Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

281–290 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#281

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

That’s why you would need an agent. Yes Facebook will brush it off if a random hacker anonymously contacts them, but if they’re approached by serious man in a suit with experience in the field, they’ll take it seriously, and, if not, you hire a social media expert to kick up a big fuss

Re: I Hacked into Facebook's Legal Department Admin Panel

#282

You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.

or even more such as dividends

Re: I Hacked into Facebook's Legal Department Admin Panel

#283

Earlier quoted context omitted.

As you've described it, blackmail shouldn't be a crime when revealing the information would be otherwise legal.

A classic case of blackmail – I know you have committed a crime. I threaten to report your crime to the police unless you pay me. The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail. If I just went ahead and reported your crime to the police – no crime of blac…

Yes, and that shouldn't be a crime.

Now a more relevant example:

I discovered a security vulnerability in FB.

1. Publish the vulnerability publicly (legal)

2. Sell the vulnerability to exploiters (illegal)

3. Accept FB's bug bounty reward (legal)

4. Attempt to negotiate a different amount with FB, falling back to #1 (illegal, blackmail)

5. Attempt to negotiate a different amount with FB, falling back to #2 (illegal, extortion)

6. Attempt to negotiate a different amount with FB, falling back to #3 (legal)

I assert that treating #4 as a crime is to use the police powers of the state to protect FB's wallet.

Re: I Hacked into Facebook's Legal Department Admin Panel

#284

Earlier quoted context omitted.

It "isn't seen as a credible thread" because it's immoral. Sequencing plays a major role here. And while that may seem somewhat arbitrary, it is significant. (Similar case, that, for some reason tech people have entirely too much trouble understanding: Announce "I'm going to shoot this gun at that target". Person, having heard you, walks and stands in front of the target. Are you still allowed/morally right to shoot?…

What's immoral is allowing the company to leave the vulnerability unfixed. It's their system, their vulnerability is their responsibility. They should be glad they were contacted by a relatively harmless person and pay them a fair value for doing work they didn't even know they needed. If they refuse to fix it, the moral thing to do is to disclose it so that the company has no choice but to fix it.

thanks for proving my point?

Re: I Hacked into Facebook's Legal Department Admin Panel

#285

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

That’s why you would need an agent. Yes Facebook will brush it off if a random hacker anonymously contacts them, but if they’re approached by serious man in a suit with experience in the field, they’ll take it seriously, and, if not, you hire a social media expert to kick up a big fuss

No, they won't. They won't even talk to the weirdo in the suit. The magical powers of suits are much overstated and, in the last 20 years, greatly diminished.

Re: I Hacked into Facebook's Legal Department Admin Panel

#286

Earlier quoted context omitted.

Blackmail with a bit of overhead tossed in then. At least most hackers keep the costs down and pass the savings on to you!

I don't think state funded healthcare works the way you think it does. The american system is the most economically inefficient system out there, to the extent that people without experience of other systems likely end up with highly distorted perception. Note that a mixed economy (combined public/private funding, like the french and australian systems) are probably for the most part the most economically efficient.…

Just a joke!

Re: I Hacked into Facebook's Legal Department Admin Panel

#287

Earlier quoted context omitted.

The market for random serverside bugs doesn't have to be liquid, it just has to exist I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol And then come in with the much larger payload and a few forum posts about it They only use Monero for payments an…

People on this subthread are talking about how you'll get caught, and maybe there's something to that, but the real reason this won't work is that nobody wants to buy your stupid auth bypass bug in a random line of business application. If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of pe…

I disagree. I can imagine tons of parties that would pay good money for access to Facebook's legal admin panel. Without knowing exactly what's in there, one could imagine lawsuit filings, documents and data that have been put aside during a legal hold, C&Ds sent to people doing things Facebook doesn't like, etc. What can you do with this data? Well, probably embarrass Facebook badly by exposing all sorts of confidential discussions. You might be able to pull an invoice scam by harvesting vendor information and sending a bunch of fake invoices to be paid. You might find other unsecured information that allows you to escalate your access. One can only imagine.

Sure, the economic value of the root password to the NAS for Joe's Carwash is quite low but I suspect even the low level systems at high profile companies is worth tons (I'd guess millions) of dollars to the right (wrong people).

Re: I Hacked into Facebook's Legal Department Admin Panel

#288

Earlier quoted context omitted.

People on this subthread are talking about how you'll get caught, and maybe there's something to that, but the real reason this won't work is that nobody wants to buy your stupid auth bypass bug in a random line of business application. If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of pe…

I disagree. I can imagine tons of parties that would pay good money for access to Facebook's legal admin panel. Without knowing exactly what's in there, one could imagine lawsuit filings, documents and data that have been put aside during a legal hold, C&Ds sent to people doing things Facebook doesn't like, etc. What can you do with this data? Well, probably embarrass Facebook badly by exposing all sorts of confident…

You can disagree, but you're wrong. The kinds of people who watch dark marketplaces for exploits are not dreaming of the super interested information they can get off a random backoffice system.

One time, about 15 "bug bounties are a ripoff" threads ago, someone actually made a non-ironic case for a high valuation for logout CSRF bugs. A competing image service could employ it to ruthlessly log users out, degrading service and jacking up their own signups. A logout CSRF. That's the kind of logic we're talking about here.

Nobody buys these kinds of bugs speculatively.

Re: I Hacked into Facebook's Legal Department Admin Panel

#289

Earlier quoted context omitted.

A classic case of blackmail – I know you have committed a crime. I threaten to report your crime to the police unless you pay me. The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail. If I just went ahead and reported your crime to the police – no crime of blac…

Yes, and that shouldn't be a crime. Now a more relevant example: I discovered a security vulnerability in FB. 1. Publish the vulnerability publicly (legal) 2. Sell the vulnerability to exploiters (illegal) 3. Accept FB's bug bounty reward (legal) 4. Attempt to negotiate a different amount with FB, falling back to #1 (illegal, blackmail) 5. Attempt to negotiate a different amount with FB, falling back to #2 (illegal,…

Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really jeopardize a person's agency and certainly leads us to a more corrupt society if it's not acknowledged formally for being untoward.

But I also think a lot of these companies are happy to frame negotiations as extortionate if someone has the audacity to counter their offer, and that's bullshit. But it would also be bullshit to try to drive up the price on a real bounty after the fact by threating to let the bountied person run free with a map to your house, so it's complicated and I can see the precedent in thought there.

Re: I Hacked into Facebook's Legal Department Admin Panel

#290

Earlier quoted context omitted.

Yes, and that shouldn't be a crime. Now a more relevant example: I discovered a security vulnerability in FB. 1. Publish the vulnerability publicly (legal) 2. Sell the vulnerability to exploiters (illegal) 3. Accept FB's bug bounty reward (legal) 4. Attempt to negotiate a different amount with FB, falling back to #1 (illegal, blackmail) 5. Attempt to negotiate a different amount with FB, falling back to #2 (illegal,…

Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really…

Publicly releasing a vulnerability is not a crime, even if FB would prefer I didn't.
Post reply on HN