Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

191–200 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#191

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter. Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?

> Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter.

No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes...

Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a la Google Project Zero? Maybe what makes that non-blackmail is the promise of revealing it no matter what, but offering to delay up to ninety days?

Re: I Hacked into Facebook's Legal Department Admin Panel

#192

Earlier quoted context omitted.

I suppose the illegal part would be the student threatening to disclose the vulnerability to others if you didn't pay. That seems like crossing the line into blackmail and being an accomplice of whoever he discloses to. But the student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. I can see the difficulty though, I guess you'd need to have…

>> student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situatio…

perhaps a third party both sides trust is hired to appraise the value

Re: I Hacked into Facebook's Legal Department Admin Panel

#193

Earlier quoted context omitted.

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required. Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilit…

The fair market price of an entire app pentest of that legal dashboard application, one which would almost certainly find that bug† if run by a competent, reputable firm, along with many other bugs, run by consultants with bios and concluded with a deliverable that Facebook can file away, is probably somewhere between $20,000 and $35,000, so the idea that the fair market value of a single finding of that engagement i…

Fair enough. I could imagine that if the work were billed by the hour or said research firm hired multiple people it would be easy for costs of the work to run up to $75k - it's within O(20k). I'm not qualified to price these though - I certainly would abhor having to pay that cost if I were a small company.

Re: I Hacked into Facebook's Legal Department Admin Panel

#194

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

I macro agree with your point about leverage although I'd like a bit more insight here... "You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything." Wouldn't that cost Facebook much more than $7,000?

Sure it does. But does it matter?

Re: I Hacked into Facebook's Legal Department Admin Panel

#195

Earlier quoted context omitted.

I macro agree with your point about leverage although I'd like a bit more insight here... "You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything." Wouldn't that cost Facebook much more than $7,000?

I don't think so. Those people get paid whether or not you focus their attention on a perimeter-exposed RCE bug. By tipping them off, all you've done is make them more effective for a time. The bug is there whether a bounty hunter finds it or not. The other "leverage" you have, if you don't like $7K bounties for auth bypass on random backend thingies, is just not do hunt for bounties at all. Facebook knows that; thei…

> I don't think so. Those people get paid whether or not you focus their attention on a perimeter-exposed RCE bug.

Well, okay, but the opportunity cost (ie. the other valuable things they could be doing) is surely something that could have a $ value attached?

Re: I Hacked into Facebook's Legal Department Admin Panel

#196

Earlier quoted context omitted.

Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter. Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?

> Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes... Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a l…

IANAL, but:

The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc.

Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on.

Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation of blackmail, no demand for money involved.

Now, not all cases of blackmail fit the classic situation. It is possible for a person to commit blackmail without demanding money, if instead they demand something else of direct value to them – for example, saying to a university president "Offer my child a place or else I'll tell the media that you are cheating on your wife".

But, in the case of Google Project Zero style "Fix this bug in 90 days or I'll publicly reveal it", it isn't clear that the demander is actually demanding anything of any direct personal benefit to themselves. Generally speaking, the direct personal benefit to the security researcher of the bug being fixed is going to be negligible. If I demand you do something which doesn't directly benefit me (or my family or friends) in any tangible way, I don't see how such a demand could legally count as blackmail.

I doubt the delay itself has any direct legal relevance. Going to someone and saying "I'm going to report your crimes to the authorities no matter what, but if you don't pay me I'll do it tomorrow, if you pay me I'll wait until next week instead" is probably still blackmail. (Getting one week's notice is invaluable if you plan to flee the country, for example.)

Re: I Hacked into Facebook's Legal Department Admin Panel

#198

Earlier quoted context omitted.

Here in Australia the state funds most medical care. In this case the blackmail vector, if we use that interpretation is the taxation system.

And we (Australia) blackmail drug makers: sell your drugs to us at a certain price and the Government will heavily subside it and you’ll get big sales. Refuse and it will get zero subsidy and nobody will buy it. https://en.m.wikipedia.org/wiki/Pharmaceutical_Benefits_Sche...

> And we (Australia) blackmail drug makers: sell your drugs to us at a certain price and the Government will heavily subside it and you’ll get big sales. Refuse and it will get zero subsidy and nobody will buy it.

The blackmail version is actually "Refuse, and we'll produce a generic version locally and perhaps even export it to any country that wants it."

https://www.wired.com/2006/12/indiadrug/

Re: I Hacked into Facebook's Legal Department Admin Panel

#199

Earlier quoted context omitted.

> Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes... Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a l…

IANAL, but: The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc. Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on. Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation o…

I think a big part is that it is not "or I will reveal". Rather, it is, "I'm revealing this bug in ninety days. Fix it sooner." Right?

Re: I Hacked into Facebook's Legal Department Admin Panel

#200

Earlier quoted context omitted.

It is not trade secret. It would be in the public interest. Just let me remember you that we are speaking about Facebook and user's privacy... As we have discovered through recent scandals, a lot of people are not aware of the level of abuse on their privacy they expose themselves by using Facebook. But just reusing the devil's argument, if they have nothing bad to hide, there is no issue to be transparent...

That's not how that works at all. You absolutely do not have a right to hack into private companies "in the public interest".

> That's not how that works at all. You absolutely do not have a right to hack into private companies "in the public interest".

Well, not as a private individual, certainly. You have to work for a nation-state's Advanced Persistent Threat group like the NSA's Tailored Access Operations.

Post reply on HN