Earlier quoted context omitted.
How is that a "no true scotsman"? Most people in this thread commenting have not indicated they work in the infosec industry. (For the record, I do, though I'm not sure I'd flatter myself by saying I'm "experienced" exactly.)
The problems I have with your absolute statement: * You are stating that all (not some) experienced security folks are agreeing unanimously. The implication is that those show disagree are not "experienced security guys" (as you called them: "everyone else") - they are the ones who aren't true scotsman * you assume those who don't explicitly indicate that they work in infosec industry do not work in the infosec indus…
Instagram's Million Dollar Bug
521–530 of 562 posts
Re: Instagram's Million Dollar Bug
#522Re: Instagram's Million Dollar Bug
#523Posting this write-up might be the last thing the researcher should have done--from a criminal liability perspective. First, the negative press might serve to piss off Facebook (who could have some perspective we are not privy to here). From Facebook's angle, the criminal aspect here may be a much closer issue, and this write-up could serve as the tipping point. Second, as a party admission, this post is could very w…
I can't see Facebook ever pursuing the criminal angle in this situation. I actually wonder if Alex's boss isn't a little unhappy with his response because it will make people think twice about their bug bounty (just look at the backlash here). The bug bounty was put out there so that people don't use or sell exploits as blackhats.
Re: Instagram's Million Dollar Bug
#524Thank you to everybody who cautioned against judgment before hearing the whole story. Here is my response: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
Re: Instagram's Million Dollar Bug
#525Earlier quoted context omitted.
Facebook's terms say they will not prosecute /report whitehats to law-enforcement. Facebook could prosecute, at the price of some goodwill from the security industry (or part of it). I'm sure a competent lawyer to mount a robust defence for the security researcher (beyond reasonable doubt, IMO).
You're missing my point and talking about something entirely different from what I'm talking about. I'm not talking about whether Facebook will prosecute and what the consequences of that will be (whether they'll win or lose whatever). I'm just pointing out that taking AWS keys is a big deal , because it's legally a big deal.
>If you give us reasonable time to respond to your report before making any information public, and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you.
IANAL: but it could be argued (in court) that he had Facebook's permission to getting the AWS keys. In his opinion (and mine) he made good faith efforts to avoid privacy violations.
Facebook's official disclosure policy has legal weight. There is legal concept (whose name is escaping me) that could apply that in laymen's terms say the official disclosure policy gives him Facebook's tacit approval - I first heard about it in the Oracle v Google where Google argued a blog post congratulating Google provided tacit approval.
Re: Instagram's Million Dollar Bug
#526Earlier quoted context omitted.
The problems I have with your absolute statement: * You are stating that all (not some) experienced security folks are agreeing unanimously. The implication is that those show disagree are not "experienced security guys" (as you called them: "everyone else") - they are the ones who aren't true scotsman * you assume those who don't explicitly indicate that they work in infosec industry do not work in the infosec indus…
I wasn't the one who made the comment you're referring to. I'm just saying there is no evidence of a "no true Scotsman" here, as far as I can tell.
Re: Instagram's Million Dollar Bug
#527Re: Instagram's Million Dollar Bug
#528Earlier quoted context omitted.
The policy reads clear enough to me to warrant a huge reward. Adding additional conditions after the fact is dealing in bad faith.
most RCE bugs can be compounded into major data dumps. That doesn't make each individual RCE a million dollar bug.
Re: Instagram's Million Dollar Bug
#529Earlier quoted context omitted.
Guy discloses vulnerability. Facebook is not as impressed as guy would have hoped. Maybe it's because he's one of several people to disclose the same vulnerability. Maybe there are just a lot of vulnerabilities (they've paid out 4.3m in bounties). Guy's reaction to rejection: take hostages and threaten Facebook. Facebook moves to defense and cuts guy off. You are not a good neighbor for kidnapping someone's family to…
This is, of course, Facebook's narrative which conflict's with Wes's. One obvious hole I can see in Facebook's story is that they insinuate that Wes broke back into the server after they disputed the bounty. If this were true, they did nothing in response to the problems Wes found for over a month. If you look at Wes's timeline, he says access to the server was no longer possible a few days after he filed the second…
Re: Instagram's Million Dollar Bug
#530Earlier quoted context omitted.
You're missing my point and talking about something entirely different from what I'm talking about. I'm not talking about whether Facebook will prosecute and what the consequences of that will be (whether they'll win or lose whatever). I'm just pointing out that taking AWS keys is a big deal , because it's legally a big deal.
Facebook's disclosure policy reads: >If you give us reasonable time to respond to your report before making any information public, and make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you. IANAL: but it could be argued (in court) that he had Fa…