Live data from Hacker News

Instagram's Million Dollar Bug (2015)

web.archive.org

61–70 of 98 posts

Re: Instagram's Million Dollar Bug (2015)

#61

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

> triagers have a whole pile of crap to wade through, to get to the useful material. This is very true. > The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer who gets to make a significant judgement call on the value of the work done. The problem, in my experience, is that they never analyze it by its potential. Why would they, th…

IMHO it’s only a matter of time until someone blows up a unicorn just for the thrill of it. That’s not something I’d support, but I won’t feel bad for companies that don’t pay adequate bug bounties.

Re: Instagram's Million Dollar Bug (2015)

#62
post #3

God, this is frustrating. They essentially cracked Instagram's entire production environment open, and took explicit steps at every turn to stay within the published guidelines, and then they just take his report with zero compensation whatsoever. Insane.

Important rebuttal:

https://web.archive.org/web/20151217232048/https://www.faceb...

Re: Instagram's Million Dollar Bug (2015)

#63
post #13

This was discussed at length when it was first submitted here 5 years ago. The researcher found a (known) exploit, claimed $2500, then a month later used internal details he gathered (and saved) from the first exploit to breach the system further to demand a bigger payout.

They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.

It's not simply practical to burn the enterprise down at Facebook scale. They likely aessed what they felt was compromised, updated that, then went about. The erred in either having proper auditing to detect how much was done, or did an improper assessment of what could be accessed.

Re: Instagram's Million Dollar Bug (2015)

#65
post #64
post #5

Previous discussion (5 years ago): https://news.ycombinator.com/item?id=10754194

Alex's response is no longer available. (His link to his Facebook post is dead.) Anyone have a mirror?

Here is a cached version on Wayback Machine: https://web.archive.org/web/20161218181922/https://www.faceb...

Re: Instagram's Million Dollar Bug (2015)

#66
post #41

Earlier quoted context omitted.

Disclaimer: I was a Security Engineer on the FB Security Team until last month and was also involved in the Bug Bounty Program :-) That's not how Facebook treats Bug Bounty Participants. By far, it's one of the better programs in terms of payouts, fairness, and triage time on critical issues. Just a recent example: a bug bounty hunter reported unexpired CDN links. After internal research, FB figured out to chain this…

I think FB's greatest achievements is convincing their employees that their jobs are actually good for society, or at least neutral. Plenty of good people working there who seem honestly confused about how their jobs lead to so corruption and downfall of our society.

Upton Sinclair got this right almost 100 years ago- “It is difficult to get a man to understand something, when his [RSUs depend] on his not understanding it.”

Of course, I also work at a FAANG, so people in glass houses and all that...

Re: Instagram's Million Dollar Bug (2015)

#68

Earlier quoted context omitted.

> triagers have a whole pile of crap to wade through, to get to the useful material. This is very true. > The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer who gets to make a significant judgement call on the value of the work done. The problem, in my experience, is that they never analyze it by its potential. Why would they, th…

IMHO it’s only a matter of time until someone blows up a unicorn just for the thrill of it. That’s not something I’d support, but I won’t feel bad for companies that don’t pay adequate bug bounties.

You mean like cracking the most lucrative accounts on Twitter and then stealing Bitcoin? https://www.wired.com/story/inside-twitter-hack-election-pla...

Re: Instagram's Million Dollar Bug (2015)

#69

(my comment is on the overall trend, as the specifics on this incident are complex) The issues with bug bounties as a whole is the market is skewed. For any work done by a bug bountier, there is exactly one legitimate buyer, who gets to make a significant judgement call on the value of the work done. Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In wh…

> Furthermore, this value is decided upon after the work has been completed, and has been provided to the company. In what other industries is this the case? Those "mail us your gold" ads on TV.

Hospitals do this, but backwards. The service provider gets to set the price.

Re: Instagram's Million Dollar Bug (2015)

#70

Earlier quoted context omitted.

They didn't change the credentials that had been hacked? God I wish the hacker had sold the vuln to North Korea.

Real life is not like the movies, in which a floppy disk of info is exchanged for a suitcase of money in a dark alley or in a boardroom. Blackhats typically find that there is little market for their info, especially before the advent of bitcoin being popular. yeah, you cracked a bunch of selfie pics. What can you do with it. not much.

In 2017 Doxagram made well over 100k selling a emails and phone mumbers associated with a relatively small list of instagram accounts.
Post reply on HN