Live data from Hacker News

I Hacked into Facebook's Legal Department Admin Panel

alaa.blog

1–10 of 301 posts

Re: I Hacked into Facebook's Legal Department Admin Panel

#4
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Facebook allows people hunting for bugs to find them on approved subdomains following their bug bounty policy.

Re: I Hacked into Facebook's Legal Department Admin Panel

#7
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Places with a bug bounty program typically publicly state rules for what they think is ok for a researcher to do, specifically to avoid that problem. Without permission like that, yes, such an investigation can quickly move into legally dangerous areas, and not all companies have gotten the idea that if someone is willing to tell you about a problem you want them on your side, threatening or suing them just means the next time someone finds something you're not told. (of course that's not a free-for-all for researchers, if you start actually poking in private data or hack actual peoples accounts that's a problem)

Re: I Hacked into Facebook's Legal Department Admin Panel

#10
post #3

I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.

Generally companies prefer if you find bugs and disclose them before malicious parties find and exploit them.

Most websites have a “responsible disclosure” policy. If you can’t find this linked on their main page, you can often find it at /security.txt or /.well-known/security.txt

[0]: https://securitytxt.org/

[1]: https://facebook.com/security.txt

Post reply on HN