I Hacked into Facebook's Legal Department Admin Panel
alaa.blog
alaa.blog
If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps.
If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 people on earth? Which makes for more like 0.0014%?
So let's say 1% of 1 million/year are up to this, I suspect it's rather more, but I can't be bothered to do the curve on past graduation rates, and figure out what the world wide figure is... you've easily got a couple of million people world wide.
When I think it's going to get really interesting is in another 10 years or so when there start to be significant numbers of bored retired former developers. At any rate the market rate probably isn't that bad.
With your numbers (assuming linear growth) after those 40 years, about one third of the total US workforce would now be CS graduates.
Wouldn't demanding money be blackmailing?
A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't.
I definitely felt blackmailed. I am not a lawyer but it felt illegal. Maybe someone can chime in to say if it is?
(Also sucks that you can release it anyway. But you do want to source these vulnerabilities from the world at large.)
Yet another reason why open source and collaboration may be better than capitalism and competition. Many hands make light work, with enough eyes all bugs are shallow, and all that.
(To be fair, open source lacks security by obscurity so a project becomes secure after many years and developers join it.)
Skilled engineers turn to cybercrime when white-hat bounties are insufficiently rewarding, so it is in everyone's interest to pay competitive rates for finding security vulnerabilities.
Modern medicine can also be like blackmail. Nobody has to actually threaten you, but nature will kill you unless you pay whatever the price of treatment. That's why we need competition, and why pharma companies like monopolies.
https://en.m.wikipedia.org/wiki/Pharmaceutical_Benefits_Sche...
The blackmail version is actually "Refuse, and we'll produce a generic version locally and perhaps even export it to any country that wants it."
Note that a mixed economy (combined public/private funding, like the french and australian systems) are probably for the most part the most economically efficient. A big problem in australia is over-provision of services, especially ending up getting more pathology tests than strictly necessary.
So in this threads context, "hey I found a vulnerability in your infrastructure, you could pay me for it" does not actually constitute blackmail unless they actually follow it with "I'm selling to the highest bidder which may not be you".
This makes the company with said vulnerability pay the true price for it - may be even just purchase it on the black market and outbid the "bad guys". Or pay someone to fix it asap before it's sold.
From my perspective, people weird ideas (in both directions!) about how much this stuff costs.
† It's a little tricky to say because the blog post is cagey about what the vulnerability actually is, but I'm thinking about all of the password-reset-flow bugs I've ever seen that fit the rest of the pattern of the post and I'm pretty sure this is low-hanging fruit for a serious app pentest.
That being said, if they pay that company 35k, for example, and they haven't found this, wouldn't that fact make this discovery worth more than 35k?
“I’m going to do x if you don’t y.”
He’s under no obligation to disclose. But the second part is coercion.
x itself might also constitute a crime.
- I'm going to refuse your offer if you don't propose something better.
- I'm going to work on it if you don't want to
- I'm going to eat the cake if don't like it
I'm not sure if this rule would cover all coercion/blackmail, but a rule like the following is probably a good guideline: If the first part negatively impacts the "victim" while the second part positively impacts the other person, it's might be getting close to coercion territory.
Let's take your cake example: The person with the cake isn't really negatively impacted. If they don't like the cake, they aren't materially harmed by someone else eating it. Although even there, context matters: Let's say you're a baker, and you sell cakes, even ones that you don't like yourself (maybe you hate buttercream icing). Taking your cake and eating it when you might otherwise have sold the cake and made money would be a problem.
It is coercion. But not all coercion is criminal.
Which leads to a very interesting situation in negotiating. It's not the first time someone tried to sell information or an idea without getting ripped off. But how can one agree the value of information without knowing it. Is there a standard word or phrase to describe that situation?
You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†).
You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty.
You can tell them "I found a vulnerability in sOmEtHiNg! But I'm not telling you what it is!" but Facebook is beset constantly by bogus bounty claims and they will blow you off.
You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything.
Part of being a good "agent" is understanding the market you're working in.
† Especially because to even try to put a valuation on the bug --- which, again, ~nobody wants to buy --- you'd have to actively exploit it to see what's on the target system, which is straightforwardly a felony.
"You can give them a hint as to what it is, to vouch for the legitimacy of your finding, but Facebook has one of the better-resourced security teams in the industry, and they're just going to find it themselves and shut it down without paying you anything."
