Monday, December 4, 2023
AXELAR
No Result
View All Result
  • Home
  • Crypto
  • Blockchain
  • Market & Analysis
  • Bitcoin
  • Ethereum
  • Fintech
  • NFTs & Web 3.0
  • Altcoins
  • DeFi
  • Dogecoin
  • XRP
AXELAR
No Result
View All Result
Home NFTs & Web 3.0

Hacking the metaverse: Why Meta wants you to find the flaws in its newest headsets

Axelar by Axelar
June 30, 2023
in NFTs & Web 3.0
0
Meta lowered the age limit for Quest accounts. Are these kids too young for exploring VR?
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Close-up of a young, blonde woman wearing a Meta Quest 2 VR headset

Related articles

This Finnish startup’s new VR headset rivals Apple’s Vision Pro – and business users will love it

This Finnish startup’s new VR headset rivals Apple’s Vision Pro – and business users will love it

December 3, 2023
Exploring NFTs for Written Works

Exploring NFTs for Written Works

December 1, 2023

Picture: Meta

When any new expertise emerges, cyber criminals and fraudsters will virtually instantly take a look to see what’s in it for them.

The web, smartphones and the Web of Issues have more and more grow to be a part of how we dwell our lives — and all of those applied sciences are focused by malicious hackers trying to steal passwords, personal information, bank details, and extra. 

So, as the metaverse and virtual reality emerge as a brand new option to live, work and relax on the internet, these platforms may even quickly grow to be the goal for cyber criminals, eager to search out and exploit vulnerabilities in {hardware} and software program or maybe to make use of the expertise to assist their scams. 

Now Fb proprietor Meta, which is ploughing huge sums into its metaverse-building initiatives, needs to get forward of the hackers by asking safety researchers to determine vulnerabilities and points in metaverse-related merchandise, resembling Meta Quest, Meta Quest Pro and the Meta Quest Touch Pro, with real disclosures rewarded with bug bounty funds that doubtlessly quantity to a whole lot of hundreds of {dollars}. 

Facebook has operated a bug bounty program for its web applications since 2011, however regardless of the metaverse being a key pillar of Meta’s business strategy, the corporate remains to be comparatively new to creating {hardware}.  

Additionally: The metaverse is coming and the security threats have already arrived 

Nonetheless, by encouraging cybersecurity consultants from outdoors Meta to hack the metaverse, the corporate’s trying to enhance the safety of merchandise for everybody.  

“Certainly one of our priorities is to additional combine the exterior analysis neighborhood with us on our journey to safe the metaverse. As a result of it is a comparatively new house for a lot of, we’re working to make the expertise extra accessible to bug hunters and to assist them submit legitimate experiences sooner,” says Neta Oren, safety analyst supervisor and bug bounty lead at Meta. 

A part of the technique behind this work includes getting Meta’s digital actuality headsets on the market in entrance of safety researchers and hackers, attaining this with Meta BountyCon, a safety conferenced centered round bug bounties that enables hunters to get hands-on with merchandise. 

The newest occasion noticed a give attention to rising threats within the VR house, one thing Oren describes as an intentional transfer in direction of “the purpose of constructing your complete business safer”. 

Meta has up to date its bug bounty phrases to spotlight that its newest merchandise, Meta Quest Professional and the Meta Quest Contact Professional controllers, are eligible for the bug bounty program, and has added new payout tips for VR expertise, together with bugs particular to Meta Quest Professional.

And for many who discover safety vulnerabilities in Meta’s digital actuality and metaverse expertise, there are monetary rewards for bug bounties of doubtless a whole lot of hundreds of {dollars}. 

Amongst different issues, the payout guidelines element how funds for locating cellular distant code execution bugs — vulnerabilities that might enable an attacker to execute malware or take management of a tool — may very well be as much as $300,000, whereas researchers who uncover account takeover vulnerabilities may very well be rewarded with as much as $130,000. 

The monetary rewards are excessive as a result of Meta needs to encourage {hardware} hackers who might not have seemed on the firm’s digital actuality choices earlier than. 

“We wish to assist researchers prioritise their efforts and give attention to a few of the most impactful areas throughout our platform,” says Oren. 

