Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

21–30 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#21
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

$50k signing bonus.

The parent poster was sarcastically pointing out that entry level engineers who are likely not contributing much to Facebook's bottom line are compensated way more than the security researchers finding these potentially costly vulnerabilities.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#22
post #7

Earlier quoted context omitted.

> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

> If they are getting work done for the amounts paid, why pay higher?

To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?

Re: Stealing Facebook access_tokens using CSRF in device login flow

#24
post #7

Earlier quoted context omitted.

> I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

If you're working on Facebook security, is that a bet you're willing to take?

People might mostly take what they're offered, have it amount to a decent enough hourly rate but there will be that one in ten or one in a hundred unhindered by moral and/or legal considerations.

At that point, it turns into a cost calculation - perhaps it would indeed be cheaper to pay tenfold or more to a hundred people than have just one sell their bug/exploit/whatever to another, more interested buyer?

Re: Stealing Facebook access_tokens using CSRF in device login flow

#25
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

>how many hours did you spend researching this?

Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps.

>I think $5,000 is a joke

This is still $5,000 more than I would get reporting a similar bug to 99.999% of companies, and I am OK with the bounty. Here is good comment on the topic of bug bounty rewards: https://news.ycombinator.com/item?id=11249173

Re: Stealing Facebook access_tokens using CSRF in device login flow

#26
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.

Right, but this is facebook, and it's breaking auth. This is the company that said that if there's a million dollar bug, they will pay out for it. I'm not saying this is a million dollar bug, but breaking auth is up there on things that are bad and is probably worth a bit more than 5k.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#27

Earlier quoted context omitted.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

If you're working on Facebook security, is that a bet you're willing to take? People might mostly take what they're offered, have it amount to a decent enough hourly rate but there will be that one in ten or one in a hundred unhindered by moral and/or legal considerations. At that point, it turns into a cost calculation - perhaps it would indeed be cheaper to pay tenfold or more to a hundred people than have just one…

> If you're working on Facebook security, is that a bet you're willing to take?

Apparently so. That's what they're offering and paying. The entity that most benefits from FB security is FB, and they seem to be OK doing this.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#28
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.

What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#29
post #19

Earlier quoted context omitted.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

I guess the reasoning would be that some hackers probably have found vulnerabilities they'd rather sell on the black market for 50K than sell to Facebook for 5K.

Who is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more?

How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#30
The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
Post reply on HN