Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

241–250 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#241

Earlier quoted context omitted.

It is not trade secret. It would be in the public interest. Just let me remember you that we are speaking about Facebook and user's privacy... As we have discovered through recent scandals, a lot of people are not aware of the level of abuse on their privacy they expose themselves by using Facebook. But just reusing the devil's argument, if they have nothing bad to hide, there is no issue to be transparent...

That's not how that works at all. You absolutely do not have a right to hack into private companies "in the public interest".

Parent comment is not talking about "rights", just public interest.

Re: I Hacked into Facebook's Legal Department Admin Panel

#242

Earlier quoted context omitted.

I suppose the illegal part would be the student threatening to disclose the vulnerability to others if you didn't pay. That seems like crossing the line into blackmail and being an accomplice of whoever he discloses to. But the student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. I can see the difficulty though, I guess you'd need to have…

>> student wouldn't be legally obligated to inform you of a vulnerability, and it wouldn't make sense to if you weren't willing to pay. Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situatio…

The thing that is missing here would seem to be a sort of zero-knowledge proof.

Re: I Hacked into Facebook's Legal Department Admin Panel

#243
post #212

Earlier quoted context omitted.

If cleaning toilets paid $1 a month, but required enough skill that you could realistically get everyone who can do that on board, you now have a leverage of having all the toilets in some region dirty. That pays more than $1. Literally the point of unions (and big part of companies).

I understand the concept of unions and I am all for them. Forcing companies to pay a lot for found exploits is something completely different though. An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs. The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part…

> An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs.

> The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.

"Nobody's forcing them to" and "they'd probably do it for free anyway" aren't what I'd consider valid reasons to keep something on a freelance basis. Perhaps "it's an infrequent odd-job" is a more sensible rationale, if there was one

Re: I Hacked into Facebook's Legal Department Admin Panel

#245
post #222

Earlier quoted context omitted.

3) is how you get the real money. Dropping zero days like its hot works and will lead to a good paying job. Example: https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl... wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they…

It works sometimes . I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me. I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.

And then sometimes you get sued.

Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw).

Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.

Re: I Hacked into Facebook's Legal Department Admin Panel

#247

Earlier quoted context omitted.

If you're OK commiting blatantly illegal acts for money you could just go rob a bank, too.

Can someone name this fallacy for me? It sounds like the slippery slope fallacy, but I'm not sure.

Its a strawman.

Re: I Hacked into Facebook's Legal Department Admin Panel

#248
post #231

Earlier quoted context omitted.

+1 for security researchers' union. Reminds me of the bounty hunters' guild in the Mandalorian but with fewer blasters.

I wish modern society had more guilds in general. So many interesting things are possible when likeminded people come together.

Like economic protectionism?

Re: I Hacked into Facebook's Legal Department Admin Panel

#249
post #212

Earlier quoted context omitted.

If cleaning toilets paid $1 a month, but required enough skill that you could realistically get everyone who can do that on board, you now have a leverage of having all the toilets in some region dirty. That pays more than $1. Literally the point of unions (and big part of companies).

I understand the concept of unions and I am all for them. Forcing companies to pay a lot for found exploits is something completely different though. An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs. The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part…

To be clear, I wasn't trying to make a moral statement on whether they should do this, I just think it's interesting.

I think that forcing companies to recognize and deal with vulnerabilities is a good thing, so to the degree this kind of setup would do that it wouldn't be all bad, but trying to extract additional gains beyond that exposure isn't good (e.g., companies would pay more to prevent bad PR from a threat to expose something than just to fix a vulnerability due to the risk it presents them, and the former is 'artificial' in this case so it wouldn't be efficient for a group to try to extract that from someone).

That is, today companies have some existential risk that a cyber security incident causes great harm to them (think: sony hacks, cambridge analytica), the existence of white hats researching these vulnerabilities and disclosing them responsible gives companies an avenue to address this risk, likely at a lower cost premium relative to hiring security teams to try and find them. I think that it's easier for companies to recognize and deal with these risks now than it used to be, and easier for security researchers to get paid for it. These are both good things, but it is quite possible that the risk posed by cyber security threats to companies is generally worth more than they're paying in aggregate (2 million in vuln fees quotes in their latest report, not much at all given the impact), so I think that some structure that would allow researchers to force companies to up the ante would be a good thing, but this is hard since it's a completely one sided market and companies can just accept the risk of an incident occurring rather than pay, even if it's inefficient.

Re: I Hacked into Facebook's Legal Department Admin Panel

#250

Earlier quoted context omitted.

> The way this is framed today by people is soo disgusting. > Most people were dirt poor in the past in the western world by today's standards. You have just adjusted one simplification to end up over exaggerating another one. A boomer's family could live off one salary. Since then women have joined the workforce and kind of the whole world by moving (migrating) or remote. While it is definitely true that those " non…

The wage stagnation relative to inflation started happening 1960s-1970s, so that was well after the time period we were discussing (pre-1960s).

* 20+ year ==> 50 to 60 year
Post reply on HN