4 ms·
Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
by reginaldo 13y ago
Well, it's already disclosed, but I really wanted to know how much people would think this kind of bug is worth.
- onestone 13y agoAfter Ryan McGeehan's comment about the "million dollar bug" (cited in your writeup), I'd say your bug is worth at least $100k.
- jonknee 13y agoA bug that lets you execute code on Facebook's servers is worth millions if not billions of dollars. You'll be rewarded with much less than that, but considering Facebook's market cap it is extraordinarily valuable.
- grugq 13y agoNo, it is not worth "millions or billions". It is worth whatever anyone is willing to pay for it. Since Facebook has very aggressive monitoring and will shutdown hacks quite rapidly, the ROI for a bug like this would have to be realised very quickly. Say in the order of days, (or maybe even hours), rather than months. How would you monetise 1 week of running code on facebook? Injecting malware would get the whole thing shutdown even faster, so you'd have to either go passive or operate in a reduced window of opportunity. There are no legal entities that would buy the bug, the USG can access any data w/ a warrant (thats free) vs. "millions or billions". Any other law enforcement agency could do the same thing. There is really no value there to them. So it would have to be blackhats, and that means some idiotic Russians mass owning everyone with old Java bugs. Again - not worth much. This sort of bug has very little value, except to facebook.
- reginaldo 13y agoI quoted that as a joke. I'm too familiar with bug bounties to ever expect one million dollars as reward for a bug. Let's hope people don't take it seriously. Lesson learned: since I'm not a native speaker, I shouldn't joke unless the joke is obvious.
- famousactress 13y agoComments on the FB post suggest the amount was 33,500$.