Earlier quoted context omitted.
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.
Stealing Facebook access_tokens using CSRF in device login flow
11–20 of 89 posts
Re: Stealing Facebook access_tokens using CSRF in device login flow
#12I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#13so you got paid $5,000 ? How long since the first report did it take for that to reach your bank account?
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#14Earlier quoted context omitted.
The bug was reported on December 8th, 2015 and fixed on February 18th, 2016 which is an unusually long time for Facebook. The bounty reached my account during the middle of March, but Facebook has recently changed their bounty payment processor to Bugcrowd, and now they have weekly payments.
Weekly payments as opposed to a lump sum? Why? I can't imagine cashflow is an issue for them.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#15I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#16Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#17Re: Stealing Facebook access_tokens using CSRF in device login flow
#18Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#19Earlier quoted context omitted.
> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.
Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#20Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.