5 ms·
Getting in might be possible, but then the attacker would have to covertly exfiltrate and store all of Facebook's content to do a dump. Does J. Random Attacker
by gpcz 11y ago
Getting in might be possible, but then the attacker would have to covertly exfiltrate and store all of Facebook's content to do a dump. Does J. Random Attacker have enough storage to do this?
- 0942v8653 11y agoMaybe; realistically, the Internet speed would probably be more of a limiting factor. At mine, it would take almost a week to fill up 1 terabyte of storage. That's plenty of time to go get a few more HDDs. At 1 Gbps you'd have about 2 hours.
- gpcz 11y agoI think you're underestimating the scale of this problem. According to http://www.datacenterknowledge.com/archives/2013/01/18/facebook-builds-new-data-centers-for-cold-storage/ http://www.datacenterknowledge.com/archives/2013/01/18/faceb... , people upload 350 million new photos per day, and they have 240 billion photos total. If we use 1 MB per photo as an average, you'd need about 334 terabytes to store a day of Facebook's pictures. You'd need 228882 terabytes to store the whole thing. Assuming Wikipedia's estimate of $35/TB for desktop hard drives, it would cost about $8 million to store Facebook's photo archive (that's without videos or text). Actually hosting it would cost even more.
- 0942v8653 11y agoIf you were bent on getting it all, even at 1 Gbps: (228882 TB to Gb) sec to years = 58 yr 3 w 1 day 18 h 40 min 58 years is going to take a long time
- yellowapple 11y agoYou can split that across multiple attackers, though. A botnet of 58 machines would be able to do it in about a year by that math. Once you cross into the thousands, a full dump like this is suddenly feasible. That's why this is more a storage problem than a bandwidth problem in practice. That's a lot of hard drives. While it might be possible to build up a botnet of a few hundred thousand slave machines to download and store it all, the task is by no means trivial.
- lobe 11y agoIf you wanted to go after photos for everyone I would agree with you. Probably just as interesting would be grabbing everyone's private messages, and although a large dump, would be nowhere as hard to store. A further option would be to filter whose photos you steal, so you only target celebrities and/or the rich and famous for maximum effect. It all depends on the aims of the hacker, but I would imagine you could make a devastating attack without stealing all of Facebook's data
- civilian 11y agoUse facebook's cache to host the stolen data and have it downloaded in parallel over the internet.
- peterwwillis 11y agoNo no no. That's not the hack. The real hack will be using Facebook to infect people with malware. Which will probably be staggeringly easy once they get inside. It will be impossible to remove, it will hijack legitimate connections to non-FB accounts with injection attacks, it will expose all the credentials of all the users of all the services of these 1 billion people. The compromise of sites that rely on Facebook for authentication tokens will pale in comparison. Attack vectors: app upgrades, browser exploits, e-mail/messenger/comment phishing, 3rd party comment section or ad-network injection, desktop integration, and of course, all the mobile networks that provide Facebook data access for free (which are largely non-smartphone and have rudimentary interfaces). One billion people will be prompted in some way, or immediately exploited using 0-days, and I would wager around 20% of users would be infected within a few hours of actually starting the attack. That's 200 million infected devices (edit: users; number of devices may be many times more). Depending on the point of entry and the access gained (let's say 20 percent of the infections lead to compromise of the whole system), that's 40 million accounts compromised in a few hours. Banks, email accounts (which lead to everything else), online shopping, e-wallets, etc all stolen. Then the data extortion packages will encrypt all the phones and wipe any usable data and demand payment or destruction of data. There'll be a very short timer, too, because the bank and other financial account session data may be reset quickly. There is a potential that markets could crash worldwide as financial balances get shifted around at the speed of the internet. Screw the Facebook data. This is a compromise that organized crime and state actors would invest millions of dollars to set up. And it's a virtual certainty that it will happen one day.
- yellowapple 11y ago> And it's a virtual certainty that it will happen one day. Hell, it's probably already happening. Facebook's a big company. Not inconceivable to think that there might be at least one underpaid, disgruntled, obese, bespectacled mole in their ranks, quietly subverting security measures and siphoning data until he gets his $1.5 million pay day and heads off to retire in Costa Rica (or attempt to before getting eaten by Dilophosaurus while trying to escape Facebook's HQ...).