You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
Lol at 2%. Not even 2% of devs in silicon valley could do that.
I Hacked into Facebook's Legal Department Admin Panel
181–190 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#182I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
Generally companies prefer if you find bugs and disclose them before malicious parties find and exploit them. Most websites have a “responsible disclosure” policy. If you can’t find this linked on their main page, you can often find it at /security.txt or /.well-known/security.txt [0]: https://securitytxt.org/ [1]: https://facebook.com/security.txt
Re: I Hacked into Facebook's Legal Department Admin Panel
#183I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
Re: I Hacked into Facebook's Legal Department Admin Panel
#184You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Really this seems like a shady security company when I describe it like that.
Re: I Hacked into Facebook's Legal Department Admin Panel
#185Re: I Hacked into Facebook's Legal Department Admin Panel
#186You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Re: I Hacked into Facebook's Legal Department Admin Panel
#187You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Re: I Hacked into Facebook's Legal Department Admin Panel
#188Earlier quoted context omitted.
I always see posts like this, but I’m wondering at what amount of money would people feel like it’s fair?
Imho it would be fair if it was treated on a cost per hour basis. So a typical sec researcher will charge $350 per hour. So if this hack took 10 hours then $3500 would be fair
First, just intuitively it feels wrong. It’s like saying that if you need a $20 permit for camping, but if you get caught camping illegally the fine should only be as much as the permit. Clearly it should be more.
More specific issues:
- Who determines how long the hack took?
- A security researcher is guaranteed the $350/hour whether or not they find the exploit. The bug hunter only gets paid if they find an exploit. Thus, if you follow this out logically every bug hunter should really just be a contracted security researcher and the only bugs being uncovered would be the ones companies were paying upfront to find. In other words, freelance bug hunting is deincentivized.
Re: I Hacked into Facebook's Legal Department Admin Panel
#189You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?
Re: I Hacked into Facebook's Legal Department Admin Panel
#190Earlier quoted context omitted.
Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.
>> Which is essentially market driven blackmail as far as I can see. Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.