Wouldn't that cost Facebook much more than $7,000?
The bug is there whether a bounty hunter finds it or not. The other "leverage" you have, if you don't like $7K bounties for auth bypass on random backend thingies, is just not do hunt for bounties at all. Facebook knows that; their desire to attract bounty hunters is priced in to the bounties they pay.
It's for this reason that people who want to make serious money and who start in bounty hunting break basically two ways:
* Either they get really good at mopping up lots of 4-figure bounties (hitting the occasional blackjack on something that pays into low-mid 5 figures), often with a fair bit of automation, or
* They graduate into consulting, where the weekly rate for this kind of work is substantially higher, you're given a briefing by the target about where to look, and where you get paid whether or not you find a marquee bug.
(A good person to ask about this stuff is 'daeken).
Seems like that captures the "higher bugs per hour" advantage of the consultant while retaining the "you only get paid for directly producing value" advantage of bounties.
The reason companies pay for app pentests and also run bug bounties is that the two modalities find different kinds of bugs. App pentesters generally get a lot of intel about their targets (source is not unusual). You're also getting a team with bios and a final deliverable that records the diligence work done, which is not an outcome you get with a bounty program.
But you can do things in between. It's not crazy to offer a gig to someone who has delivered a good finding on a bounty project. But you have to do something to incentivize them beyond what the bounty already does, and the most normal way to do that is to not make payment contingent.
Well, okay, but the opportunity cost (ie. the other valuable things they could be doing) is surely something that could have a $ value attached?
The middle manager who cares a lot about staying “on budget” for bounties could care less how long it takes the security team to track down a bug.
It's not even cut-and-dried for the RCEs that firms like this do buy. Bounty programs at giant tech companies are generally aware of the market prices for RCEs and are not overtly trying to screw you over. The flip side is that the price you get from a broker is (1) negotiated and (2) tranched, so the "number" you get is a best-case, not guaranteed, and can collapse if the bug is burned before the IC agencies the broker sells it to finish using it to hurt people. The bounty number, on the other hand, is a sure thing.
But ~nobody is buying auth bypass vulnerabilities. Maybe if you can mint OG Twitter accounts and aren't worried about going to prison.
I had some young college students report a very clever bug to me a few years ago, and they chose to take a rather aggressive approach when it came to discussing the bounty. We paid them a sum they were very happy with, but also gave them warning that if they took that same approach with the wrong company they could easily find themselves charged with a crime.
Really this seems like a shady security company when I describe it like that.
So a hacker group that will blackmail companies?
$7500 for spending anywhere less than a month on something is a pretty decent compensation.
You also seem to forget that despite the fairness of the compensation, disclosing the vulnerability could damage real users, in this case Facebook’s.
If you think $7500 for finding something like this is not enough, you shouldn’t do it. You wouldn’t clean toilets for $1 a month either right?
Literally the point of unions (and big part of companies).
Forcing companies to pay a lot for found exploits is something completely different though.
An important distinction is that the hackers are not employees of the company who are underpaid or mistreated somehow. Nobody is forcing these people to look for bugs.
The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
The rewards for these kinds of things are pretty public, so you can guess how much you will get paid for finding certain security bugs. If the amounts are too low, again, just don't do it.
Oh, no, the horror! Almost a trillion dollar company would need to pay a couple of extra grands to a security researcher who discovered an enormous vulnerability.
> The people who are after bug bounties get a kick out of finding cool security issues. I am sure a part of them would still be doing it even if there were no reward.
"Nobody's forcing them to" and "they'd probably do it for free anyway" aren't what I'd consider valid reasons to keep something on a freelance basis. Perhaps "it's an infrequent odd-job" is a more sensible rationale, if there was one
I think that forcing companies to recognize and deal with vulnerabilities is a good thing, so to the degree this kind of setup would do that it wouldn't be all bad, but trying to extract additional gains beyond that exposure isn't good (e.g., companies would pay more to prevent bad PR from a threat to expose something than just to fix a vulnerability due to the risk it presents them, and the former is 'artificial' in this case so it wouldn't be efficient for a group to try to extract that from someone).
