Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

211–220 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#211

Earlier quoted context omitted.

Here in Australia the state funds most medical care. In this case the blackmail vector, if we use that interpretation is the taxation system.

Blackmail with a bit of overhead tossed in then. At least most hackers keep the costs down and pass the savings on to you!

I don't think state funded healthcare works the way you think it does. The american system is the most economically inefficient system out there, to the extent that people without experience of other systems likely end up with highly distorted perception.

Note that a mixed economy (combined public/private funding, like the french and australian systems) are probably for the most part the most economically efficient. A big problem in australia is over-provision of services, especially ending up getting more pathology tests than strictly necessary.

Re: I Hacked into Facebook's Legal Department Admin Panel

#212
post #184

Earlier quoted context omitted.

It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…

> some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met So a hacker group that will blackmail companies? $7500 for spending anywhere less than a month on something is a pretty decent compensation. You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users,…

If cleaning toilets paid $1 a month, but required enough skill that you could realistically get everyone who can do that on board, you now have a leverage of having all the toilets in some region dirty. That pays more than $1.

Literally the point of unions (and big part of companies).

Re: I Hacked into Facebook's Legal Department Admin Panel

#213

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#214

Earlier quoted context omitted.

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

I had to chuckle at your comment (at first glance it does seem foolish), thinking about it a little more however, I realize that there is a good reason to why they do it, and if you are careful enough you can probably evade the negative consequences. I guess you have to know what you are doing.

Re: I Hacked into Facebook's Legal Department Admin Panel

#215

Earlier quoted context omitted.

The fair market price of an entire app pentest of that legal dashboard application, one which would almost certainly find that bug† if run by a competent, reputable firm, along with many other bugs, run by consultants with bios and concluded with a deliverable that Facebook can file away, is probably somewhere between $20,000 and $35,000, so the idea that the fair market value of a single finding of that engagement i…

Fair enough. I could imagine that if the work were billed by the hour or said research firm hired multiple people it would be easy for costs of the work to run up to $75k - it's within O(20k). I'm not qualified to price these though - I certainly would abhor having to pay that cost if I were a small company.

20-35k assuming a sort of baseline project being 2 people, 2 weeks.

Re: I Hacked into Facebook's Legal Department Admin Panel

#216

Earlier quoted context omitted.

Respectfully, I feel like you all are making up a taxonomy that feels right to you, but that is definitely not accepted by the vuln research field. Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there ar…

The academic difference is quite distinct and is well understood in the research community there. Impressive vulnerabilities that could take down all of Google wouldn’t be accepted into any security research conferences/journals if the bug didn’t involve a new class of vulnerability or discovery method. The term “bug prospector” might not be widely accepted, but people just looking for well understood bugs in product…

Vulnerability researchers aren't generally academic researchers. "Vulnerability research" is a term of art.

Re: I Hacked into Facebook's Legal Department Admin Panel

#217
post #45

Earlier quoted context omitted.

>but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad. >some of the only fans users makes in a month what a plain SE would make in a year I'm sure if you could think of a way to make software engineers as appealing as naked women, you'd probably find yourself a pretty great job paying well over the people on onlyfans.

well, I might. I finish college back in 2019 and my teacher who was my counselor, runs several projects trying to make SE and CS more attractive to girls. I guess she'll have a harder job to do now, knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers. Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenage…

You can become popular on onlyfans too, your audience will just be gay men.

Re: I Hacked into Facebook's Legal Department Admin Panel

#218

Earlier quoted context omitted.

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

I mean you would be using a live OS and set up a key on that instance so it’s always a new identity, if you choose not to persist it, that service just doesn’t let you message any other way.

It would be much harder to mix identity with your clearnet pgp, if that’s what you were thinking, as the machines would air airgapped or the other ones simply off if you are using the same computer to boot the live os

Any other configuration is just lazy

Re: I Hacked into Facebook's Legal Department Admin Panel

#219
post #212

Earlier quoted context omitted.

> some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met So a hacker group that will blackmail companies? $7500 for spending anywhere less than a month on something is a pretty decent compensation. You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users,…

If cleaning toilets paid $1 a month, but required enough skill that you could realistically get everyone who can do that on board, you now have a leverage of having all the toilets in some region dirty. That pays more than $1. Literally the point of unions (and big part of companies).

I understand the concept of unions and I am all for them.

Forcing companies to pay a lot for found exploits is something completely different though.

An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs.

The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.

The rewards for these kinds of things are pretty public, so you can guess how much you will get paid for finding certain security bugs. If the amounts are too low, again, just don't do it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#220

Earlier quoted context omitted.

Rather than the exploiter setting an arbitrary price (which would be closer to blackmail), I think parent comment was saying that the fair market value of disclosing such a bug was worth closer to $75k given the unique skill set required. Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilit…

The fair market price of an entire app pentest of that legal dashboard application, one which would almost certainly find that bug† if run by a competent, reputable firm, along with many other bugs, run by consultants with bios and concluded with a deliverable that Facebook can file away, is probably somewhere between $20,000 and $35,000, so the idea that the fair market value of a single finding of that engagement i…

One point of you to consider though, I guess FB runs pentests all the time, either internally or externally by appointing some other company to do it.

That being said, if they pay that company 35k, for example, and they haven't found this, wouldn't that fact make this discovery worth more than 35k?

Post reply on HN