Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

181–190 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#181

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

Lol at 2%. Not even 2% of devs in silicon valley could do that.

2% of worldwide devs....

Re: I Hacked into Facebook's Legal Department Admin Panel

#182
post #10
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Generally companies prefer if you find bugs and disclose them before malicious parties find and exploit them. Most websites have a “responsible disclosure” policy. If you can’t find this linked on their main page, you can often find it at /security.txt or /.well-known/security.txt [0]: https://securitytxt.org/ [1]: https://facebook.com/security.txt

I'd suggest "most" is liberal. A few is more likely.... most corporates take it as an offense (someone may be fired, only the most enlightened of CISO's in progressive orgs treat it as anything but heresy). In SilVal - sure, a higher number because they can get it. Everyone else treats these types of issues as "guilty before proven innocent"

Re: I Hacked into Facebook's Legal Department Admin Panel

#183
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Check out HackerOne or BugCrowd. Companies have programs with details on what’s allowed vs not, responsibly report and optionally share findings after they’re fixed.

Re: I Hacked into Facebook's Legal Department Admin Panel

#184

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance, such that if a company doesn't pay out the bounty the researcher can still collect. I don't know if this would count as extortion though, so it might not even be legal.

Really this seems like a shady security company when I describe it like that.

Re: I Hacked into Facebook's Legal Department Admin Panel

#186

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.

Re: I Hacked into Facebook's Legal Department Admin Panel

#187

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

It's like most "open source" knowledge work on the internet. You can't really convert it into money directly, except via reputation. reputation leading to better SEO, better job offers, better ads on your blog, better speaker invites, better consulting gigs.

Re: I Hacked into Facebook's Legal Department Admin Panel

#188
post #129

Earlier quoted context omitted.

I always see posts like this, but I’m wondering at what amount of money would people feel like it’s fair?

Imho it would be fair if it was treated on a cost per hour basis. So a typical sec researcher will charge $350 per hour. So if this hack took 10 hours then $3500 would be fair

I’m not a security researcher but I disagree with this rationale on a number of levels.

First, just intuitively it feels wrong. It’s like saying that if you need a $20 permit for camping, but if you get caught camping illegally the fine should only be as much as the permit. Clearly it should be more.

More specific issues:

- Who determines how long the hack took?

- A security researcher is guaranteed the $350/hour whether or not they find the exploit. The bug hunter only gets paid if they find an exploit. Thus, if you follow this out logically every bug hunter should really just be a contracted security researcher and the only bugs being uncovered would be the ones companies were paying upfront to find. In other words, freelance bug hunting is deincentivized.

Re: I Hacked into Facebook's Legal Department Admin Panel

#189

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter.

Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?

Re: I Hacked into Facebook's Legal Department Admin Panel

#190

Earlier quoted context omitted.

Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.

>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.

It differs from blackmail because you the sick person are the one requiring others to perform a service for your benefit. With blackmail (and generally extortion) you are threatening to take an action unless someone pays you not to.
Post reply on HN