Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

31–40 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#31

Earlier quoted context omitted.

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

$50k signing bonus . The parent poster was sarcastically pointing out that entry level engineers who are likely not contributing much to Facebook's bottom line are compensated way more than the security researchers finding these potentially costly vulnerabilities.

Phew. Thanks.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#32

Earlier quoted context omitted.

I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.

What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.

But someone isn't. That's the point. These bugs don't go for $10k on the black market.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#33
post #22

Earlier quoted context omitted.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?

95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#34

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings.

Is there much reading available for that kind of thing?

Re: Stealing Facebook access_tokens using CSRF in device login flow

#35
post #22

Earlier quoted context omitted.

> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?

95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal .

Governments also buy zero days.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#36
post #34

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

I don't know much about it tbh. tptacek and a few others have spoken extensively about bug bounties on HN. I'll try and dig up a few of their past comments.

Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very quickly. This leaves the attacker with a very narrow window to exploit the bug.

Attackers on the black market paying for exploits are looking to make money from those exploits. If there is only one place they can use the exploit and perhaps only have a few days or even hours to use it how much would it really be worth? The exploits that pay big on the black market are ones that are enormously widespread and less likely to be fixed quickly.

If I can find better, more detailed, explanations I'll post them here. Maybe tptacek can link to his past comments...

Re: Stealing Facebook access_tokens using CSRF in device login flow

#37
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

Outside of whatever bounty Facebook chooses to offer for it, this vulnerability has a value on the open market of, perhaps, $50.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#38
post #34

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

No, there isn't. Even the people who participate in the grey market for exploits (sales that aren't overtly prohibited by law and for which participation would be unlikely to make you an accessory to a felony) are very quiet about it.

But, a good starting point might be the analyses people have done on the Hacking Team leak.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#39

Earlier quoted context omitted.

I think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.

What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.

People always say this but where would you go to find such a buyer? If you could find someone who would purchase it from you, would you process to then sell it to them?

If you can't find a buyer and/or would most likely be unwilling to commit a crime, it's a moot point.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#40
post #6
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

Hell, I'd pay 6 just for shits and giggles.

Then do it. Facebook has a great security team, but it's a huge product with a lot of code churn, and there are plenty of shits and giggles left to find. Hang up a sign on Twitter or here, something credible that you can't get out of simply by changing your name to "admiralfred" or "commodorefred", that says you'll pay $6,000 for a Facebook CSRF.

You'll get a taker. Nobody other than Facebook is bidding for these bugs, and you're promising to be the high bidder for a lot of them.

Post reply on HN