Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

61–70 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#61
post #45

Earlier quoted context omitted.

If it's a government buying the exploit, they wouldn't care about recouping the cost. Hence why a large sum is feasible.

Didn't the HT leaks show vulns that'd be sold to anyone? An online service hack just wouldn't command the same pricing. Is there any source/docs to indicate the e.g. NSA pays $50K for this kind of vuln? Also note that the majority of government entities can just legally request information.

>Is there any source/docs to indicate the e.g. NSA pays $50K for this kind of vuln?

If anything smaller governments without in-house vulnerability research would be more willing to pay large amounts.

>Also note that the majority of government entities can just legally request information.

The kind of governments that would be interested in exploiting Facebook probably aren't the kind that could legally request the information in the first place.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#63
post #41

Earlier quoted context omitted.

That's odd considering the potential monetary damage of such bugs can far exceed $10k.

One can smash a car up with a sledgehammer. Is the value of a sledgehammer equal to the value of a car?

>Is the value of a sledgehammer equal to the value of a car?

My previous post was poorly worded; I didn't mean to imply equality.

To use your analogy, valuing a serious vulnerability on a platform that has 1.65B users in the $5-10k range is tantamount to selling a 30lb sledge hammer for a dollar.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#64
post #58

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I think people on HN are underestimating the tabloid market and previous prices paid for photos https://en.wikipedia.org/wiki/List_of_most_expensive_celebri... , TMZ regularly pays out 5k for photos/videos, selling to them is the hard part and not getting caught in some type of undercover sting during the process is why most people will take the bounty

Buying stolen property is a crime. TMZ would be committing a crime if they bought photos from hackers. Doing that would be the end of TMZ.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#65
post #58

Earlier quoted context omitted.

I think people on HN are underestimating the tabloid market and previous prices paid for photos https://en.wikipedia.org/wiki/List_of_most_expensive_celebri... , TMZ regularly pays out 5k for photos/videos, selling to them is the hard part and not getting caught in some type of undercover sting during the process is why most people will take the bounty

Buying stolen property is a crime. TMZ would be committing a crime if they bought photos from hackers. Doing that would be the end of TMZ.

they already have precedent for buying illegally obtained footage and nothing happened to them

http://pagesix.com/2014/05/15/employee-who-leaked-solange-ja... http://www.newyorker.com/magazine/2016/02/22/inside-harvey-l...

they would be more worried about a gawker/hulk hogan like lawsuit then getting criminally prosecuted

Re: Stealing Facebook access_tokens using CSRF in device login flow

#66
post #65

Earlier quoted context omitted.

Buying stolen property is a crime. TMZ would be committing a crime if they bought photos from hackers. Doing that would be the end of TMZ.

they already have precedent for buying illegally obtained footage and nothing happened to them http://pagesix.com/2014/05/15/employee-who-leaked-solange-ja... http://www.newyorker.com/magazine/2016/02/22/inside-harvey-l... they would be more worried about a gawker/hulk hogan like lawsuit then getting criminally prosecuted

IANAL, but the first link does not support that conclusion. It is not made clear whether that employee was in fact committing theft and selling stolen goods to TMZ (the hotel threatens to press charges (what charges?) on the employee but did those charges actually go through?).

Furthermore, nothing happening in one case != okay to do whatever you want. I guarantee you TMZ has a team of lawyers that makes sure they stay on the right side of the fine line of plausible deniability.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#67
post #63

Earlier quoted context omitted.

One can smash a car up with a sledgehammer. Is the value of a sledgehammer equal to the value of a car?

> Is the value of a sledgehammer equal to the value of a car? My previous post was poorly worded; I didn't mean to imply equality. To use your analogy, valuing a serious vulnerability on a platform that has 1.65B users in the $5-10k range is tantamount to selling a 30lb sledge hammer for a dollar.

But what if producing a sledgehammer only cost 50 cents? Then people would sell sledgehammers for a dollar or less.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#68
post #3

I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?

Don't understand the downvoting here.. Very irrational or emotional motivated. I'll explain why is a joke: $5,000 is nothing considering what could cost to Facebook if someone in a black market finds this, plus a CSRF vulnerability is from a Security 101 lecture nowadays. They do have the resources and should put more money to audit their production code and pay bigger bounties for someone who's not part of their company and finds a bug like this. Again, down voting non-sense.. this is not reddit guys, this is Hacker News.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#69

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I posted below (and got hardly and irrationally downvoted) that $5,000 is a joke. And your comment and others don't change my mind. A CSRF vulnerability, looking forward to reading a post on a SQL Injection next time.. I worked doing bots on my school days when I was a kid, and I saw the gray/black market can be unfortunately extremely profitable. $5,000 is nothing, we're not talking about a little startup here, it's Facebook, and they do have resources. Have you ever seen nasty content on Facebook on your wall, been spammed or even hacked? It's because of these kind of vulnerabilities get breached. Of course they can happen, but $5,000 is nothing considering the economic impact that can have if someone exploits it badly. A PR campaign to fix a mess wouldn't cost a few thousands, rather a few millions. Again: kudos to the OP for posting this and doing things the right way (reporting to facebook), but again, sadly good developers are getting underpriced...

PS: and by the way, I'm in no way circle jerking, this is not reddit, I'm here for a serious discussion on the topic.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#70
post #59

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…

Why would you calculate hourly rate? I'd rather try to calculate the economic impact that this could have for the company, especially marketing costs to repair bad PR if something like private messages, pictures, info, etc. get breached. Do you think Facebook would spend $5,000 for that? Hell no, marketing budgets are in the magnitude of millions of dollars... I'm in no way supporting to exploit these vulnerabilities, and kudos to the OP (and many others) for finding these bugs and reporting to their companies instead of exploiting. I just think that big tech companies should pay bigger bounties.
Post reply on HN