Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

41–50 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#41

Earlier quoted context omitted.

What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.

But someone isn't. That's the point. These bugs don't go for $10k on the black market.

That's odd considering the potential monetary damage of such bugs can far exceed $10k.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#42
post #22

Earlier quoted context omitted.

> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?

95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal .

I don't believe it's illegal to sell vulnerabilities.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#43
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.

I glossed over the trailing space on the plus sign and read it your way first too, FWIW.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#44
post #8

Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000

I'm pretty sure a first year security engineer at Facebook gets paid a lot more than $5k too. They're not your employer, they don't owe you money, if you want to mess around looking for security vulnerabilities in your free time it's good of them to pay you at all.

I fully support Facebook paying bug bounties, but let's compare apples to apples here.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#45
post #19

Earlier quoted context omitted.

I guess the reasoning would be that some hackers probably have found vulnerabilities they'd rather sell on the black market for 50K than sell to Facebook for 5K.

Who is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more? How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.

If it's a government buying the exploit, they wouldn't care about recouping the cost. Hence why a large sum is feasible.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#46
post #45

Earlier quoted context omitted.

Who is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more? How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.

If it's a government buying the exploit, they wouldn't care about recouping the cost. Hence why a large sum is feasible.

Didn't the HT leaks show vulns that'd be sold to anyone? An online service hack just wouldn't command the same pricing. Is there any source/docs to indicate the e.g. NSA pays $50K for this kind of vuln?

Also note that the majority of government entities can just legally request information.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#47
post #40
post #6

Earlier quoted context omitted.

Hell, I'd pay 6 just for shits and giggles.

Then do it. Facebook has a great security team, but it's a huge product with a lot of code churn, and there are plenty of shits and giggles left to find. Hang up a sign on Twitter or here, something credible that you can't get out of simply by changing your name to "admiralfred" or "commodorefred", that says you'll pay $6,000 for a Facebook CSRF. You'll get a taker. Nobody other than Facebook is bidding for these bug…

Hmm. Seems like Facebook should create some front entities and buy cheap exploits on the black market. Of course, perhaps they already do. Smart folks work there.

edit

Actually, now that i think about it, someone in the right situation could probably make a nice living for a few years buying cheap/obscure exploits for lots of companies that provide bug bounties and submitting them. Beer money at least, perhaps tuition.

Seems sort of on the scale of small time drug dealer. Illegal, very risky in the long term, but possible to get away with for a few years if you're cautious.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#48
post #17

Out of curiosity, was there any particular reason why you decided to write a blog post about this vulnerability 5 months after the bug was fixed?

I wanted to move from Blogspot to a personal domain, but kept delaying it for a long time.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#49
post #41

Earlier quoted context omitted.

But someone isn't. That's the point. These bugs don't go for $10k on the black market.

That's odd considering the potential monetary damage of such bugs can far exceed $10k.

One can smash a car up with a sledgehammer. Is the value of a sledgehammer equal to the value of a car?

Re: Stealing Facebook access_tokens using CSRF in device login flow

#50

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

You're probably right, but this comment would be a lot better if it included information (e.g. about how the black market works) and dropped the slurs ("circle jerk", "crying").
Post reply on HN