Live data from Hacker News

Deleting any Facebook album

7xter.com

41–50 of 107 posts

Re: Deleting any Facebook album

#41
post #19

Holy heck, $12.5K? That's one heck of a nice bug bounty program Facebook has there. That is likely more than the black market would pay for this, or at least a lot less hassle (plus the black market might have little interest as this cannot be used for hijackings, just trolling/harrassment).

I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.

No, but imagine the ressources they would have had to throw at the problem if the user had instead decided to delete ALL the photo albums on the site. Or imagine if he would have used the exploit to delete all the photos of a movie launch, etc. The reward is appropriate.

Re: Deleting any Facebook album

#42
post #32

Earlier quoted context omitted.

In a week, an attacker with an account-takeover exploit could attack every high-profile celebrity and likely dig up enough dirt on them to get far more than $50,000 in hush money. Or they could go the old-fashioned route and use it to snoop on the plans of wealthy people to kidnap them and hold them for ransom. There are many, many possibilities for making money if you can gain access to anyone's facebook account, ev…

Do you have firsthand or even secondhand knowledge of a market for account takeover bugs where the buyers are monetizing those bugs via celebrity dirt? Do you have knowledge of markets for account takeover where buyers are directly monetizing those bugs at all? I'm not asking if you can hypothesize such a market. I'm asking if you know about one actually existing. It's been suggested to me that there is in fact at le…

I don't, but I strongly suspect they exist. While it's not my MO, I am quite certain that a blackhat-hacker with an exploit that enables them to compromise anyone's personal account would have the idea to target wealthy/famous people for personal gain. I also don't think it's beyond reason to think they could generate more than $50,000 through malicious means. Doing it without getting caught would be the challenging part, I guess.

Re: Deleting any Facebook album

#43

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

For the seriousness of this bug 12k doesn't seem like much to me. I don't know if I would turn it in for that little. With my personal dislike of facebook, the alternative is so very, very tempting..

Re: Deleting any Facebook album

#45
post #38
post #27

Earlier quoted context omitted.

$ 12,500 is not a lot of money for this kind of work, if he is hired to find the same bugs he will earn much more.

I understand your sentiment here, but that's a difficult comparison. Friends of mine make more money hunting bug bounties each year than their (competitive) full time salaries as consultants or developers. These sorts of things are publicly verifiable - Michal Zalewski has commented on it before as a member of the Google appsec team, and if you look on Twitter for writeups from the same folks you come to the same con…

I completely understand the personal motivation behind solving this bounties but when you talk about people earning a lot of money you are talking about outliers. It is profitable work for very few elite security researchers. Most of computer security people will never find a bug in Google Chrome.

Re: Deleting any Facebook album

#46
post #19

Earlier quoted context omitted.

I doubt the "black market" would pay much of anything for this bug, because, like most severe web vulnerabilities, it has no half-life.

No, but imagine the ressources they would have had to throw at the problem if the user had instead decided to delete ALL the photo albums on the site. Or imagine if he would have used the exploit to delete all the photos of a movie launch, etc. The reward is appropriate.

I understand the reward, but Facebook was buying the incentive for people to look for bugs like this; they weren't competing with the black market.

Re: Deleting any Facebook album

#47

If $12,500 seems like a lot of money, remember that Facebook theoretically loses $22,453 for every minute their website is down. In other words, they generate $12,500 every 33 seconds. Paying out that sum of money to increase the number of people searching for security flaws is quite smart.

For the seriousness of this bug 12k doesn't seem like much to me. I don't know if I would turn it in for that little. With my personal dislike of facebook, the alternative is so very, very tempting..

That alternative being...

Re: Deleting any Facebook album

#49
So here seems like as good a thread as any.

What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish.

Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bounty program?

Does this kind of email seem ok?

    "Hi, I have seen a security vulnerability on your site. How do I report it? What do you pay?…

    May you respond in the next 7 days or I will be forced to take this to xxx.org for the protection of your users"

Re: Deleting any Facebook album

#50

So here seems like as good a thread as any. What do you do when you think a company would just fix the bug based on your report and not pay out anything? I have seen so many bugs in the wild like this. For example a site in the uk where I can get access to any account I wish. Are there any data protection laws that would provide leverage? How would you make first contact with a company that doesn't advertise a bug bo…

That sounds akin to extortion...

Edit: I should probably expand on that. Telling a company that you know about a bug but won't tell them about it if they don't pay you and instead threaten to turn it over to other parties who may have more nefarious intentions is pretty much extortion and is likely illegal.

I understand that you'd want to make money out of it, but if the company offers no bug bounty, it's no good threatening them. If you do so, it'll likely trigger a hostile response.

Post reply on HN