Facebook Sweetens Deal for Hackers to Catch Security Bugs

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=vWSCBb0KmSs



Duration: 3:04
5 views
0


Reported today in Wired.

In the wake of extensive mishandling of user data and a series of security missteps, Facebook has deployed a number of security and privacy initiatives. A key focus: expanding its longstanding bug bounty program. Now, Facebook is courting outside hackers more aggressively than ever.

Last year, the company began paying bounties for certain bugs researchers might find in third-party services that integrate with Facebook. Now, the company will expand the types of bugs that are eligible, and even pay out for bugs that have also been directly submitted to another developer's own bug bounty. Essentially, Facebook is willing to reward bugs that impact its platform even if a researcher has already gotten another payout elsewhere for finding it. The company is also adding bonuses from $1,000 to $15,000 if researchers find bugs in the fundamental code of its native products—like WhatsApp, Messenger, Oculus, or Portal—and then also submit additional materials, like showing how the bugs could actually be exploited in the wild. Before now, there wasn’t a specifically codified bonus structure if you went above and beyond in a submission, a practice Facebook wants to encourage.

“Reports submitted to us thanks to security researchers allow us to learn from their insights," says Dan Gurfinkel, who heads Facebook's bug bounty program. "And that allows us to catch more bugs in the future. Humans are always more creative than machines, so we want to see how they’re able to bypass our protections."

In Facebook's notorious data breach last year, for example, hackers abused a chain of three bugs that allowed them to grab account authentication tokens through the 'View As' feature. Around the same time, Facebook disclosed and patched a critical WhatsApp bug submitted through its bounty program that exploited a flaw in the WhatsApp media gallery flow.

Facebook offers a minimum payout of $500 for accepted bugs, and no maximum—meaning that there’s no specific upper limit on how valuable a bug could potentially be. So far the largest payout from Facebook's bounty is $50,000, while Apple will pay out up to $1 million for the most valuable iOS bugs.

It's worth it to Facebook to get on top of the unintended potential data exposures that come from third-party integrations. Facebook previously only allowed bug hunters to submit findings about third parties that came from analyzing publicly available information without actively hacking those services. But now, Facebook will accept bugs discovered through active penetration testing, so long as the approach complies with the guidelines set out by the third-party itself. The idea of potentially double-paying for bugs is unusual, but may give Facebook more insight into the type of bugs third-parties have and whether they've been fixed.

"We know that some bug bounty programs do not get the attention they deserve," he says. "And we want our security researchers to increase the coverage they currently have for these apps and websites to make sure Facebook users remain secure even if the problem doesn’t stem from Facebook itself."

Facebook is also updating its bug bounty terms of service to emphasize that participating hackers will always be protected from reprisal. In the case of third-party bugs found through active analysis, Facebook's bounty will now require that researchers submit proof that their methods were authorized under the third-party's rules.

Gurfinkel says that while Facebook's security team finds many bugs on its own, often using tools like the company's code mapping tool Zoncolan, it also meets once a week to review and analyze reports submitted to the bug bounty. That group then uses those findings to update its bug-hunting arsenal.

"We want to make sure we get more eyes finding security vulnerabilities in Facebook," Gurfinkel says. "And every time a security researcher reports a vulnerability to our program we use the insights they provided us with to see if we can catch not just this instance of the report, but also the whole class of vulnerability."

Some large bug bounties are private and invitation-only, but Facebook will accept bug reports from anyone. This can make for a problematic signal-to-noise ratio at times, but Gurfinkel says it's well worth it to keep the program open and receive the most diverse, far-reaching array of bug submissions possible. In total, the bounty had about 700 valid submissions in 2018 and will likely surpass that number in 2019. But though all of Tuesday's changes seem positive, a bug bounty can only be one piece of a larger security strategy. Hopefully Facebook isn't compensating for something.




Other Videos By Colin Boyd SEO


2019-10-15You can’t use the Pixelbook Pen with the Pixelbook Go
2019-10-15Uber, Spin, and Lime scooters are now legal in San Francisco, but Skip is out
2019-10-15Meetup wants to charge users $2 just to RSVP for events — and some are furious
2019-10-15Politicians aren’t ‘entirely’ above the rules, Twitter says
2019-10-15New Google Devices, Mouse Mind Reading, and More News
2019-10-15New computer model predicts where Ebola might strike next
2019-10-15Sony is launching its 360-degree audio format this fall
2019-10-15Google to revamp Nest Aware with simpler pricing and new features
2019-10-15Chromebook 101: How to change your Chrome OS channels and get unreleased features
2019-10-15Harry Potter fans can spend $75 a year on a new subscription service
2019-10-15Facebook Sweetens Deal for Hackers to Catch Security Bugs
2019-10-15How to buy the Google Pixel 4 and the 4 XL
2019-10-15The Pixel 4 doesn’t include any headphones, or even a 3.5mm adapter in the box
2019-10-15YouTube gets alleged copyright troll to agree to stop trolling YouTubers
2019-10-15Google is discontinuing the Daydream View VR headset, and the Pixel 4 won’t support Daydream
2019-10-15How to Watch the Fourth Democratic Primary Debate Tonight
2019-10-15Elizabeth Warren swears off major donations from Facebook, Google executives
2019-10-15Google Pixel 4 buyers won’t get unlimited photo uploads at original quality
2019-10-15Pixel Buds 2 hands-on: Google takes on the AirPods
2019-10-15Pixel 4 Recorder app can transcribe speech in real time without an internet connection
2019-10-15Google’s new Nest Mini has better controls, similar sound, and the same price