Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

291–300 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#291

Earlier quoted context omitted.

Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really…

Publicly releasing a vulnerability is not a crime, even if FB would prefer I didn't.

The facilitation the gp was referring to was what would be done with the vulnerability after it was publicly released.

Re: I Hacked into Facebook's Legal Department Admin Panel

#292

Earlier quoted context omitted.

That’s why you would need an agent. Yes Facebook will brush it off if a random hacker anonymously contacts them, but if they’re approached by serious man in a suit with experience in the field, they’ll take it seriously, and, if not, you hire a social media expert to kick up a big fuss

No, they won't. They won't even talk to the weirdo in the suit. The magical powers of suits are much overstated and, in the last 20 years, greatly diminished.

the suit is a metaphor. it means someone people take seriously

Re: I Hacked into Facebook's Legal Department Admin Panel

#293
post #269

Earlier quoted context omitted.

We have lots of that already, but it's more "protect the rich" than "protect our IT workers"

I hate to break it to you but the people saying things like "eat the rich" lump Bezos/Zuckerberg and the programmers/IT folks working for them into roughly the same bucket.

Who said to eat anyone?

Re: I Hacked into Facebook's Legal Department Admin Panel

#294

Earlier quoted context omitted.

You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…

Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.

Many do. On Darknet Diaries Podcast they mentioned even the NSA buys zero days, and selling to them (if you're a US citizen) won't be (as?) illegal as selling to a foreign nation is.

Re: I Hacked into Facebook's Legal Department Admin Panel

#295
post #84

How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....

It's undoubtably some third party system, not code written at Facebook.

Thanks, this seems likely.

Re: I Hacked into Facebook's Legal Department Admin Panel

#296
post #84

How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....

You have an unrealistically high expectation of code review.

I have worked several years at FAANG, and error like this were very hard to make due to how the frameworks were written.

But it seems that this was third-party code, which I guess explains it.

Re: I Hacked into Facebook's Legal Department Admin Panel

#297

Earlier quoted context omitted.

Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really…

Publicly releasing a vulnerability is not a crime, even if FB would prefer I didn't.

Threatening it as consequence of non-payment is, though. The nature of blackmail is weird, it gets written about a lot.

Re: I Hacked into Facebook's Legal Department Admin Panel

#298
post #269

Earlier quoted context omitted.

I hate to break it to you but the people saying things like "eat the rich" lump Bezos/Zuckerberg and the programmers/IT folks working for them into roughly the same bucket.

Who said to eat anyone?

Motörhead [1] and Aerosmith [2]

[1] https://www.youtube.com/watch?v=Wh3t49NsWBA

[2] https://www.youtube.com/watch?v=o-0lAhnoDlU

Re: I Hacked into Facebook's Legal Department Admin Panel

#299

Earlier quoted context omitted.

But there are people who generally research vulnerabilities in academia and your “term of art” doesn’t really apply there. Point being - “vulnerability researcher” means one thing talking to a PhD student at CMU vs talking to someone in the industry.

No, Ph.D students doing vuln research understand that they are researchers in two different senses. Talk to some of them. They're not confused about this.

I’ve worked in sec academia and, if they don’t know they are interacting with someone from industry, using the term “vulnerability research” absolutely does not mean what you’re talking about.

The fact that you are saying “they are researchers in two different senses” means you already know the overlap of terminology and it requires context to disambiguate, which is my entire fucking point. The “vulnerability research” that people hunting for bug bounties are doing is not “vulnerability research” in the academic sense.

Re: I Hacked into Facebook's Legal Department Admin Panel

#300

Earlier quoted context omitted.

No, Ph.D students doing vuln research understand that they are researchers in two different senses. Talk to some of them. They're not confused about this.

I’ve worked in sec academia and, if they don’t know they are interacting with someone from industry, using the term “vulnerability research” absolutely does not mean what you’re talking about. The fact that you are saying “they are researchers in two different senses” means you already know the overlap of terminology and it requires context to disambiguate, which is my entire fucking point. The “vulnerability researc…

Research in the academic sense is computer science research. "Vulnerability research" is a term of art that means "discovering and qualifying vulnerabilities". Most vuln researchers aren't academic. The term itself goes back decades and predates widespread academic offensive security research; nobody at COAST would have thought to call themselves "vulnerability researchers" because vulnerabilities weren't their focus.

I'm honestly a little lost about what the dispute even is here. Obviously, the term "vulnerability research" is old, and means pretty much what I said it meant in the previous paragraph. What's the confusion? It sounds almost as if you're trying to say "vulnerability research" means "academic security research". Obviously, it does not. Are you just trying to say it should mean that?

Post reply on HN