Earlier quoted context omitted.
Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. If they don't pay it, post the bug on Twitter. Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?
> Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes... Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a l…
I Hacked into Facebook's Legal Department Admin Panel
201–210 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#202Earlier quoted context omitted.
Which is essentially market driven blackmail as far as I can see. Once I meet my new neighbours (one of whom is a moral philosopher by trade) I might ask about how to assess if that's ok. Personally it feels somewhat ok to me, speaking as someone who's built industrial espionage for money.
So, what is your proposed solution for people who find security vulnerabilities in systems? Keep in mind these vulns are worth money in the black market.
This makes the company with said vulnerability pay the true price for it - may be even just purchase it on the black market and outbid the "bad guys". Or pay someone to fix it asap before it's sold.
Re: I Hacked into Facebook's Legal Department Admin Panel
#203Earlier quoted context omitted.
IANAL, but: The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc. Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on. Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation o…
I think a big part is that it is not "or I will reveal". Rather, it is, "I'm revealing this bug in ninety days. Fix it sooner." Right?
Re: I Hacked into Facebook's Legal Department Admin Panel
#204Earlier quoted context omitted.
>> student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situatio…
perhaps a third party both sides trust is hired to appraise the value
Re: I Hacked into Facebook's Legal Department Admin Panel
#205Earlier quoted context omitted.
> There's security research and there's bug prospecting. If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research". Bug bounty programs are mainly targeted at bug prospectors. > Both have streaks of narcissists and showboaters but the latter seems to be thick with them. Thank god for that. Blog posts like the one this thread is…
Respectfully, I feel like you all are making up a taxonomy that feels right to you, but that is definitely not accepted by the vuln research field. Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there ar…
In general though I do think we diffuse the term 'research' a bit in this case by applying it to a very broad spectrum of actions and motivations. As a result I think we lose some of the nuances of incentive that emerge at opposite ends of that spectrum. I mean we do call them 'bug bounties' afterall and we don't call Duane Chapman 'Dog the Fugitive Reseacher'. :)
Re: I Hacked into Facebook's Legal Department Admin Panel
#206You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
Re: I Hacked into Facebook's Legal Department Admin Panel
#207Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.
Anything mildly "interesting" being sold through such a program would be high treason. How do you know this "Russian website" isn't actually a CIA honeypot? Or maybe it's not a honeypot, but instead of paying you 250K you just die of heart attack in a couple of months? Or they sell your identity back to your govt. as part of some unrelated game.
Bad business.
Re: I Hacked into Facebook's Legal Department Admin Panel
#208Earlier quoted context omitted.
> Is it legal to do this? Post on Twitter that you've asked Company X for this bounty and if they don't pay it by Date X you'll post it on Twitter. No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes... Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a l…
Maybe what you need to do is post consulting fees on your Twitter, and then post something that just says, "Facebook, I've found a bug, I'm posting it in 90 days." Then it's up to Facebook to find it and fix it, or make you an offer you can't refuse.
Re: I Hacked into Facebook's Legal Department Admin Panel
#209Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…
So a hacker group that will blackmail companies?
$7500 for spending anywhere less than a month on something is a pretty decent compensation.
You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users, in this case Facebook’s.
If you think $7500 for finding something like this is not enough, you shouldn’t do it. You wouldn’t clean toilets for $1 a month either right?
Re: I Hacked into Facebook's Legal Department Admin Panel
#210You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol
And then come in with the much larger payload and a few forum posts about it
They only use Monero for payments and PGP signed messaging on White House