Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

221–230 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#221

Earlier quoted context omitted.

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

1. You can create throwaway PGP keys, it's not like they can definitively identify you 2. You can encrypt messages for target PGP public key(s) without actually signing them

It's a good way to prevent people from snooping on your messages. Why do you think it's a bad idea?

Re: I Hacked into Facebook's Legal Department Admin Panel

#222

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

3) is how you get the real money. Dropping zero days like its hot works and will lead to a good paying job. Example:

https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl...

wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah

reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they had

Re: I Hacked into Facebook's Legal Department Admin Panel

#223

Earlier quoted context omitted.

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

1. You can create throwaway PGP keys, it's not like they can definitively identify you 2. You can encrypt messages for target PGP public key(s) without actually signing them It's a good way to prevent people from snooping on your messages. Why do you think it's a bad idea?

The newer protocols for encrypted messaging like Signal are intentionally less weak than PGP in order to give plausible deniability. Specifically, the other person in the conversation can forge messages from you inside it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#224

Earlier quoted context omitted.

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

1. You can create throwaway PGP keys, it's not like they can definitively identify you 2. You can encrypt messages for target PGP public key(s) without actually signing them It's a good way to prevent people from snooping on your messages. Why do you think it's a bad idea?

because it works but some people think it getting in criminal hands is too big a price.

Re: I Hacked into Facebook's Legal Department Admin Panel

#225
post #184

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

It seems like the problem is that there is disclosing as a zero day isn't seen as a credible thread, since it's generally seen as bad practice. If security researchers wanted to try and collect more they could in theory form some kind of union to keep up the price of bounties, with like a middle agent pricing the bounty and disclosing the vulnerability if the price isn't met. Maybe combine with some kind of insurance…

+1 for security researchers' union. Reminds me of the bounty hunters' guild in the Mandalorian but with fewer blasters.

Re: I Hacked into Facebook's Legal Department Admin Panel

#226

Earlier quoted context omitted.

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

Using PGP signed messaging to do crimes seems like a pretty bad idea. As in, worse than not doing it.

If you want to stay whitehat and avoid jail, committing crimes is a bad idea. For criminals, blackmailing is part of their M.O.

There's an international market of brokers for zero days, but this specific vulnerability is less in demand.

I doubt that the information found at Facebook legal team could be used by nation-states (but perhaps I am not thinking creatively enough). I can imagine it being used as leverage by a nefarious nation-state, or informational by anti-trust dept. but it would be thrown out of court (therefore only viable for parallel construction). In the case of leverage the nefarious nation-state would feel the wrath of Facebook and/or US government. A country where Facebook has near zero adoption and already on bad terms with USA while within power vacuum, perhaps. Russia has Vkontakte, North Korea and China don't use Facebook either.

Regarding PGP, you don't have to use your real name. You can use an alias. You can sign each other's keys at a crypto party.

Re: I Hacked into Facebook's Legal Department Admin Panel

#227
post #84

How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....

You would be surprised how little effort sometimes goes into code reviews or security scans.

Up until recently the team I was dropped into didn’t have any authentication for all their endpoints, I pointed this out and secured them all, except for one. This one endpoint was only used internally, but was still exposed.

During multiple security scans and a penetration test, this didn’t even come up.

I even had a hard time convincing our product manager this should be secured, and could be done in an hour or two, if I could get some time.

Re: I Hacked into Facebook's Legal Department Admin Panel

#228

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.

Honeypots, I guess? At least that's what I'd set up if I were CIA/NSA. Ask Facebook to create a bunch of vulns that leave the intruder in a sandbox, sell the vulns, and watch where the attacks come from.

Re: I Hacked into Facebook's Legal Department Admin Panel

#229
post #222

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

3) is how you get the real money. Dropping zero days like its hot works and will lead to a good paying job. Example: https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl... wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they…

It works sometimes.

I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me.

I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.

Re: I Hacked into Facebook's Legal Department Admin Panel

#230
post #212

Earlier quoted context omitted.

If cleaning toilets paid $1 a month, but required enough skill that you could realistically get everyone who can do that on board, you now have a leverage of having all the toilets in some region dirty. That pays more than $1. Literally the point of unions (and big part of companies).

I understand the concept of unions and I am all for them. Forcing companies to pay a lot for found exploits is something completely different though. An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs. The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part…

> Forcing companies to pay a lot for found exploits is something completely different though.

Oh, no, the horror! Almost a trillion dollar company would need to pay a couple of extra grands to a security researcher who discovered an enormous vulnerability.

Post reply on HN