They fixed the issue pretty fast, but what bugs me is that I didn't get a thank you. I wasn't looking to gain anything, but I figure telling someone that their site is exposed warrants some gratitude.
- Stopped reporting anything that is not an issue in the source code of an open source project. I do so in their mailing lists or issue tracker.
- Began to treat random internet bug reports with kindness and gratitude.
Fortify on pronq is their SAAS application security scanner for those who were wondering.
Still, I don't understand why more people don't sell the exploits to the highest bidder. It seems counter intuitive to me.
Maybe there are more people who sell the exploits and you just don't hear about it as much as people who submit them to the corporations before publicizing them.
Edit: looks like I was wrong!
There is a specific kind of bug that is worth 6 figures on the black market: clientside remote code execution. Somehow, HN has gotten the impression that the going rate for the hardest bugs in the world to reliably weaponize is actually the going rate for all bugs everywhere.
The same reasons people don't steal from shops or commit other crimes:
1. Morals
2. Risk of getting caught and subsequent punishment
If Instagram comments are gone/disappearing, then a more secure version could gain user-share from Instagram.
Edit: Even CNBC is aware of data hacking[0]. Scary to know that people here don't even consider sabotage as a threat-model...
[0] http://www.cnbc.com/2016/03/09/the-next-big-threat-in-hackin...
Realistically though if this an were to become big enough to promote an alternative then Instagram would be all over it and thus fix it within minutes.
Sounds great. Where do I invest?
Also, many people invest in even worse and more fraudulent schemes. Publicly traded companies have scammed entire states and nations, costing dozens of billions to trillions of dollars, all while NYSE investors trade their stock like cash.
Edit: If you can't deal in facts, deal in downmods and unsubstantiated platitudes.
No, nobody is going to invest in this scheme.
- no one, ever
IIRC FB/Instagram didn't payout on a report that took their entire AWS keys though...
If Facebook was sending t-shirts instead of writing 4-5 figure checks, these discussions would be more interesting. But that's not what Facebook does.
Put it this way: before Facebook started these bounty programs, what do you think the price sheet for Facebook bugs on the "black market" looked like?
https://cms-images.idgesg.net/images/article/2014/06/googles...
But is causing monetary loss to Facebook, specifically, worth much to anybody? Anybody who would take the risk of committing a crime to do so?
This bug deletes content on Instagram. Unless you are the most underhanded of Instagram competitors, or just want to cause wanton Instagram picture destruction, I don't see why you as a third party would pay for it. Also, since I assume FB has backups, this is at most a relatively sophisticated DOS attack. Now, if you could insert data then you have stage 1 of a APT deployment platform, which is a whole other story.
Also, you underestimate the lifetime potential earnings won of "I discovered an attack on one of the 2-3 most popular internet platforms on earth at 13 and practiced textbook responsible disclosure with it". Beyond that, selling bugs to the highest bidder is very hard to justify, ethically speaking, and a lot of people put a high price on their integrity.
On the seller side, how easy is it to actually get paid? There's no point in trying to sell exploits if you're just going to get cheated, get busted selling to some sort of undercover law enforcement, or just go to a lot of trouble for not a lot of payoff.
From a buyer perspective, you need to have a way to verify an exploit, or else you're just buying a pig in a poke. And you need a way to monetize the exploit, or some other motivation. And you really have no way to know how long your exploit will remain functional.
(Or, you know, people could be basically good.)
On what basis could law enforcement act undercover to trap sellers?
This only applies to the US, as the laws are probably difference elsewhere. The CFAA[1] is a very vague and broad law that aims to stop people from accessing systems, sending malicious data, etc. It is intentionally written in such a way to be forgiving to the victim since security is hard by default [citation needed]. So even if you found an exploit without using it yourself, you'll probably be charged with aiding and abetting or something similar.
[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
Selling exploits in general is not that legally risky†. Prosecutors have to prove mens rea at trial, beyond a reasonable doubt. People sell bugs to anonymous marketplaces all the time.
The question isn't whether selling Facebook bugs to the black market is itself illegal. It's whether the DOJ could set up a sting to capitalize on the greed of people who would do that. Yes, they could.
† It's not not legally risky, either, especially in the case of bugs like these, where you've been given permission to attack Facebook's servers only in conjunction with their bounty program --- your civil liability to a website that doesn't run a bounty, if you sold a bug you found in their site and it was used in some way to harm them, could be astronomical.
> Formerly: founder @ Matasano
Neat! Matasano is what got me into crypto - though my pursuit has since been limited.
I'm glad you liked the crypto stuff we did!
Long story short, companies offer guaranteed set-size rewards as a counterpoint to the black market's potential highly variant payouts.
I think the argument that a black market sale of an exploit won't necessarily be as clear cut is still valid.
http://pastebin.com/raw/0SNSvyjJ
"Leaking documents, expropriating money from banks, and working to secure the computers of ordinary people is ethical hacking. However, most people that call themselves "ethical hackers" just work to secure those who pay their high consulting fees, who are often those most deserving to be hacked."