That is, today companies have some existential risk that a cyber security incident causes great harm to them (think: sony hacks, cambridge analytica), the existence of white hats researching these vulnerabilities and disclosing them responsible gives companies an avenue to address this risk, likely at a lower cost premium relative to hiring security teams to try and find them. I think that it's easier for companies to recognize and deal with these risks now than it used to be, and easier for security researchers to get paid for it. These are both good things, but it is quite possible that the risk posed by cyber security threats to companies is generally worth more than they're paying in aggregate (2 million in vuln fees quotes in their latest report, not much at all given the impact), so I think that some structure that would allow researchers to force companies to up the ante would be a good thing, but this is hard since it's a completely one sided market and companies can just accept the risk of an incident occurring rather than pay, even if it's inefficient.
Sequencing plays a major role here. And while that may seem somewhat arbitrary, it is significant.
(Similar case, that, for some reason tech people have entirely too much trouble understanding: Announce "I'm going to shoot this gun at that target". Person, having heard you, walks and stands in front of the target. Are you still allowed/morally right to shoot?)
Anything mildly "interesting" being sold through such a program would be high treason. How do you know this "Russian website" isn't actually a CIA honeypot? Or maybe it's not a honeypot, but instead of paying you 250K you just die of heart attack in a couple of months? Or they sell your identity back to your govt. as part of some unrelated game.
Bad business.
Is that as legal as posting the bug on Twitter straightaway, which as I understand is legal?
No, it is not legal. This is called blackmail. https://www.justia.com/criminal/offenses/white-collar-crimes...
Although as a non-legal expert, I'm not clear on how this is different from demanding that the company fix the bug or else you'll reveal it after ninety days a la Google Project Zero? Maybe what makes that non-blackmail is the promise of revealing it no matter what, but offering to delay up to ninety days?
The classic situation of blackmail is demanding money from someone, or else you'll reveal some embarrassing fact about them, report that they committed some crime, etc.
Saying "Give me money or I will publicly disclose a bug in your computer systems" – that fits the classic situation of blackmail straight on.
Saying "Fix this bug in 90 days or I'll publicly reveal it" – doesn't fit the classic situation of blackmail, no demand for money involved.
Now, not all cases of blackmail fit the classic situation. It is possible for a person to commit blackmail without demanding money, if instead they demand something else of direct value to them – for example, saying to a university president "Offer my child a place or else I'll tell the media that you are cheating on your wife".
But, in the case of Google Project Zero style "Fix this bug in 90 days or I'll publicly reveal it", it isn't clear that the demander is actually demanding anything of any direct personal benefit to themselves. Generally speaking, the direct personal benefit to the security researcher of the bug being fixed is going to be negligible. If I demand you do something which doesn't directly benefit me (or my family or friends) in any tangible way, I don't see how such a demand could legally count as blackmail.
I doubt the delay itself has any direct legal relevance. Going to someone and saying "I'm going to report your crimes to the authorities no matter what, but if you don't pay me I'll do it tomorrow, if you pay me I'll wait until next week instead" is probably still blackmail. (Getting one week's notice is invaluable if you plan to flee the country, for example.)
The act being threatened – reporting your crime to the police – is totally legal, even socially encouraged. It is only the demanding of money (or other benefits) not to do it part which is the crime of blackmail.
If I just went ahead and reported your crime to the police – no crime of blackmail.
If I just didn't – no blackmail (but could be some other crime, such as misprision)
It's only when I tell you that whether I'm going to do it depends on whether you do something for me that blackmail has been committed.
Now a more relevant example:
I discovered a security vulnerability in FB.
1. Publish the vulnerability publicly (legal)
2. Sell the vulnerability to exploiters (illegal)
3. Accept FB's bug bounty reward (legal)
4. Attempt to negotiate a different amount with FB, falling back to #1 (illegal, blackmail)
5. Attempt to negotiate a different amount with FB, falling back to #2 (illegal, extortion)
6. Attempt to negotiate a different amount with FB, falling back to #3 (legal)
I assert that treating #4 as a crime is to use the police powers of the state to protect FB's wallet.
But I also think a lot of these companies are happy to frame negotiations as extortionate if someone has the audacity to counter their offer, and that's bullshit. But it would also be bullshit to try to drive up the price on a real bounty after the fact by threating to let the bountied person run free with a map to your house, so it's complicated and I can see the precedent in thought there.
But whether it's legal or not, it won't work. Facebook will likely never do business with you again, but they'll watch your Twitter account for the free bugs you're promising to give them.
