6 ms·
I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's
by daraosn 10y ago
I think $5,000 is a joke, this is a serious vulnerability... Despite this, congratulations for finding it and reporting directly to them, the right way. If it's possible to know, how many hours did you spend researching this?
- cmdrfred 10y agoHell, I'd pay 6 just for shits and giggles.
- tptacek 10y agoThen do it. Facebook has a great security team, but it's a huge product with a lot of code churn, and there are plenty of shits and giggles left to find. Hang up a sign on Twitter or here, something credible that you can't get out of simply by changing your name to "admiralfred" or "commodorefred", that says you'll pay $6,000 for a Facebook CSRF. You'll get a taker. Nobody other than Facebook is bidding for these bugs, and you're promising to be the high bidder for a lot of them.
- jfoutz 10y agoHmm. Seems like Facebook should create some front entities and buy cheap exploits on the black market. Of course, perhaps they already do. Smart folks work there. edit Actually, now that i think about it, someone in the right situation could probably make a nice living for a few years buying cheap/obscure exploits for lots of companies that provide bug bounties and submitting them. Beer money at least, perhaps tuition. Seems sort of on the scale of small time drug dealer. Illegal, very risky in the long term, but possible to get away with for a few years if you're cautious.
- rl3 10y ago>I think $5,000 is a joke, this is a serious vulnerability... I tend to agree. They should probably add a zero to that. Obviously $5,000 is a lot of money, but not to Facebook, and especially not in the context of fixing serious vulnerabilities on a platform that has 1.65B users. If Facebook paid more they'd enhance their security in the process, at the cost of what amounts to chump change for them.
- MichaelGG 10y agoMaybe. But for anyone to make money off it, they'd need to be willing to be or work with a criminal, right? If they are getting work done for the amounts paid, why pay higher?
- conradk 10y agoI guess the reasoning would be that some hackers probably have found vulnerabilities they'd rather sell on the black market for 50K than sell to Facebook for 5K.
- MichaelGG 10y agoWho is paying 50k for these things? A while back the Hacking Team dumps showed very low prices. Zero days in widespread desktop systems were like 100k. Why would a remote service flaw that can be fixed at a moment's notice be worth much more? How do you recoup 50k on FB? Not a theoretical "I'll hack Tom Cruises' pictures and blackmail him" but an actual demonstrated business model.
- rl3 10y agoIf it's a government buying the exploit, they wouldn't care about recouping the cost. Hence why a large sum is feasible.
- MichaelGG 10y agoDidn't the HT leaks show vulns that'd be sold to anyone? An online service hack just wouldn't command the same pricing. Is there any source/docs to indicate the e.g. NSA pays $50K for this kind of vuln? Also note that the majority of government entities can just legally request information.
- rl3 10y ago>Is there any source/docs to indicate the e.g. NSA pays $50K for this kind of vuln? If anything smaller governments without in-house vulnerability research would be more willing to pay large amounts. >Also note that the majority of government entities can just legally request information. The kind of governments that would be interested in exploiting Facebook probably aren't the kind that could legally request the information in the first place.
- shepardrtc 10y agoI think $5,000 is a lot of money. I'd be pretty happy if they sent that to me. In years past, companies would just give you a nice pat on the back.
- andkenneth 10y agoRight, but this is facebook, and it's breaking auth. This is the company that said that if there's a million dollar bug, they will pay out for it. I'm not saying this is a million dollar bug, but breaking auth is up there on things that are bad and is probably worth a bit more than 5k.
- stephengillie 10y agoWhat if someone else was offering $10,000 for Facebook bugs, so they could exploit them? This bug could probably result in more than $5,000 in damages to the Facebook brand.
- argonaut 10y agoBut someone isn't. That's the point. These bugs don't go for $10k on the black market.
- franjkovic 10y ago>how many hours did you spend researching this? Two to three hours discovering and writing the initial report, couple more hours (unsuccessfully) trying to escalate it using pre-approved apps. >I think $5,000 is a joke This is still $5,000 more than I would get reporting a similar bug to 99.999% of companies, and I am OK with the bounty. Here is good comment on the topic of bug bounty rewards: https://news.ycombinator.com/item?id=11249173 https://news.ycombinator.com/item?id=11249173
- tptacek 10y agoOutside of whatever bounty Facebook chooses to offer for it, this vulnerability has a value on the open market of, perhaps, $50.
- daraosn 10y agoDon't understand the downvoting here.. Very irrational or emotional motivated. I'll explain why is a joke: $5,000 is nothing considering what could cost to Facebook if someone in a black market finds this, plus a CSRF vulnerability is from a Security 101 lecture nowadays. They do have the resources and should put more money to audit their production code and pay bigger bounties for someone who's not part of their company and finds a bug like this. Again, down voting non-sense.. this is not reddit guys, this is Hacker News.