Live data from Hacker News

Deleting any Facebook album

7xter.com

31–40 of 107 posts

Re: Deleting any Facebook album

#32
post #13

Earlier quoted context omitted.

It's not very useful to compare bug bounty payouts to what the "black market" would pay for a vulnerability. Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this): 0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer. 1. Look for a buyer. If you're not well-connected, you might stumble into a…

In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…

Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all?

I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing.

It's been suggested to me that there is in fact at least one set of buyers for account takeover bugs. But they aren't monetizing those accounts.

Re: Deleting any Facebook album

#33

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

[deleted]

Re: Deleting any Facebook album

#34
post #30
post #27

Earlier quoted context omitted.

$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.

While this is absolutely true, I know some people that like to do this type of stuff for "fun" and the bounty is just icing on the cake. It also won't hurt him in finding that kind of work in the future.

Yeah, I feel it's more about earning respect than making a living.

"I made $10k just for a quick hack"[1] has enormous bragging value - it's both a large enough payout for that, and it can actually be used without going to jail. Much better than actually bringing Facebook down.

[1] It doesn't matter how much work went into finding the exploit, one can still brag about doing it left-handed in 5 minutes.

Re: Deleting any Facebook album

#35
post #18

Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).

It's a great incentive to not sell it on the black market.

Or when you do find something really exploitable you already have a financial incentive to be good.

Re: Deleting any Facebook album

#36

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

Yet there's no way to tell FB about problems without having an account (that I could find in 5 minutes). I found potential phishing attempts in the Windows Store, suggested apps right from the start menu. MS refuses to do anything about phishing/scams on their store, and FB offers no way to contact them (I tried a few email addresses like legal@, to no response).

Yeah there's no way that's enough money to submit to creating a FB account. [only half-joking... EDIT: three-quarters?]

Re: Deleting any Facebook album

#37
post #32

Earlier quoted context omitted.

In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…

Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all? I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing. It's been suggested to me that there is in fact at le…

If they aren't monetizing them, can you be more specific about what these hypothetical exploit buyers are doing with the pwned accounts?

Re: Deleting any Facebook album

#38
post #27

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.

I understand your sentiment here, but that's a difficult comparison. Friends of mine make more money hunting bug bounties each year than their (competitive) full time salaries as consultants or developers.

These sorts of things are publicly verifiable - Michal Zalewski has commented on it before as a member of the Google appsec team, and if you look on Twitter for writeups from the same folks you come to the same conclusion. I have in mind one particular friend who literally bankrupted a bug bounty in three hours.

Another security researcher by the name of Nicholas Gregoire earned $35,000 combined from Yahoo and Facebook for a single vulnerability in each company - both server-side request forgery. He found it in Yahoo's YQL console, then decided to look elsewhere for it in a very deterministic fashion, and came across it in Parse (Facebook). He found many more bugs in a period of a few months, but he explicitly didn't look as seriously as some people do, which entails actively tracking acquisitions by companies like Google and Facebook.

It can be something of a meat grinder, but finding bug bounties is extremely profitable work. Then of course, having this work on a rèsumè is an immediate step up for getting interviews.

Re: Deleting any Facebook album

#39
post #13

Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).

It's not very useful to compare bug bounty payouts to what the "black market" would pay for a vulnerability. Let's look through the challenges of selling a vulnerability that allows for arbitrary account takeover (much more serious than this): 0. Find the vulnerability. Assume that no one will find it by the time you find a third party buyer. 1. Look for a buyer. If you're not well-connected, you might stumble into a…

The US government actually buys vulnerabilities. It's not really illegal so you don't need to worry about an FBI sting.
Post reply on HN