I think you could flip this on White House Market pretty quick and pretty well. Either partner up with someone willing to risk their rep, or just sell 99 cent tutorials for a week and get your rep up. Or resell fullz lol
And then come in with the much larger payload and a few forum posts about it
They only use Monero for payments and PGP signed messaging on White House
It would be much harder to mix identity with your clearnet pgp, if that’s what you were thinking, as the machines would air airgapped or the other ones simply off if you are using the same computer to boot the live os
Any other configuration is just lazy
It's a good way to prevent people from snooping on your messages. Why do you think it's a bad idea?
There's an international market of brokers for zero days, but this specific vulnerability is less in demand.
I doubt that the information found at Facebook legal team could be used by nation-states (but perhaps I am not thinking creatively enough). I can imagine it being used as leverage by a nefarious nation-state, or informational by anti-trust dept. but it would be thrown out of court (therefore only viable for parallel construction). In the case of leverage the nefarious nation-state would feel the wrath of Facebook and/or US government. A country where Facebook has near zero adoption and already on bad terms with USA while within power vacuum, perhaps. Russia has Vkontakte, North Korea and China don't use Facebook either.
Regarding PGP, you don't have to use your real name. You can use an alias. You can sign each other's keys at a crypto party.
If your bug generates OG Instagram accounts, you'll probably find a buyer --- they will be loons who are likely to land you a prison sentence, because that's the general caliber of person who commits felonies to briefly lock up short account names on Instagram, and you'll have absolutely no way of arguing in court that you didn't know exactly what they were going to do. But you'll probably sell it, because there is an existing business process that acquires OG Instagram accounts your bug can slot into.
Nobody has a business process for exploiting access to a stupid internal legal dashboard application. Nobody is going to shell out more than $7000, speculatively, for access to this website.
Sure, the economic value of the root password to the NAS for Joe's Carwash is quite low but I suspect even the low level systems at high profile companies is worth tons (I'd guess millions) of dollars to the right (wrong people).
One time, about 15 "bug bounties are a ripoff" threads ago, someone actually made a non-ironic case for a high valuation for logout CSRF bugs. A competing image service could employ it to ruthlessly log users out, degrading service and jacking up their own signups. A logout CSRF. That's the kind of logic we're talking about here.
Nobody buys these kinds of bugs speculatively.
https://nakedsecurity.sophos.com/2019/06/13/microsofts-battl...
wah wah bad person publishing zero days wah wah Irresponsible disclosure hurts everyone. wah wah
reality: https://krebsonsecurity.com/2020/04/microsoft-patch-tuesday-... got hired @Microsoft, started fixing other bugs they didnt know they had
I'm not sure everyone would have the nerve to aggressively drop zero days, you don't know who you are going to cross, my paranoia would not let me.
I'm also not a security person, but I am sure there are people who have the necessary skills, but have the same nerves as I have.
Source: got sued by Sony for disclosing that they screwed up their ECDSA implementation so badly that you could compute their private keys (and then putting Linux back on the PS3 using that flaw).
Microsoft not doing that with Xbox (orig/360) hackers is why the Xbox One has really good security. They hired them instead.
Same goes here.
It is not about the vulnerability, it is about the content.
The real money is probably something more boring than setting up exploits--such as setting up a security consulting practice that charges a ton of money. It's a lot easier because then you would have less pressure to discover completely novel exploits.
Instagram keeps surprising me...
There's also the issue of "follower farmers". Basically, some spam accounts start following tens of thousands of people hoping at least some will check their profiles, maybe follow them back or click on their spam.
I noticed this mostly on Twitter, and after some digging, it turns out to be a common tactic used by spammer bots (or umm, "marketting teams"). I don't know how common that issue is on Instagram though but it could be same.
Too bad Twitter didn't do the purge of inactive accounts, would've been interesting.
Fun fact: Tunisia, a relatively small North African country, was awarded the second highest number of Facebook bounties this year[1].
[1]: https://about.fb.com/news/2020/11/bug-bounty-program-10th-an...
Most websites have a “responsible disclosure” policy. If you can’t find this linked on their main page, you can often find it at /security.txt or /.well-known/security.txt
However, some companies (including Facebook) have a bug bounty program that provides a prescribed safe harbor that you can operate within to discover vulnerabilities within their products or infrastructure in exchange for some kind of recognition or award.
