Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

11–20 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#11

Earlier quoted context omitted.

The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.

Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.

I suspect franjkovic means that there's a queue of lump sums to get deposited to their respective owners, and payments in that queue get processed once per week.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#12
post #7
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

Re: Stealing Facebook access_tokens using CSRF in device login flow

#13

so you got paid $5,000 ? How long since the first report did it take for that to reach your bank account?

The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.

[deleted]

Re: Stealing Facebook access_tokens using CSRF in device login flow

#14

Earlier quoted context omitted.

The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.

Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.

Weekly, as opposed to Google's biannual system.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#15
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#16
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal!

Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#18
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

$50-100k signing bonus; not annual compensation.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#19
post #7

Earlier quoted context omitted.

> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

I guess the reasoning would be that some hackers probably have found vulnerabilities they'd rather sell on the black market for 50K than sell to Facebook for 5K.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#20
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

50K signing bonus
Post reply on HN