted.

What does it mean to be a moral philosopher 'by trade'?

Unemployed

It's a rather small field, but IIRC, I had a philosophy professor in college whose specialty was the Ethics, and he had a sideline consulting with hospitals as a medical ethicist. He was also brilliant-- In the course I took with him we covered scientific ethics, one of the more memorable of my academic experiences.

Re: I Hacked into Facebook's Legal Department Admin Panel

#134
I'm a little bit disappointed, because from the title I expected a little bit of deep dive into the content of the admin panel.

Something like an insight into what kind of secret power or privacy abuse was available to the legal department without the users really realizing.

Re: I Hacked into Facebook's Legal Department Admin Panel

#135

I'm a little bit disappointed, because from the title I expected a little bit of deep dive into the content of the admin panel. Something like an insight into what kind of secret power or privacy abuse was available to the legal department without the users really realizing.

Exploiting a vulnerability to learn and then reveal trade secrets is probably a crime. You have Facebook's tacit permission to look for vulnerabilities, but not to use them or pivot from them.

Re: I Hacked into Facebook's Legal Department Admin Panel

#136

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage.

You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†).

You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty.

You can tell them "I found a vulnerability in sOmEtHiNg! But I'm not telling you what it is!" but Facebook is beset constantly by bogus bounty claims and they will blow you off.

You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything.

Part of being a good "agent" is understanding the market you're working in.

Especially because to even try to put a valuation on the bug --- which, again, ~nobody wants to buy --- you'd have to actively exploit it to see what's on the target system, which is straightforwardly a felony.

Re: I Hacked into Facebook's Legal Department Admin Panel

#137

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

That's the most American comment I've read all day, and that's saying something!

Re: I Hacked into Facebook's Legal Department Admin Panel

#138

Earlier quoted context omitted.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

Here in Australia the state funds most medical care. In this case the blackmail vector, if we use that interpretation is the taxation system.

And we (Australia) blackmail drug makers: sell your drugs to us at a certain price and the Government will heavily subside it and you’ll get big sales. Refuse and it will get zero subsidy and nobody will buy it.

https://en.m.wikipedia.org/wiki/Pharmaceutical_Benefits_Sche...

Re: I Hacked into Facebook's Legal Department Admin Panel

#139
post #122
post #85

Earlier quoted context omitted.

It’s that second part. “I’m going to do x if you don’t y.” He’s under no obligation to disclose. But the second part is coercion. x itself might also constitute a crime.

Using an "if" doesn't mean coercion if first action is legitimate - I'm going to refuse your offer if you don't propose something better. - I'm going to work on it if you don't want to - I'm going to eat the cake if don't like it

Not quite. Let's say I know you're cheating on your partner: I can tell the partner, and that's legally fine. But if I say "I'm going to tell the partner if you don't pay me $7500" then that is not fine, even though the first action is legitimate. Coercion really is quite a bit about the second part as well.

I'm not sure if this rule would cover all coercion/blackmail, but a rule like the following is probably a good guideline: If the first part negatively impacts the "victim" while the second part positively impacts the other person, it's might be getting close to coercion territory.

Let's take your cake example: The person with the cake isn't really negatively impacted. If they don't like the cake, they aren't materially harmed by someone else eating it. Although even there, context matters: Let's say you're a baker, and you sell cakes, even ones that you don't like yourself (maybe you hate buttercream icing). Taking your cake and eating it when you might otherwise have sold the cake and made money would be a problem.

Re: I Hacked into Facebook's Legal Department Admin Panel

#140

I'm a little bit disappointed, because from the title I expected a little bit of deep dive into the content of the admin panel. Something like an insight into what kind of secret power or privacy abuse was available to the legal department without the users really realizing.

Exploiting a vulnerability to learn and then reveal trade secrets is probably a crime. You have Facebook's tacit permission to look for vulnerabilities, but not to use them or pivot from them.

It is not trade secret. It would be in the public interest. Just let me remember you that we are speaking about Facebook and user's privacy...

As we have discovered through recent scandals, a lot of people are not aware of the level of abuse on their privacy they expose themselves by using Facebook.

But just reusing the devil's argument, if they have nothing bad to hide, there is no issue to be transparent...

Post reply on HN