The terms of Facebooks bounty are here: https://www.facebook.com/whitehat
Based on a cursory glance and the fact that this individual was awarded in their program, it appears they operated by the book.
Prosecuting activity that happens outside of these parameters has definitely happened in the past and will continue. It's not always a cut and dried decision. It can be difficult/expensive to effectively prosecute and you may find a lot of social backlash depending on the nature and impact of the activity.
If you are genuinely trying to find exploits in good faith, and are acting within the parameters spelled out in their bug bounty program, it’s all good. You also may get paid.
This blog entry sort of dramatized what happened for clicks. I actually think it’s unwise to characterize any exploit like this, because it adds a PR dimension consumer companies just don’t want or need.
It sort of creates a sense of adversarial relationship which isn’t really what FB is after.
But it sounds like a risky endeavor put this way and probably helps get retweets attention in the short term.
(edit: to clarify b/c this can easily be interpreted otherwise, I'm not calling the writer of this article either of those. The headline is a bit of cheap clickbait but the article is a good walkthrough of their mindset)
If the end result of your work isn't a whitepaper or something similar from which others can learn, then you can call your work "security research".
Bug bounty programs are mainly targeted at bug prospectors.
> Both have streaks of narcissists and showboaters but the latter seems to be thick with them.
Thank god for that. Blog posts like the one this thread is about are really valuable to those of us interested in the work of others.
I can see how what I said could be interpreted as 'folks that blog about their work are narcissists'. That wasn't my intent. The headline is a bit clickbaity but the explanation is a good walkthrough. This isn't the far end of the spectrum that I had in mind. Watching twitter or working for a bug bounty program is a better way to get exposed to that set.
Bug Bounty King really spoke to me haha
Yeah, they're very common. But, in my experience, showboating wasn't.
Further: this idea that "research" is something we have to valorize, and that you have to meet a public interest threshold to be worthy of it, is itself a standard to which the real world does not adhere. There are lots of different kinds of "research" out there; there are researchers who look for cures for cancer, and there are "researchers" who maintain stacks of index cards full of competitive market intelligence gleaned from press releases. The term "researcher" is about the kind of work you do, not the use to which it's put.
Maybe I'm just old and not keeping up with what the kids these days are saying, but I don't think "bug prospector" is a thing.
The term “bug prospector” might not be widely accepted, but people just looking for well understood bugs in production systems aren’t doing “research” in the academic sense anymore than a person at McDonald’s “researching” the menu to decide what to eat.
The fact that you are saying “they are researchers in two different senses” means you already know the overlap of terminology and it requires context to disambiguate, which is my entire fucking point. The “vulnerability research” that people hunting for bug bounties are doing is not “vulnerability research” in the academic sense.
I'm honestly a little lost about what the dispute even is here. Obviously, the term "vulnerability research" is old, and means pretty much what I said it meant in the previous paragraph. What's the confusion? It sounds almost as if you're trying to say "vulnerability research" means "academic security research". Obviously, it does not. Are you just trying to say it should mean that?
In general though I do think we diffuse the term 'research' a bit in this case by applying it to a very broad spectrum of actions and motivations. As a result I think we lose some of the nuances of incentive that emerge at opposite ends of that spectrum. I mean we do call them 'bug bounties' afterall and we don't call Duane Chapman 'Dog the Fugitive Reseacher'. :)
See sibling comments for the actual reason: Facebook and other companies typically allow this kind of security research, as long as the intent is not malicious and the researcher operates within some boundaries.
Any U.S. based pentester would always think twice before logging in a compromised system.
Making this kind of research illegal only makes sure the end result is always the latter.
Basically, he triggered the "Password Reset" process and then guessed the reset token?
So this endpoint simply allowed setting up a new password with a POST request for the specified email address and he was able to guess the email .. ¯\_(ツ)_/¯
SetPassword and the parameters to the function are just username and newPassword.
I guess they assumed there was authentication happening before the request would even be served (pre-existing session).
Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors.
$7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.
So a typical sec researcher will charge $350 per hour. So if this hack took 10 hours then $3500 would be fair
First, just intuitively it feels wrong. It’s like saying that if you need a $20 permit for camping, but if you get caught camping illegally the fine should only be as much as the permit. Clearly it should be more.
More specific issues:
- Who determines how long the hack took?
