Earlier quoted context omitted.
What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.
But someone isn't. That's the point. These bugs don't go for $10k on the black market.
Stealing Facebook access_tokens using CSRF in device login flow
41–50 of 89 posts
Re: Stealing Facebook access_tokens using CSRF in device login flow
#42Earlier quoted context omitted.
> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?
95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal .
Re: Stealing Facebook access_tokens using CSRF in device login flow
#43Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
FB's first years only get $50k? In Bay Area California??? WTF world am I living in where people actually get compensated properly? The past few days I've seen posts where compensation at very respectable companies is abysmal! Edit: Apologies for not reading it correctly. I now stand corrected that the parent meant a $50k signing bonus in addition to a more reasonable annual compensation.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#44Pretty cool that FB's first years get $50k+ signing bonuses, but a serious vulnerability gets $5000
I fully support Facebook paying bug bounties, but let's compare apples to apples here.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#45Earlier quoted context omitted.
I guess the reasoning would be that some hackers probably have found vulnerabilities they'd rather sell on the black market for 50K than sell to Facebook for 5K.
Who is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more? How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#46Earlier quoted context omitted.
Who is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more? How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.
If it's a government buying the exploit, they wouldn't care about recouping the cost. Hence why a large sum is feasible.
Also note that the majority of government entities can just legally request information.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#47Earlier quoted context omitted.
Hell, I'd pay 6 just for shits and giggles.
Then do it. Facebook has a great security team, but it's a huge product with a lot of code churn, and there are plenty of shits and giggles left to find. Hang up a sign on Twitter or here, something credible that you can't get out of simply by changing your name to "admiralfred" or "commodorefred", that says you'll pay $6,000 for a Facebook CSRF. You'll get a taker. Nobody other than Facebook is bidding for these bug…
edit
Actually, now that i think about it, someone in the right situation could probably make a nice living for a few years buying cheap/obscure exploits for lots of companies that provide bug bounties and submitting them. Beer money at least, perhaps tuition.
Seems sort of on the scale of small time drug dealer. Illegal, very risky in the long term, but possible to get away with for a few years if you're cautious.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#48Out of curiosity, was there any particular reason why you decided to write a blog post about this vulnerability 5 months after the bug was fixed?
Re: Stealing Facebook access_tokens using CSRF in device login flow
#49Earlier quoted context omitted.
But someone isn't. That's the point. These bugs don't go for $10k on the black market.
That's odd considering the potential monetary damage of such bugs can far exceed $10k.
Re: Stealing Facebook access_tokens using CSRF in device login flow
#50The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.