Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

51–60 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#51
post #38
post #34

Earlier quoted context omitted.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

No, there isn't. Even the people who participate in the grey market for exploits (sales that aren't overtly prohibited by law and for which participation would be unlikely to make you an accessory to a felony) are very quiet about it. But, a good starting point might be the analyses people have done on the Hacking Team leak.

What's your opinion on bug bounties for hosted applications v.s. bug bounties for actual pieces of software?

To me, the latter seem like a much more obviously good idea than the former. Notably, issues of somebody going out of scope- like the Facebook issue a while back- mostly disappear. Bounties on things like Chrome seem to be almost drama-free; the worst possible case, aside from somebody 0-daying a bug out of anger, is somebody not getting paid.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#52
post #38
post #34

Earlier quoted context omitted.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

No, there isn't. Even the people who participate in the grey market for exploits (sales that aren't overtly prohibited by law and for which participation would be unlikely to make you an accessory to a felony) are very quiet about it. But, a good starting point might be the analyses people have done on the Hacking Team leak.

[deleted]

Re: Stealing Facebook access_tokens using CSRF in device login flow

#53
post #35

Earlier quoted context omitted.

95% of people are incentivized enough to not sell to hackers by the incentive of not becoming a criminal .

Governments also buy zero days.

Sure just walk into an embassy with a Flash drive, I'm sure they've got sacks of doubloons in a basement safe just waiting for someone like you..

Re: Stealing Facebook access_tokens using CSRF in device login flow

#54

Earlier quoted context omitted.

What if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.

But someone isn't. That's the point. These bugs don't go for $10k on the black market.

Never mind the fact that it does matter to a lot of people whether they are committing a crime. Not everyone is a capitalist sociopath.

If someone without a conscience wanted to maximize their profit, they'd probably just sell to both sides.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#55
post #41

Earlier quoted context omitted.

But someone isn't. That's the point. These bugs don't go for $10k on the black market.

That's odd considering the potential monetary damage of such bugs can far exceed $10k.

The problem with valuing bugs at their damage potential is that the total damage potential of all bugs in any given product is almost certainly magnitudes greater than the total value of the product itself.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#56
post #34

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

The Hacking Team hack had some interesting fallout... I believe the article below was posted on HN a while ago: [Edit, just saw tptacek's comment]

https://tsyrklevich.net/2015/07/22/hacking-team-0day-market/

https://www.wired.com/2015/07/hacking-team-leak-shows-secret...

Re: Stealing Facebook access_tokens using CSRF in device login flow

#57
post #34

Earlier quoted context omitted.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

I don't know much about it tbh. tptacek and a few others have spoken extensively about bug bounties on HN. I'll try and dig up a few of their past comments. Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very…

What's more is there can't really be an established "market" for a unique exploit. If a product isn't being regularly traded then there's no easily findable pool of buyers. There's also no ongoing/repeat business which outside of contract law (and even for plenty of business conducted under contract) is all there is to keep people honest.

You'd need to be very well connected to be able to get good value out of an exploit. There could very well be people that are. Hackers in leather dusters travelling the world exchanging thumb drives in shady third world bars, sounds cool as hell, in fact I hope there are people living that life just because it makes reality that little bit more interesting. But your average pen tester isn't that.

Whenever i see the "better value on the black market" crowd show up here I'm actually reminded of a, Jim Jefferies I think, bit about the black market not meaning you can just head down to the docks at night going "GUNS. I WANT TO BUY A GUN".

Re: Stealing Facebook access_tokens using CSRF in device login flow

#58

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I think people on HN are underestimating the tabloid market and previous prices paid for photos https://en.wikipedia.org/wiki/List_of_most_expensive_celebri..., TMZ regularly pays out 5k for photos/videos, selling to them is the hard part and not getting caught in some type of undercover sting during the process is why most people will take the bounty

Re: Stealing Facebook access_tokens using CSRF in device login flow

#59

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd be curious to know what those same folks think regular security staff should be paid.

From another thread here, the author talking about the time involved:

>Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps.

I'll round his estimate up to 6-8 hours, or basically a normal work day:

$5000 / 8 = $625 an hour

$625 * 40(hour work-week) * 50(weeks) = $1,250,000 annually

Let's say it took an entire week's worth of time (comes out at $125/hour):

$5000 * 50 = $250,000

Is that range wildly out of line for what Facebook would potentially be paying for a full-time employee? The actual salary number would probably be lower, this would be including the cost taxes/insurance/perks/etc.

Even as a contractor, where the "expect to bill ~1000 hours a year" rule of thumb is/was common, puts the range at $125,000-$625,000.

Seems as though if you can reliably find organizations willing to pay these amounts and have the skill/luck/grit to grind out vulnerabilities at those companies you'll make a decent living. Or, put another way, these company's are paying bounties comparable to what the same research would have cost coming from a staff member.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#60
post #50

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

You're probably right, but this comment would be a lot better if it included information (e.g. about how the black market works) and dropped the slurs ("circle jerk", "crying").

You're right. It was a bit of a knee jerk response to what I was reading in the comments.
Post reply on HN