How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?
How much would an exploit like this be worth on the black market? What's the potential loss / liability on Facebook's side? Hundreds of thousands? Millions?
It is far more convenient (and safer) to just take the guaranteed ~$10K and move on with your life.
Would that work? Asking for a friend.
Corporate espionage exists, insider trading exists (and is more common than you might think), there's any number of parties who might pay for insider info (once properly laundered) about Facebook activities.
Why would "the government of Iran" care about what Facebook is up to? Isn't FB banned in Iran?
What multiplier of the $7500 bounty would you want for the trouble of committing a crime? Who's the buyer (FB afaik doesn't buy a whole lot of publicly traded companies, so it probably needs to be someone who can get into the deals, and quickly)? How do you find them? How do you convince that buyer that your deal is worth the money and the hassle of committing a crime? How do you trust the buyer? How do you handle it if the hole gets closed before the buyer can profit? How do you value the risk it gets closed before you got your deal? Does all that work out in a way that you really don't want to take the bounty?
People buying backdoor access into companies probably happens occasionally, but it's probably not the easy high-profit thing compared to bounties many people think, but rather on the level of selling account information by the dozen for a few bucks - and for something like that you'll burn them quickly.
There are markets for vulnerabilities that slot seamlessly into existing business processes. In other words, you can tend to find a buyer for a vulnerability that would replace another vulnerability already being used, that accomplishes pretty much exactly the same thing as that vulnerability. The more people run that business process, the more likely it is that there's a liquid market.
Lots of organizations have business processes that rely on browser RCEs. Generally, there aren't many organizations that have business process that rely on serverside vulnerabilities in line-of-business applications that have instantaneous half-lives, because once the patch is developed they're gone.
(‘?’ because I’m on my third whiskey and about to turn in :)
https://thehustle.co/coca-cola-stolen-recipe
> Months earlier, when Pepsi received the trio’s initial letter, they’d promptly forwarded it to Coca-Cola, and informed them they had a leaker. In turn, Coca-Cola had brought in the FBI to conduct an undercover investigation.
> On July 5, 2006, Williams, Dimson, and Duhaney were arrested on charges of wire fraud and unlawfully stealing and selling trade secrets.