The bug bounty scheme has already resulted within the disclosure of a number of beforehand undiscovered vulnerabilities.

Additionally: Accidental teleports and virtual high-fives: What I’ve learned about VR meetings

A disclosure submitted at BountyCon discovered a problem in Meta Quest’s oAuth circulate — an open commonplace used to grant web sites or purposes entry to person’s data on different web sites, which might have led to an attacker gaining management of a person’s entry token, and management of their account, with simply two clicks 

“We fastened this situation, and our investigation discovered no proof of abuse and we rewarded this report a complete of $44,250, which displays the influence of the vulnerability,” says Oren. 

One other researcher was awarded $27,200 after discovering a vulnerability that might have allowed an attacker to bypass SMS-based 2FA by exploiting a rate-limiting situation to brute pressure the verification pin required to substantiate somebody’s cellphone quantity. The vulnerability was additionally fastened after disclosure. 

These vulnerabilities may not have been uncovered — at the least not as shortly — with out the bug bounty scheme, which is why, for Meta, it is essential to proceed to develop it. 

“We welcome any contribution from the exterior neighborhood to get as many eyes on the code as potential, persevering with to check our merchandise, and make them safer,” says Oren. 

The bug bounty program for the metaverse follows within the footsteps of Meta’s different bug bounty schemes, a few of which have been working for a decade — and the corporate additionally has a spread of knowledge safety groups to assist be certain that the metaverse and Meta’s different platforms are as safe in opposition to cyber threats as potential. 

They embody safety opinions of merchandise, a threat-modelling workforce, a red team running penetration tests against the company, and extra, which is all along with the bug bounty program. All of this effort matches collectively for Meta to make sure that any product launched is as safe in opposition to as many threats as potential. 

“These are all issues we have discovered over time that we apply once we construct new merchandise, so the brand new merchandise have already got all these embedded into them,” says Oren. 

Additionally: Cybersecurity: These are the new things to worry about in 2023

After new vulnerabilities, that are disclosed as a part of the bug bounty scheme, have been investigated and mitigated, safety updates are rolled out to the merchandise. To make sure that the safety updates that repair vulnerabilities are utilized, Meta’s VR merchandise robotically verify for updates at launch after which apply them. 

“We’re sharing these bugs publicly to verify everybody within the business can be taught from us. It’s normal that when one large firm publishes most of these issues, different corporations will look internally for one thing comparable,” Oren explains. 

And since outdoors researchers aren’t restricted to Meta merchandise, in the event that they discover one thing in Meta Quest Professional or one other Meta system, they’re additionally possible to take a look at comparable merchandise constructed by others. 

“We all know that our researchers do not solely hunt on Meta. So, in the event that they discover a bug with us, they could then go and search for it in our opponents and they’re going to report it to them as properly,” says Oren. 

“That is why we predict training is so essential as a result of the researchers, no matter they be taught with us, they will implement for different corporations whereas they hunt,” she says. 

MORE ON CYBERSECURITY





Source link

Tags: findflawsHackingheadsetsMetametaversenewest
Share76Tweet47
Previous Post

Noah (NOAH) Remains Neutral%, Underperforms the Crypto Market Thursday

Next Post

The Huge Power and Potential Danger of AI-Generated Code

Related Posts

This Finnish startup’s new VR headset rivals Apple’s Vision Pro – and business users will love it

This Finnish startup’s new VR headset rivals Apple’s Vision Pro – and business users will love it

by Axelar
December 3, 2023
0

VarjoWhen Apple launched its Vision Pro earlier this yr, it joined a crowded virtual reality headset market that features entries...

Exploring NFTs for Written Works

Exploring NFTs for Written Works

by Axelar
December 1, 2023
0

This can be a put up that I wrote again in 2021 on the top of the NFT mania. The...

This new VR headset rivals Apple’s Vision Pro – but it’s not for most people

This new VR headset rivals Apple’s Vision Pro – but it’s not for most people

by Axelar
November 29, 2023
0

VarjoWhen Apple launched its Vision Pro earlier this yr, it joined a crowded virtual reality headset market that features entries...

