Live data from Hacker News

At Facebook, zero-day exploits, backdoor code bring war games drill to life

arstechnica.com

1–10 of 52 posts

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#2
I was there that day, sitting near several of the people deeply involved. I'm not really a security guy, so I was mostly a morbidly curious bystander. Early on, I saw a bunch of SeriouslyScary(tm) stuff in chat, and decided to see what was up. I was shoulder-surfing while they were looking at the url/endpoint, and when we found the code, and then the diff that put it into the codebase, the collective "oh shit" was something I won't soon forget.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#4
Meh.

Rest of world (including many governments) "we are not allowing use of Facebook for the intelligence threat it poses against our entire societies". Techy people: "Facebook isn't good for your privacy, internet users!"

Facebook PR puff piece: "Look, we take security very seriously, we even dumped some serious money on it!"

Bottom line: you can have great people but when you are such a high profile target holding the personal information of millions, it's not going to stop you from being abused or strong-armed by your host-government.

Fundamentally, centralization of anything to the level that Google or Facebook represent is a bad thing.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#6

  The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software.
What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#8
post #6

The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

(I work at Facebook but don't know anything about the event in question or if this post is accurate)

I suspect it wasn't actually a "0-day" in that sense, but rather a disclosed but unpatched vulnerability, and described as "a real 0-day exploit" in the article because of the typical reduced fidelity of press articles.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#9

Meh. Rest of world (including many governments) "we are not allowing use of Facebook for the intelligence threat it poses against our entire societies". Techy people: "Facebook isn't good for your privacy, internet users!" Facebook PR puff piece: "Look, we take security very seriously, we even dumped some serious money on it!" Bottom line: you can have great people but when you are such a high profile target holding…

[deleted]

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#10
"In 2010, hackers penetrated the defenses of Google...The hacks allowed the attackers to make off with valuable Google intellectual property and information about dissidents who used the company's services. It also helped coin the term "advanced persistent threat," or APT,"

Sorry Ars but the term "Advanced Persistent Threat" was not coined in 2010. Businessweek was using the term in 2008[1] and that was hardly the first time it appears in the literature.

[1] http://www.businessweek.com/stories/2008-04-09/an-evolving-c...

Post reply on HN