Earlier quoted context omitted.
FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.
$50k signing bonus . The parent poster was sarcastically pointing out that entry level engineers who are likely not contributing much to Facebook's bottom line are compensated way more than the security researchers finding these potentially costly vulnerabilities.
Stealing Facebook access_tokens using CSRF in device login flow
31–40 of 89 posts
Re: Stealing Facebook access_tokens using CSRF in device login flow
#32Earlier quoted context omitted.
I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.
What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#33Earlier quoted context omitted.
Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?
> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#34The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
Is there much reading available for that kind of thing?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#35Earlier quoted context omitted.
> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?
95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal .
Re: Stealing Facebook access_tokens using CSRF in device login flow
#36The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?
Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very quickly. This leaves the attacker with a very narrow window to exploit the bug.
Attackers on the black market paying for exploits are looking to make money from those exploits. If there is only one place they can use the exploit and perhaps only have a few days or even hours to use it how much would it really be worth? The exploits that pay big on the black market are ones that are enormously widespread and less likely to be fixed quickly.
If I can find better, more detailed, explanations I'll post them here. Maybe tptacek can link to his past comments...
Re: Stealing Facebook access_tokens using CSRF in device login flow
#37I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#38The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.
I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?
But, a good starting point might be the analyses people have done on the Hacking Team leak.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#39Earlier quoted context omitted.
I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.
What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.
If you can't find a buyer and/or would most likely be unwilling to commit a crime, it's a moot point.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#40I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
Hell, I'd pay 6 just for shits and giggles.
You'll get a taker. Nobody other than Facebook is bidding for these bugs, and you're promising to be the high bidder for a lot of them.