Identify a Facebook user by his phone number despite privacy settings set
ysamm.com
ysamm.com
The Others don’t matter to determine the value here; there is only one person to sell to.
It's not intended as a source of primary income, it's an incentive to report vulnerabilities when you find them. It's the tech industry equivalent of getting a box of beers for helping out.
Any attempt to hurt the system will ultimately make the system stronger[1]. If you attack FB or bug bounties by leaking vulns it will hurt users only.
Responsible disclosure is a farce where people volunteer to help large corporations augment their Q&A processes in most cases without pay. The only winners (except organizations) are the bug-bounty market places which help rig the game and extract what should be done by somebody on a permanent salary and 401. But in a society that normalizes having no health insurance and instead considers it normal for cancer treatment to start a gofundme, there is little surprise that "jobs" exist where you only get paid if you produce a result. It is capitalism functioning as intended.
The tragedy is that the asymmetry of number of people unwilling to do responsible disclosure (SandboxEscaper[2], Janit0r[3], etc) and those others who can afford to invest a year of their time without salary is too big. With every good person that "rips these companies a new one", there will be more pressure on the company to "improve security", which leads to higher bug-bounty payouts but also more people entering the market and competition among the masses to fight for the prize. The only way this is fair is if there is a UBI (and also then only if the it is truly universal or the bounties are limited to locations where people are covered by UBI)
The bug bounties are often defended by people who had success in it and went on to make a name for themselves in infosec. Because why wouldn't they defend a system that seemed to have worked for them?
But it's not like these companies couldn't afford to pay proper wages for those people who tried but failed as well. The argument that it gives you the required experience with some beer-money to become a better hacker, or that it is so much fun is a strawman. Because those few that are getting paid for their "hobby" doesn't count since it ignores those that compete HungerGames style because they don't know where else to go with their silly degree stuck in a country where nobody wants to hire them (regardless of WFH & remote-only).
The solution imho is regulation and legislation of these firms. Force them to pay their taxes, to store data locally so it never leaves a jurisdiction, outlaw targeted advertising, use criminal law for CEO's who bust unions, etc etc. How they do this is their problem really. On a technical side they could use SCION protocol to ensure no packet ever leaves a block of countries that are legally aligned with these rules. Or they can use their much beloved AI that they speak constantly about when dragged in front of congress. It doesn't matter what route people take as long as we start holding them accountable.
Finally create enough awareness in society that if these cases continue to exist, then a manager from such a company will be unable to travel to your country, or that somebody working at X will not be celebrated as "probably a genius" in society but the "useful idiots" that they are. Also people who work for a (legal) secret tax jurisdiction that have dirt on these companies or their employees they can be a real hero by breaking that country's law and leak info about the international financial crimes committed by these firms. But that takes more guts than dropping vulns or simply "deleting fartbook".
These measures would address the problem at its root, hurt the company and its shareholders financially, while even creating jobs in these places and who knows lift a few people out of poverty.
[1] "The Technological Society" by Jacques Ellul: https://archive.org/details/JacquesEllulTheTechnologicalSoci...
[2] https://twitter.com/SandboxEscaper (suspended)
[3] https://www.bleepingcomputer.com/news/security/brickerbot-au...
I don't get this. What's wrong with incentevizing bounty hunting? Isn't the whole point of bounties to provide an incentive to the public to find & report bugs?
Personally, if I found a bug that had a market, it's going to the highest (legal) bidder. Be it Mossad, Facebook or Mr. Bone Saw's personal security team. Bug hunting is a professional service not a humanitarian one.
This strategy (although certainly better-intentioned) failed for the same reason your proposal would fail.
What’s the similarity here? I’m not entirely sure a fairy tale disproves OPs argument, particularly when the circumstances are so different (you can’t bring in bugs from another app, facebook has a history of paying up and the bounty fees are tiny for them).
To some extent this dynamic must already exist, which is a troubling thought.
I've not seen any evidence for this behaviour existing, even with Microsoft Bug Bounties of up to $250,000, or even heard of developers being tempted to introduce bugs for friends to find them.
I assume the bigger risk is developers intentionally introduce bugs for nefarious purposes (i.e. black market sale), rather than to win a bug bounty.
I wonder if OP tried bulk requests see if there is any request limit or other throttling checks at least.
> Identify a Facebook user by *his* phone number despite privacy settings set
Stop being so obtuse about exculpatory mistakes; I am not suggesting HN comments should be humourless, but this is not Reddit.
No one can tell if you're genuinely offended (by grammar or societal gender-terms) by or just a smart arse, your sarcastic tone implies the latter.
I don't think "exculpatory" means what you think it means.
https://www.merriam-webster.com/dictionary/exculpatory#note-...
Yep my usage a bit odd, I forgot it is a common legal term. Maybe *trivial* would be a better word.