Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

21–30 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#22
post #11

Any details on how it worked?

"The problem lay in a private application programming interface (the slice of code allowing certain outside access) that wasn’t properly checking the person deleting the comment was the same one who posted it, the spokesperson added."

http://www.forbes.com/sites/thomasbrewster/2016/05/03/facebo...

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#23
post #13

Earlier quoted context omitted.

Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.

Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...

haha you can't be serious right? I am sorry but I honestly found that amusing. Like Instagram engineers scratching their heads as to why comments are disappearing while there's an up-rise of users and then someone finally decides to create a secure alternative and is upheld as the savior.

Realistically though if this an were to become big enough to promote an alternative then Instagram would be all over it and thus fix it within minutes.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#24
post #13

Earlier quoted context omitted.

Yes, this particular class of bug isn't all that useful. If someone started using the exploit it wouldn't be long before a user complained that their comments were being deleted and then Facebook would figure it out in a hurry.

Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...

I see. So, the business plan here is: outbid Facebook to buy the rights to arrange the commission of, what, tens of thousands of felonies, in order to secure a marginal benefit for a competitor to the world's most popular photo sharing application, where those rights expire instantaneously as soon as one of the best security teams on the planet notices what's happening.

Sounds great. Where do I invest?

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#25
post #7

Earlier quoted context omitted.

I know, right? $10,000! Facebook is worth billions! Think what the black market might pay for a bug that would delete any Instagram comment!

A bug that allows unauthorized children to delete content from other user's accounts may point to other vulnerabilities, which could have even more value. IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...

There are no Facebook vulnerabilities that have a value any higher than what Facebook is going to pay for them.

If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does.

Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#27

Earlier quoted context omitted.

What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?

GP is not talking about just sharing. This is selling information for monetary gain. The buyer of which is also attempting to profit from it.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#28

Earlier quoted context omitted.

What's the marketplace like? On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff. From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way…

Is there really information that you can obtain on your own that you can be criminally prosecuted for sharing? On what basis could law enforcement act undercover to trap sellers?

Easy. All the sting operation has to do is make it clear to the seller what the "buyer" "intends" to do with the bug. It doesn't even have to be overt: they could simply say "we are looking to pay $10,000 for a bug that would enable us to download all the private photographs from Justin Bieber's Facebook account".

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#29
post #3
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Agreed. Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me. Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.

Don't underestimate the value of money that's guaranteed instead of a hypothetical possibility, now instead of maybe sometime, yours free and clear instead of legally dodgy, that you can boast to friends and future potential employers about instead of hiding as a shameful secret.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#30
post #24

Earlier quoted context omitted.

Presumably an Instagram rival could find it useful. If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram. Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model... [0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...

I see. So, the business plan here is: outbid Facebook to buy the rights to arrange the commission of, what, tens of thousands of felonies, in order to secure a marginal benefit for a competitor to the world's most popular photo sharing application, where those rights expire instantaneously as soon as one of the best security teams on the planet notices what's happening. Sounds great. Where do I invest?

Best security teams on the planet? You are talking about Instagram? I've read multiple reports of their properties being completely owned in the last few months, just here. The fact that they are still up is a testament to the researchers who reported the errors to FB.

Also, many people invest in even worse and more fraudulent schemes. Publicly traded companies have scammed entire states and nations, costing dozens of billions to trillions of dollars, all while NYSE investors trade their stock like cash.

Edit: If you can't deal in facts, deal in downmods and unsubstantiated platitudes.

Post reply on HN