- A security researcher is guaranteed the $350/hour whether or not they find the exploit. The bug hunter only gets paid if they find an exploit. Thus, if you follow this out logically every bug hunter should really just be a contracted security researcher and the only bugs being uncovered would be the ones companies were paying upfront to find. In other words, freelance bug hunting is deincentivized.
The barrier for most people to sell data to criminals is high, both because it's illegal and because most people have at least enough of an ethical compass to not sell their services to scammers.
The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
You're probably right. Windows Server / IIS doesn't seem like them
But it seems that this was third-party code, which I guess explains it.
Or an intranet app originally and devs not expecting it to be exposed to the internet?
But i’d bet it wasn’t a mishap but an assumption gone wrong (or stale).
Up until recently the team I was dropped into didn’t have any authentication for all their endpoints, I pointed this out and secured them all, except for one. This one endpoint was only used internally, but was still exposed.
During multiple security scans and a penetration test, this didn’t even come up.
I even had a hard time convincing our product manager this should be secured, and could be done in an hour or two, if I could get some time.
That wouldn't really make sense, would it? As it allowed him to log in.
> So let’s get back to see what I’ve done here, I sent random requests using intruder with a CSRF token and random emails with a new password to this endpoint /savepassword
> Now I went to the login page and I put the login email and the new password and BOOM I logged in Successfully into the application and I can enter the admin panel
Something like an insight into what kind of secret power or privacy abuse was available to the legal department without the users really realizing.
As we have discovered through recent scandals, a lot of people are not aware of the level of abuse on their privacy they expose themselves by using Facebook.
But just reusing the devil's argument, if they have nothing bad to hide, there is no issue to be transparent...
Well, not as a private individual, certainly. You have to work for a nation-state's Advanced Persistent Threat group like the NSA's Tailored Access Operations.
All those names could be recovered in theory.
How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?
What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a crime? How do you trust the buyer? How do you handle it if the hole gets closed before the buyer can profit? How do you value the risk it gets closed before you got your deal? Does all that work out in a way that you really don't want to take the bounty?
People buying backdoor access into companies probably happens occasionally, but it's probably not the easy high-profit thing compared to bounties many people think, but rather on the level of selling account information by the dozen for a few bucks - and for something like that you'll burn them quickly.
There are markets for vulnerabilities that slot seamlessly into existing business processes. In other words, you can tend to find a buyer for a vulnerability that would replace another vulnerability already being used, that accomplishes pretty much exactly the same thing as that vulnerability. The more people run that business process, the more likely it is that there's a liquid market.
Lots of organizations have business processes that rely on browser RCEs. Generally, there aren't many organizations that have business process that rely on serverside vulnerabilities in line-of-business applications that have instantaneous half-lives, because once the patch is developed they're gone.
(‘?’ because I’m on my third whiskey and about to turn in :)
https://thehustle.co/coca-cola-stolen-recipe
> Months earlier, when Pepsi received the trio’s initial letter, they’d promptly forwarded it to Coca-Cola, and informed them they had a leaker. In turn, Coca-Cola had brought in the FBI to conduct an undercover investigation.
> On July 5, 2006, Williams, Dimson, and Duhaney were arrested on charges of wire fraud and unlawfully stealing and selling trade secrets.
It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.
Would that work? Asking for a friend.
Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities.
Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?
Even in my 1 weekend web apps I ensure password reset tokens are secured against their user and token type, but Facebook, a $720,000,000,000 company, can't do it for their ADMIN site?
The other day, someone shared a link to an app [1] that estimastes how much a only fan user makes. I got tell, it got to me. I was never money orientated and I don't plan to become; but seeing how much someone makes by being naked in front of a web cam vs a software engineer salary is kinda sad.
some of the only fans users makes in a month what a plain SE would make in a year. besides the fact that there are some serious wrong thing with the world, I thought this kind of skill would be more rewarded. Giving the fact that you could exploit this vulnerability to make a lot more money (or am I mistaken?).
I'm not sure why you feel the need to imply some else's work isn't valuable to make the point that this work should be more valuable.
The people at the top have a lot of hard-work, skill, and "being born attractive". Sex work is work.
>some of the only fans users makes in a month what a plain SE would make in a year
I'm sure if you could think of a way to make software engineers as appealing as naked women, you'd probably find yourself a pretty great job paying well over the people on onlyfans.
Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenager she'll be interested in STEM.
I have a daughter and, while obviously I’d prefer she didn’t end up on onlyfans, I really don’t want to limit what she should do or what talent she should leverage to reach happiness and/or prosperity.
The way this is framed today by people is soo disgusting.
1) Women did work before 1960.
2) Two incomes are better than one. Married couples are better off financially. Many women worked part time while the children were at school or in the evenings when the husband was back at home. I know this because my grandmother did and many of her friends.
3) A married couple typically provides the best environment for raising children. Most people want children.
4) Most people were dirt poor in the past in the western world by today's standards.
> Most people were dirt poor in the past in the western world by today's standards.
You have just adjusted one simplification to end up over exaggerating another one. A boomer's family could live off one salary. Since then women have joined the workforce and kind of the whole world by moving (migrating) or remote. While it is definitely true that those "none westerners were dead poor in the past compared to today" there is a 20+ year long wage stagnation in the west and increase in prices on some of the very fundamental needs like housing, which results in memes about gen XYZ not being able to afford them, create stable conditions, have a spouse and then a family (kids).
Anyway, we are in this together, always on(line), connected, one global world and it depends how you view it: Appreciate the advancements the non-western world has made or focus on the gap they still have to the west. Though this all comes to the expense of the western world, which is kind of required to close the global gap.
We now see the vestigial remains of this “natural state” in western countries, thanks to the changes brought by mass-industrialization and consumerism (both forces being constantly hungry for bodies, and hence working as Great Levellers between sex, race, age, culture, etc) but it’s still very much present all over the world - the problems in Afghanistan or Pakistan are well-reported, for example, but hardly unique.
You must hate women empowerment and be sexist. You must actively support such wishes to be politically correct.
But you seem really upset about all this. To be clear, what you are mad about is how there are lots of men willing to pay to see naked and sexual content online, right? That really upsets you?
Joke apart, the appeal were already there. making money from the comfort of your bed. Seeing the how much money you can make thought, that's what really broke my back.
I think you are hugely overestimating the number of women making any kind of significant money on onlyfans, let alone the kind of "in a month what a software engineer earns in a year" money you're talking about. That's very few people. If that makes you feel better for whatver reason.
Like every other internet hustle (say instagram "influencers"), so many people are hustling and maybe being taken advantage of and making very little. Who does make serious money is some combination of luck, business sense, aptitude, and lots of work. Some women get rich being models too (and this is of course a kind of modeling, or at least that's part of it), but it's not like any woman can just decide to become rich by modeling.
I'm not sure what you're alarmed about, but if you are foreseeing a future where all women choose to pursue no career but onlyfans, which seems to be literally what you are describing being alarmed about, I don't think you have to worry about that, so perhaps you can sleep better.
Also not sure why we're talking about this on a post about Facebook security vulnerability and their bounty program, but ok.
This is a good thing. Sorry if my above comment was dismissive and callous. Honestly, it is kind of sad as a society, that's what ends up being valued more highly.
>knowing that a girl could rely on her beauty to makes thousands of dollars exposing herself to strangers.
That's not really anything new. Such things have always existed.
To be honest, my comment was mainly in reference to the business model itself. It's hard to compare a salary or wage with lots of money from donations or subscriptions.
I'm sure there's people on onlyfans that make barely anything and there's lots of software engineers with high paying jobs.
>Damn it, I have a two year old niece, I guess me and my brother better think something fast, so when shes a teenager she'll be interested in STEM.
I dunno, teach her self respect and explain the value in success using ones talents and abilities as opposed to exploiting their appearance or bodies.
There's always been the option for girls to do the second one. I'm glad your teacher and people like her are trying hard to give girls more options like the first.
Main reason this is so is because of scale. One healthcare worker can look after a ward at most, one software engineer can write software that affects millions in a very small way, and some onlyfans accounts hit a smaller scale but with more revenue per user on average.
but I'll say this: I saw everywhere how underrated health workers are, and I agree. They should be paid a lot more; even more than athletes, in my book.
but how about SE and CS, have you heard anything? the whole economy would crumble, if weren't for online business. internet, apps, video chats, smart phones... I'm yet to see an AD saying thank you for what those brilliant CS and SE people have done for the world.
Sure, of course some software engineers make in a month far more than a plain onlyFans user would make in a year.