Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In other words, if you wanted to game the odds, you'd start by offering it on the black market, then if there were no takers after X number of days, offer it to Facebook?


It is unlikely that there is any black market for this bug, or for the RCE that compromised Facebook's crypto secrets.

https://news.ycombinator.com/item?id=11249173


Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html


Like Dylan says, people will pay for web server software bugs, if the software is widely installed, because you can make money by building and grooming a fleet of compromised servers. There is a way to do it, and that way works.

There is not a good, reliable way to make money from Facebook account takeover. You can conceive of them speculatively, but that is not the same thing as knowing you can execute, or, better, already having a business process in place that is already executing, just waiting for a new bug.


Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck".

I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.


>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun*

I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account.

You'd have to have a real vendetta against someone to value ruining their life at $15k.


> You'd have to have a real vendetta against someone to value ruining their life at $15k.

15k is actually cheap when compared with the costs of a private eye, a biker gang or a contract killer.


For a political hit, $15k might be a very reasonable valuation.


> You'd have to have a real vendetta against someone to value ruining their life at $15k.

You're thinking about it wrong. There is no opportunity cost in their worldview, just lulz to be had at the expense of people they deem worthy of ruination.

(I never said the people that live in the intersection of trolls and blackhats are great at financial or career planning, after all.)


Footnote on the graphic: *All payout amounts are chosen at the discretion of ZERODIUM and are subject to change or cancellation without notice.

Translation: "Show us what you got and then we'll screw you over."

Sounds like you're less likely to get screwed by an escrow service found on TOR.


Or simply publishing it first and leveraging to opportunity for contract work. I'd really hope you're able to get a commitment from ZERODIUM before giving them the details.


This comment states:

> Facebook's security team is one of the strongest and most sophisticated of any company

If that is true, how come they didn't catch this relatively obvious glitch discussed here.


No team can catch all the bugs.

As for 'obvious', hindsight, yada yada.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: