Monday, October 2, 2023
Krypto Portfolio
No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Altcoin
  • DeFi
  • Dogecoin
  • Regulations
  • NFT
  • Blockchain
  • More
    • XRP
    • Market & Analysis
KRYPTO PORTFOLIO
No Result
View All Result
Home NFT

Hacking the metaverse: Why Meta wants you to find the flaws in its newest headsets

admin by admin
July 19, 2023
in NFT
0
Hacking the metaverse: Why Meta wants you to find the flaws in its newest headsets
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Close-up of a young, blonde woman wearing a Meta Quest 2 VR headset

Related articles

Back To BlockShine ☀️

Back To BlockShine ☀️

September 29, 2023
Meta Quest 2 vs Quest 3: How to decide which one is right for you

Meta Quest 2 vs Quest 3: How to decide which one is right for you

September 28, 2023

Picture: Meta

When any new expertise emerges, cyber criminals and fraudsters will virtually instantly take a look to see what’s in it for them.

The web, smartphones and the Web of Issues have more and more turn out to be a part of how we stay our lives — and all of those applied sciences are focused by malicious hackers seeking to steal passwords, personal information, bank details, and extra. 

So, as the metaverse and virtual reality emerge as a brand new technique to live, work and relax on the internet, these platforms will even quickly turn out to be the goal for cyber criminals, eager to seek out and exploit vulnerabilities in {hardware} and software program or maybe to make use of the expertise to help their scams. 

Now Fb proprietor Meta, which is ploughing huge sums into its metaverse-building tasks, needs to get forward of the hackers by asking safety researchers to determine vulnerabilities and points in metaverse-related merchandise, similar to Meta Quest, Meta Quest Pro and the Meta Quest Touch Pro, with real disclosures rewarded with bug bounty funds that probably quantity to a whole bunch of 1000’s of {dollars}. 

Facebook has operated a bug bounty program for its web applications since 2011, however regardless of the metaverse being a key pillar of Meta’s business strategy, the corporate continues to be comparatively new to creating {hardware}.  

Additionally: The metaverse is coming and the security threats have already arrived 

Nonetheless, by encouraging cybersecurity specialists from exterior Meta to hack the metaverse, the corporate’s seeking to enhance the safety of merchandise for everybody.  

“Considered one of our priorities is to additional combine the exterior analysis group with us on our journey to safe the metaverse. As a result of this can be a comparatively new house for a lot of, we’re working to make the expertise extra accessible to bug hunters and to assist them submit legitimate reviews sooner,” says Neta Oren, safety analyst supervisor and bug bounty lead at Meta. 

A part of the technique behind this work entails getting Meta’s digital actuality headsets on the market in entrance of safety researchers and hackers, attaining this with Meta BountyCon, a safety conferenced centered round bug bounties that enables hunters to get hands-on with merchandise. 

The latest occasion noticed a concentrate on rising threats within the VR house, one thing Oren describes as an intentional transfer in the direction of “the purpose of creating all the business safer”. 

Meta has up to date its bug bounty phrases to spotlight that its newest merchandise, Meta Quest Professional and the Meta Quest Contact Professional controllers, are eligible for the bug bounty program, and has added new payout pointers for VR expertise, together with bugs particular to Meta Quest Professional.

And for many who discover safety vulnerabilities in Meta’s digital actuality and metaverse expertise, there are monetary rewards for bug bounties of probably a whole bunch of 1000’s of {dollars}. 

Amongst different issues, the payout guidelines element how funds for locating cell distant code execution bugs — vulnerabilities that would permit an attacker to execute malware or take management of a tool — might be as much as $300,000, whereas researchers who uncover account takeover vulnerabilities might be rewarded with as much as $130,000. 

The monetary rewards are excessive as a result of Meta needs to encourage {hardware} hackers who might not have regarded on the firm’s digital actuality choices earlier than. 

“We need to assist researchers prioritise their efforts and concentrate on a few of the most impactful areas throughout our platform,” says Oren. 

The bug bounty scheme has already resulted within the disclosure of a number of beforehand undiscovered vulnerabilities.

Additionally: Accidental teleports and virtual high-fives: What I’ve learned about VR meetings

A disclosure submitted at BountyCon discovered a problem in Meta Quest’s oAuth circulate — an open commonplace used to grant web sites or purposes entry to person’s data on different web sites, which might have led to an attacker gaining management of a person’s entry token, and management of their account, with simply two clicks 

“We mounted this concern, and our investigation discovered no proof of abuse and we rewarded this report a complete of $44,250, which displays the influence of the vulnerability,” says Oren. 

One other researcher was awarded $27,200 after discovering a vulnerability that would have allowed an attacker to bypass SMS-based 2FA by exploiting a rate-limiting concern to brute power the verification pin required to verify somebody’s telephone quantity. The vulnerability was additionally mounted after disclosure. 

These vulnerabilities may not have been uncovered — at the least not as shortly — with out the bug bounty scheme, which is why, for Meta, it is vital to proceed to broaden it. 

“We welcome any contribution from the exterior group to get as many eyes on the code as doable, persevering with to check our merchandise, and make them safer,” says Oren. 

The bug bounty program for the metaverse follows within the footsteps of Meta’s different bug bounty schemes, a few of which have been working for a decade — and the corporate additionally has a spread of knowledge safety groups to assist be sure that the metaverse and Meta’s different platforms are as safe towards cyber threats as doable. 

They embrace safety evaluations of merchandise, a threat-modelling crew, a red team running penetration tests against the company, and extra, which is all along with the bug bounty program. All of this effort matches collectively for Meta to make sure that any product launched is as safe towards as many threats as doable. 

“These are all issues we have discovered through the years that we apply once we construct new merchandise, so the brand new merchandise have already got all these embedded into them,” says Oren. 

Additionally: Cybersecurity: These are the new things to worry about in 2023

After new vulnerabilities, that are disclosed as a part of the bug bounty scheme, have been investigated and mitigated, safety updates are rolled out to the merchandise. To make sure that the safety updates that repair vulnerabilities are utilized, Meta’s VR merchandise routinely verify for updates at launch after which apply them. 

“We’re sharing these bugs publicly to ensure everybody within the business can study from us. It’s normal that when one huge firm publishes some of these issues, different firms will look internally for one thing related,” Oren explains. 

And since exterior researchers aren’t restricted to Meta merchandise, in the event that they discover one thing in Meta Quest Professional or one other Meta system, they’re additionally seemingly to take a look at related merchandise constructed by others. 

“We all know that our researchers do not solely hunt on Meta. So, in the event that they discover a bug with us, they may then go and search for it in our rivals and they’re going to report it to them as properly,” says Oren. 

“That is why we expect training is so vital as a result of the researchers, no matter they study with us, they’re going to implement for different firms whereas they hunt,” she says. 

MORE ON CYBERSECURITY





Source link

Tags: findflawsHackingheadsetsMetametaversenewest
Share76Tweet47
Previous Post

Dogecoin (DOGE) Engagement Fails To Impress

Next Post

IMF Urges Fiat Currency Be Protected From Crypto, Says Digital Assets Should Never Be Accepted As Legal Tender

Related Posts

Back To BlockShine ☀️

Back To BlockShine ☀️

by admin
September 29, 2023
0

As I child I bear in mind studying a Donald Duck story about him being pissed off that folks have...

Meta Quest 2 vs Quest 3: How to decide which one is right for you

Meta Quest 2 vs Quest 3: How to decide which one is right for you

by admin
September 28, 2023
0

June Wan/ZDNETThe Meta Quest 3 launch is upon us, and early reviews point out that it is coming with some...

Swiss Web3 Tornado

Swiss Web3 Tornado

by admin
September 26, 2023
0

Coin Fam🇨🇭☀️ Within the final article we teased VESA being in Switzerland, and the way the nation is advancing leaps...

OpenSim land area at new all-time-high — again – Hypergrid Business

OpenSim land area at new all-time-high — again – Hypergrid Business

by admin
September 16, 2023
0

OpenSim land space has handed 130,000 customary area equivalents this month, for a brand new all-time excessive. That is the...

SOLD OUT Synthopia NFT Drop & Updates

SOLD OUT Synthopia NFT Drop & Updates

by admin
September 14, 2023
0

Pay attention up, degens Summer season’s out, and it's time to gear up for one more season of Web3 and...

Load More
  • Trending
  • Comments
  • Latest
Gary Gensler is hurting the little guys for Wall Street

Gary Gensler is hurting the little guys for Wall Street

June 27, 2023
how web3 companies are leveraging AI

how web3 companies are leveraging AI

June 28, 2023
Hong Kong’s crypto push puts HSBC and StanChart in a bind

Hong Kong’s crypto push puts HSBC and StanChart in a bind

June 27, 2023
Why The Ripple General Counsel Demands Impartiality From SEC Staff

Why The Ripple General Counsel Demands Impartiality From SEC Staff

June 27, 2023
Bitcoin gets leg-up from Chinese liquidity: Here’s why this is important

Bitcoin gets leg-up from Chinese liquidity: Here’s why this is important

0
Lido Centralization Risks On Ethereum Raises Concerns: Will LDO Crash?

Lido Centralization Risks On Ethereum Raises Concerns: Will LDO Crash?

0
24 Crypto Terms You Should Know

24 Crypto Terms You Should Know

0
Blockchain Pioneers Vitalik Buterin, Polygon Co-founder Commit $100M To Pandemic Research

Blockchain Pioneers Vitalik Buterin, Polygon Co-founder Commit $100M To Pandemic Research

0
Musée d’Orsay Embraces Crypto to Attract New Audiences

Musée d’Orsay Embraces Crypto to Attract New Audiences

October 2, 2023
Trader Calls Ethereum-Based Altcoin ‘Most Obvious Play’ Amid Bear Market, Predicts Rally for Bitcoin and ETH

Trader Calls Ethereum-Based Altcoin ‘Most Obvious Play’ Amid Bear Market, Predicts Rally for Bitcoin and ETH

October 2, 2023
Is Uptober here? Bitcoin, Ethereum suddenly pumps, wiping $70M in shorts

Is Uptober here? Bitcoin, Ethereum suddenly pumps, wiping $70M in shorts

October 2, 2023
Bitcoin holders show renewed confidence in the king coin

Bitcoin holders show renewed confidence in the king coin

October 2, 2023

Live Prices

Recent News

Musée d’Orsay Embraces Crypto to Attract New Audiences

Musée d’Orsay Embraces Crypto to Attract New Audiences

October 2, 2023
Trader Calls Ethereum-Based Altcoin ‘Most Obvious Play’ Amid Bear Market, Predicts Rally for Bitcoin and ETH

Trader Calls Ethereum-Based Altcoin ‘Most Obvious Play’ Amid Bear Market, Predicts Rally for Bitcoin and ETH

October 2, 2023
Is Uptober here? Bitcoin, Ethereum suddenly pumps, wiping $70M in shorts

Is Uptober here? Bitcoin, Ethereum suddenly pumps, wiping $70M in shorts

October 2, 2023

Browse By Tags

Altcoin Analyst appeal Bank Binance Bitcoin Blockchain Blog BTC Bulls Business CEO Coinbase Court Crypto Data DeFi digital Dogecoin ETF ETH Ethereum Exchange Foundation FTX Futures Heres Hypergrid IBM Key Lawsuit Market Million network Price Rally REPORT Ripple Sam SEC Top Trading Whales Whats XRP

© 2023 All rights Reserved | krypto Portfolio | Impressum | SEO.CH

No Result
View All Result
  • Home
  • Cryptocurrency
  • Bitcoin
  • Ethereum
  • Altcoin
  • DeFi
  • Dogecoin
  • Regulations
  • NFT
  • Blockchain
  • More
    • XRP
    • Market & Analysis

© 2023 All rights Reserved | krypto Portfolio | Impressum | SEO.CH