VESA at Cypher Capital

VESA at Cypher Capital

by Axelar
November 25, 2023
0

  Hello fam, At present we’re celebrating a union that occurred lately when VESA travelled to Dubai for a month...

How Fnality and J.P. Morgan are Redefining Finance

How Fnality and J.P. Morgan are Redefining Finance

by Axelar
November 23, 2023
0

Final week noticed a few main bulletins coming from enterprises with their blockchain initiatives. These are altering the face of...

Load More

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Using Cloudflare Pages with IPFS

Using Cloudflare Pages with IPFS

June 12, 2023
VC Spectra Gaining Momentum Against Cosmos and Bitcoin – CryptoMode

VC Spectra Gaining Momentum Against Cosmos and Bitcoin – CryptoMode

August 2, 2023
Crypto Analyst Lays Out 2025 Solana (SOL) Price Target, Updates Outlook on Chainlink (LINK)

Crypto Analyst Lays Out 2025 Solana (SOL) Price Target, Updates Outlook on Chainlink (LINK)

July 26, 2023
ApeX Protocol Welcomes New Telegram Bot for Derivatives Trading

ApeX Protocol Welcomes New Telegram Bot for Derivatives Trading

October 3, 2023
USDT, USDC, and DAI: Has the SEC kickstarted stablecoin season?

USDT, USDC, and DAI: Has the SEC kickstarted stablecoin season?

0
Lido Centralization Risks On Ethereum Raises Concerns: Will LDO Crash?

Lido Centralization Risks On Ethereum Raises Concerns: Will LDO Crash?

0
24 Crypto Terms You Should Know

24 Crypto Terms You Should Know

0
Monaco, NFTs, And Formula 1: Reasons Polygon Is Bullish

Monaco, NFTs, And Formula 1: Reasons Polygon Is Bullish

0
Navigating the Crypto Seas: A Guide to Intelligent Investing in Cryptocurrency | by Mystic Mirage | Dec, 2023

Navigating the Crypto Seas: A Guide to Intelligent Investing in Cryptocurrency | by Mystic Mirage | Dec, 2023

December 4, 2023
Will Bitcoin break into the $40k range soon?

Will Bitcoin break into the $40k range soon?

December 4, 2023
ChatGPT thinks $8 is a realistic target for XRP in 2024

ChatGPT thinks $8 is a realistic target for XRP in 2024

December 4, 2023
OpenAI Agreed to Buy $51 Million of AI Chips From a Startup Backed by CEO Sam Altman

OpenAI Agreed to Buy $51 Million of AI Chips From a Startup Backed by CEO Sam Altman

December 4, 2023

Recent News

Navigating the Crypto Seas: A Guide to Intelligent Investing in Cryptocurrency | by Mystic Mirage | Dec, 2023

Navigating the Crypto Seas: A Guide to Intelligent Investing in Cryptocurrency | by Mystic Mirage | Dec, 2023

December 4, 2023
Will Bitcoin break into the $40k range soon?

Will Bitcoin break into the $40k range soon?

December 4, 2023

Categories

  • Altcoins
  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • DeFi
  • Dogecoin
  • Ethereum
  • Fintech
  • Market & Analysis
  • NFTs & Web 3.0
  • Uncategorized
  • XRP

Recommended

  • Navigating the Crypto Seas: A Guide to Intelligent Investing in Cryptocurrency | by Mystic Mirage | Dec, 2023
  • Will Bitcoin break into the $40k range soon?
  • ChatGPT thinks $8 is a realistic target for XRP in 2024
  • OpenAI Agreed to Buy $51 Million of AI Chips From a Startup Backed by CEO Sam Altman
  • Pax Dollar (USDP) Falls 0%, Underperforms the Crypto Market Sunday

© 2023 AXELAR | All Rights Reserved

No Result
View All Result
  • Home
  • Crypto
  • Blockchain
  • Market & Analysis
  • Bitcoin
  • Ethereum
  • Fintech
  • NFTs & Web 3.0
  • Altcoins
  • DeFi
  • Dogecoin
  • XRP

© 2023 AXELAR | All Rights Reserved