Live data from Hacker News

Viewing profile — arice

arice

HN member
Joined
Wed, May 05, 2010, 9:00 PM UTC
HN karma
333
Public activity
22 items

About arice

founder & cto, hackerone | internet bug bounty | former facebook security

https://twitter.com/senorarroz

Recent public activity

  1. comment
    Comment #31952507

    [HackerOne CTO here] There are certainly some important lessons for us to learn here but, just for clarity, this wasn't one of them. The data access in question here was central to…

  2. comment
    Comment #14269168

    That's helpful feedback on missing context from our post. Thanks. This series by VICE articulates the sometimes subtle distinctions between legitimate monitoring software built for…

  3. story
  4. comment
    Comment #10554713

    That's me, and I'm quite embarrassed as I never paused to consider how it could be interpreted. That was a real story. Shortly after we established Facebook's bug bounty program, w…

  5. comment
    Comment #10554595

    Great questions. We'll line up a more analytical post on the topic as I don't know all the answers here, and we all should. In the interim, here's a few rough from memory answers: …

  6. comment
    Comment #10521492

    Great feedback, thanks. The 180 day guidance you reference falls under a "Last Resort" clause when "... the Response Team [is] unable or unwilling to provide a disclosure timeline"…

  7. comment
    Comment #9581180

    I don't make a habit of storing assets in banks that fail to insure me against a total loss of those assets. That insurance just happens to require extensive third-party verificati…

  8. comment
    Comment #9581114

    The stance you take is harmful when said organizations are responsible for the stewardship of the data of others, and being "less secure" places the general public at risk. The tru…

  9. comment
    Comment #7133289

    This is great work by Egor, as usual. I work on Facebook's security and thought I'd add a bit more clarity here on the mitigation steps available to developers. Awareness here is i…

  10. story
  11. comment
    Comment #5379517

    Hopefully not too oddly: Facebook was one of the first OAuth 2.0 implementations and the additional benefits of requiring stricter pre-registration was not initially apparent. An u…

  12. comment
    Comment #4986959

    I'm very sorry you had this experience. We would never intentionally ignore a legitimate bug report. If you could send me a message (link in profile) with the e-mail address you us…

  13. comment
    Comment #4541013

    FYI: Facebook has open sourced this tool, you can find it on github. Here's the commit that added Bootstrap: https://github.com/daaku/rell/commit/64bd62d40df54ddc08a9270...

  14. comment
    Comment #3605692

    Unfortunately, much of the internet industry has an established history of doing just that. This heavy-handed approach to vulnerability disclosure has led to an atmosphere of distr…

  15. comment
    Comment #3605584

    Facebook's Responsible Disclosure Policy applies to all Facebook properties. The exceptions you outlined specifically apply to our bounty program. Basically, we may not pay a cash …

  16. comment
    Comment #3605343

    I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they …

  17. comment
    Comment #1934389

    Not every computer is guaranteed to be free of malicious software capable of acting on behalf of the individual. This necessitates that security filters operate on private communic…

  18. comment
    Comment #1617770

    Yishan Wong makes some interesting points: http://www.quora.com/Are-Foursquare-and-Gowalla-going-to-sur...

  19. comment
    Comment #1443908

    I'm a confused user: The field didn't tell me what I should put in, so I just typed Bob and it worked.

  20. comment
    Comment #1377671

    The same choice is still possible on Facebook, no? There is a default-unchecked "Keep me logged in" box and a Logout button.

  21. comment
    Comment #1357835

    FWIW, the previous default was "Friends and Networks", not "Friends and Family". That includes Networks like the United Kingdom with 20M users and no restrictions on who could join…

  22. comment
    Comment #1356341

    Haha! If that is a virus, then so is this: http://news.ycombinator.com/item?id=1354731 :-)