Live data from Hacker News

Stealing Facebook access_tokens using CSRF in device login flow

josipfranjkovic.com

81–89 of 89 posts

Re: Stealing Facebook access_tokens using CSRF in device login flow

#81
post #59

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…

$250k/yr is not at all a crazy number for someone who can reliably generate Facebook vulnerabilities from a black box cold start.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#82
post #41

Earlier quoted context omitted.

That's odd considering the potential monetary damage of such bugs can far exceed $10k.

One can smash a car up with a sledgehammer. Is the value of a sledgehammer equal to the value of a car?

Stealing this.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#84
post #70
post #59

Earlier quoted context omitted.

I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…

Why would you calculate hourly rate? I'd rather try to calculate the economic impact that this could have for the company, especially marketing costs to repair bad PR if something like private messages, pictures, info, etc. get breached. Do you think Facebook would spend $5,000 for that? Hell no, marketing budgets are in the magnitude of millions of dollars... I'm in no way supporting to exploit these vulnerabilities…

The hourly rate is to make an apples-to-apples comparison to someone whose full-time job is to do that kind of security work, either salaried or contracted.

Would it make sense to award bonuses to every in-house security researcher based on an estimated, hypothetical worst-case cost? It doesn't take much imagination to see how that reasoning applies to other positions. Do accountants get big bonuses for avoiding multi-million-dollar errors? Lawyers for avoiding costly lawsuits? Operations (IT and otherwise) for keeping infrastructure running? Customer service for assuaging disastrous public interactions? Stretched to absurdity, would you pay for a taxi based on how badly you need to get to point B?

I believe saying "preventing these kinds of problems (doing this work) is what we pay you for" is a reasonable conclusion and paying a market rate for that general value makes more sense versus calculating a kind of commission per individual contribution. That does have a certain appeal (and I wouldn't mind seeing a discussion about it) but I haven't gotten the impression that's the perspective of those who think all* bug bounties should be higher.

*: Added caveat as I'd bet every researcher can name companies that pay poorly

Re: Stealing Facebook access_tokens using CSRF in device login flow

#85
post #38
post #34

Earlier quoted context omitted.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

No, there isn't. Even the people who participate in the grey market for exploits (sales that aren't overtly prohibited by law and for which participation would be unlikely to make you an accessory to a felony) are very quiet about it. But, a good starting point might be the analyses people have done on the Hacking Team leak.

I seem to remember Miller mentioning in passing he got paid ~50K per vuln (you can guess who paid it by looking up Millers past employers).

Re: Stealing Facebook access_tokens using CSRF in device login flow

#86
post #59

The circle jerk discussion about the rewards paid out by bug bounties on this site is getting ridiculous. It has been talked about ad nauseum and it seems that most people crying that the reward isn't high enough because "you could make so much more on the black market" don't actually know anything about how vulnerabilities are monetized on the black market.

I'd be curious to know what those same folks think regular security staff should be paid. From another thread here, the author talking about the time involved: >Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. I'll round his estimate up to 6-8 hours, or basically a normal work day: $5000 / 8 = $625 an hour $625 * 40(hour w…

I don't think you can infer that all the researcher's finding would be critical bugs in one of the big companies (that pay well). It probably follows a normal distribution where most of the time it's non-critical bugs in medium-sized companies.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#87
post #34

Earlier quoted context omitted.

I'd love to learn about how these sorts of vulnerabilities tend to get moneitized in black market settings. Is there much reading available for that kind of thing?

I don't know much about it tbh. tptacek and a few others have spoken extensively about bug bounties on HN. I'll try and dig up a few of their past comments. Essentially what the argument comes down to is that a one off bug to exploit a company like Facebook is actually not worth very much to anyone on the black market because the bug is likely only valid for one company and that company will likely patch the bug very…

> [...] that company will likely patch the bug very quickly.

I have heard many instances where it isn't the case (some bugs are often being exploited for months before the company finds out)... and you probably did too... but anyways, as an example, you don't need a lot of time to copy lots of data...

Re: Stealing Facebook access_tokens using CSRF in device login flow

#88
post #63

Earlier quoted context omitted.

> Is the value of a sledgehammer equal to the value of a car? My previous post was poorly worded; I didn't mean to imply equality. To use your analogy, valuing a serious vulnerability on a platform that has 1.65B users in the $5-10k range is tantamount to selling a 30lb sledge hammer for a dollar.

But what if producing a sledgehammer only cost 50 cents? Then people would sell sledgehammers for a dollar or less.

Rather than torture this analogy further:

Obviously exploit pricing is generally efficient and adheres to free market principles. That said, it's hypothetically possible that an exploit against a large tech company could sell for far more if the circumstances are right, considering the price to damage ratio is so skewed in addition to the unique nature of each exploit.

Therefore, large tech companies don't really have much to lose by paying far more than they currently do on bounties.

Granted, eliminating what's largely a hypothetical edge case is not the primary benefit to paying higher; incentivizing far more white hat researchers is.

Re: Stealing Facebook access_tokens using CSRF in device login flow

#89
post #80
post #77

The black market is a false dichotomy. Either you need the money for your work, then negotiate a reasonable price, or you don't, then disclosing it for free might actually helps someone not to be lowballed by BigCo the next time. There really should be a bug marketplace, instead of one side having all the power and paying pennies.

Markets aren't magical. They route resources, they don't create them from thin air. If Facebook is ultimately the only organization that realizes $5000+ in value from a vulnerability, then no matter how you structure the marketplace, it isn't going discover a higher price for that flaw. If you believe otherwise, you're missing a business opportunity. Go create a "bug market" for Facebook and Google serversides. It's…

By submitting a bug through a bug bounty system you place the reward into Facebook's hands. Following the same argument you can say they can offer $1, because they are the only organization interested in the bug. After all exploiting a vulnerability puts you on the wrong side of the law.

However I do believe saying you discovered a pretty serious bug by putting it on a market sends a strong message. Your system is vulnerable and you are too cheap to pay up.

Post reply on HN