Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

71–80 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#71
post #69

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I posted below (and got hardly and irrationally downvoted) that $5,000 is a joke. And your comment and others don't change my mind. A CSRF vulnerability, looking forward to reading a post on a SQL Injection next time.. I worked doing bots on my school days when I was a kid, and I saw the gray/black market can be unfortunately extremely profitable. $5,000 is nothing, we're not talking about a little startup here, it's…

The price is not only what you can get on the black market, but it's also considering:

- How likely it is for someone else to find it (even internally)

- How long does it take for it to be identified and exploited, the impact of that, and time for mitigation/fixing

Re: Stealing Facebook access_tokens using CSRF in device login flow

#72
post #69

Earlier quoted context omitted.

I posted below (and got hardly and irrationally downvoted) that $5,000 is a joke. And your comment and others don't change my mind. A CSRF vulnerability, looking forward to reading a post on a SQL Injection next time.. I worked doing bots on my school days when I was a kid, and I saw the gray/black market can be unfortunately extremely profitable. $5,000 is nothing, we're not talking about a little startup here, it's…

The price is not only what you can get on the black market, but it's also considering: - How likely it is for someone else to find it (even internally) - How long does it take for it to be identified and exploited, the impact of that, and time for mitigation/fixing

True, but it's also:

- How much would it cost to repair the trust of the users if the breach occurs. PR, marketing, organizational costs

Do you think a big company would pay $5k for a PR campaign to fix a mess due to a breach of private data? Not remotely.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#73
post #72

Earlier quoted context omitted.

The price is not only what you can get on the black market, but it's also considering: - How likely it is for someone else to find it (even internally) - How long does it take for it to be identified and exploited, the impact of that, and time for mitigation/fixing

True, but it's also: - How much would it cost to repair the trust of the users if the breach occurs. PR, marketing, organizational costs Do you think a big company would pay $5k for a PR campaign to fix a mess due to a breach of private data? Not remotely.

It's always a question of probability: expected cost x expected probability gives you the end cost

You don't lock a $1000 bike with an $1000 lock, maybe with a $100 lock though

Re: Stealing Facebook access_tokens using CSRF in device login flow

#74
post #72

Earlier quoted context omitted.

True, but it's also: - How much would it cost to repair the trust of the users if the breach occurs. PR, marketing, organizational costs Do you think a big company would pay $5k for a PR campaign to fix a mess due to a breach of private data? Not remotely.

It's always a question of probability: expected cost x expected probability gives you the end cost You don't lock a $1000 bike with an $1000 lock, maybe with a $100 lock though

[deleted]

Re: Stealing Facebook access_tokens using CSRF in device login flow

#75
post #22

Earlier quoted context omitted.

Maybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?

> If they are getting work done for the amounts paid, why pay higher? To incentivize people to tell them and not sell it to hackers? Because these sorts of things are very valuable to Facebook and they have gobs of money? Because a higher total would make more people interested in looking for issues?

If anything it's to give people the incentive to actually flesh out a bug report and send it to them. I really have no idea where everyone's getting this "The black market will pay billions!" idea from.

Facebook is a closed system, an exploit there is worth precisely nada. Any use of it for monetary gain will be shut down fast and probably audit-logged to find you. Find an exploit kernel-level that allows you to execute any command you want at any administrative level on Windows/Linux/etc which allows people to drastically increase their botnet size? That'll get you some cheese.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#77
The black market is a false dichotomy. Either you need the money for your work, then negotiate a reasonable price, or you don't, then disclosing it for free might actually helps someone not to be lowballed by BigCo the next time.

There really should be a bug marketplace, instead of one side having all the power and paying pennies.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#78
post #69

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I posted below (and got hardly and irrationally downvoted) that $5,000 is a joke. And your comment and others don't change my mind. A CSRF vulnerability, looking forward to reading a post on a SQL Injection next time.. I worked doing bots on my school days when I was a kid, and I saw the gray/black market can be unfortunately extremely profitable. $5,000 is nothing, we're not talking about a little startup here, it's…

As I said downthread, Facebook was the highest bidder for this interaction-required CSRF bug; the next-highest bidder would probably be $50.

There is virtually no market at all for serverside bugs, because they have no half-life: as soon as they're detected, they stop working against all targets instantaneously. Contrast that with browser clientsides, which have long half-lives.

A SQL injection bug in a Facebook service would not fetch much more than $50 from anyone but Facebook itself.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#79
post #58

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I think people on HN are underestimating the tabloid market and previous prices paid for photos https://en.wikipedia.org/wiki/List_of_most_expensive_celebri... , TMZ regularly pays out 5k for photos/videos, selling to them is the hard part and not getting caught in some type of undercover sting during the process is why most people will take the bounty

Every time this topic comes up, someone brings up the "market" for stolen photographs. For a site so interested in startups, we sure don't like to think like businesspeople when it comes to this topic.

Think about the steps required to acquire and monetize stolen photographs from Facebook accounts. Only a few of those steps involve Facebook vulnerabilities, just like only a few of the steps involving building a software company involve actually writing software.

But in order for that business to work at all, it needs a steady supply of Facebook vulnerabilities; all the work setting up a sales channel for photos, in reconnoitering accounts to figure out which ones to raid for photos, in determining what the prices for photos should be, in scouting out new customers for photos, and most of all providing OPSEC for a ridiculously risky criminal venture, all of it is at a standstill until someone (a) sells them a vulnerability and (b) shows them how to pivot that flaw to acquiring photographs.

Nobody is running that business, ready to receive Facebook CSRFs (or even serverside RCEs) so they can get another few weeks of Facebook photo-snarfing in. One way you know that is that when celebrity photos are stolen in phishing attacks, it's a major news story.

Vulnerabilities that command high prices on the black market do so because they slot into already-existing criminal enterprises. If the enterprise does not yet exist, the vulnerability is worth zero.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#80
post #77

The black market is a false dichotomy. Either you need the money for your work, then negotiate a reasonable price, or you don't, then disclosing it for free might actually helps someone not to be lowballed by BigCo the next time. There really should be a bug marketplace, instead of one side having all the power and paying pennies.

Markets aren't magical. They route resources, they don't create them from thin air. If Facebook is ultimately the only organization that realizes $5000+ in value from a vulnerability, then no matter how you structure the marketplace, it isn't going discover a higher price for that flaw.

If you believe otherwise, you're missing a business opportunity. Go create a "bug market" for Facebook and Google serversides. It's not illegal to buy vulnerabilities, or to sell them (so long as you're reasonably sure they're not going to be used as part of a specific criminal enterprise --- but don't worry, if you stick a $5000 price tag on a serverside bug, or even a $500 price tag, you can be pretty sure it won't be used by criminals).

Post reply on HN