Earlier quoted context omitted.
Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn…
That's why I: - Stopped reporting anything that is not an issue in the source code of an open source project. I do so in their mailing lists or issue tracker. - Began to treat random internet bug reports with kindness and gratitude.
Facebook rewarded a 10-year-old for finding Instagram security flaw
81–90 of 90 posts
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#82It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
I don't think it's that simple of a decision, or one that could be generalised to all cases. What if you found an exploit that let you break a widespread form of DRM, access normally paywalled information, or gain control of a device that you rightfully own but the manufacturer locked down against you? It really depends on your moral/philosophical stance, but all the money in the world wouldn't make me report any of…
http://pastebin.com/raw/0SNSvyjJ
"Leaking documents, expropriating money from banks, and working to secure the computers of ordinary people is ethical hacking. However, most people that call themselves "ethical hackers" just work to secure those who pay their high consulting fees, who are often those most deserving to be hacked."
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#83Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#84Earlier quoted context omitted.
Previous commenters on HN have thought differently https://news.ycombinator.com/item?id=10795785 ;)
It is the same commentator. It appears in this most recent comment he neglected to add a sarcasm indicator.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#85Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I'm presuming without verifiable parental consent prior to use - to use their services? Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?
In this case, seeing as COPPA is a US law and the kid in question is from Finland (and thus likely under Facebook's EU subsidiary), I'm guessing not.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#86The bug is worth $100.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#87Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#88It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
Off topic, but I once found a Magento SQL database backup from going to a robots.txt page for a company that I will not name. I told them how I was able to get to this file and laid out the other vulnerabilities with their site set up. I had access to all of their customer emails, all of their admin logins, encrypted passwords, and salts. Was able to find git credentials and a whole swathe of information that shouldn…
Fortify on pronq is their SAAS application security scanner for those who were wondering.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#89$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to Static site content Source code SSL key pairs iOS and Android app signing keys iOS push notification keys Email server credentials Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys http://exfiltrated.com/research-Instagram-RCE.php
Because he broke the rules: https://www.facebook.com/notes/alex-stamos/bug-bounty-ethics...
The point I was trying to make is the market value seems wildly different from what Facebook pays out. The pricing gives me the impression that Facebook's bug bounty program is more concerned with public relations than it is about improving Facebook security.
Re: Facebook rewarded a 10-year-old for finding Instagram security flaw
#90Earlier quoted context omitted.
I'm hoping the bug was a little more complicated than just "we forgot to check." That's a pretty dumb mistake to make...
Do you see how the PS3 security system was thwarted?[1] 1: http://www.engadget.com/2010/12/29/hackers-obtain-ps3-privat...