Live data from Hacker News

Facebook rewarded a 10-year-old for finding Instagram security flaw

theverge.com

81–90 of 90 posts

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#81

Earlier quoted context omitted.

Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn…

That's why I: - Stopped reporting anything that is not an issue in the source code of an open source project. I do so in their mailing lists or issue tracker. - Began to treat random internet bug reports with kindness and gratitude.

Thanks for being excellent!

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#82
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

I don't think it's that simple of a decision, or one that could be generalised to all cases. What if you found an exploit that let you break a widespread form of DRM, access normally paywalled information, or gain control of a device that you rightfully own but the manufacturer locked down against you? It really depends on your moral/philosophical stance, but all the money in the world wouldn't make me report any of…

A recent manifesto around that:

http://pastebin.com/raw/0SNSvyjJ

"Leaking documents, expropriating money from banks, and working to secure the computers of ordinary people is ethical hacking. However, most people that call themselves "ethical hackers" just work to secure those who pay their high consulting fees, who are often those most deserving to be hacked."

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#84
post #36
post #18

Earlier quoted context omitted.

Previous commenters on HN have thought differently https://news.ycombinator.com/item?id=10795785 ;)

It is the same commentator. It appears in this most recent comment he neglected to add a sarcasm indicator.

you missed the ;) at the end of my message :D

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#85
post #47

Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services? Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?

In this case, seeing as COPPA is a US law and the kid in question is from Finland (and thus likely under Facebook's EU subsidiary), I'm guessing not.

Anticipating this objection I looked at some COPPA info briefly (I'm in the UK, in not that familiar with USCs) and it suggested that the jurisdiction was based on location of the controlling company or the servers (either being sufficient) and not location of the children accessing the service. That makes sense as otherwise company's could just use offshore servers and bypass the regulation.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#88
post #2

It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.

Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn…

I reported an xss in HP's pronq fortify login screen without getting as much as a thank you.

Fortify on pronq is their SAAS application security scanner for those who were wondering.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#89
post #63

$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to Static site content Source code SSL key pairs iOS and Android app signing keys iOS push notification keys Email server credentials Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys http://exfiltrated.com/research-Instagram-RCE.php

Because he broke the rules: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...

I believe that particular opinion has been discussed to death here before, so I won't address it.

The point I was trying to make is the market value seems wildly different from what Facebook pays out. The pricing gives me the impression that Facebook's bug bounty program is more concerned with public relations than it is about improving Facebook security.

Re: Facebook rewarded a 10-year-old for finding Instagram security flaw

#90

Earlier quoted context omitted.

I'm hoping the bug was a little more complicated than just "we forgot to check." That's a pretty dumb mistake to make...

Do you see how the PS3 security system was thwarted?[1] 1: http://www.engadget.com/2010/12/29/hackers-obtain-ps3-privat...

Yes, dumb mistakes happen often, but that doesn't make them not dumb.
Post reply on HN