I've always wondered, aren't these types of bug investigations illegal? Aren't the investigators concerned about criminal prosecution? Not being snarky; I'm asking sincerely.
In general you are on shaky legal ground. However, some companies (including Facebook) have a bug bounty program that provides a prescribed safe harbor that you can operate within to discover vulnerabilities within their products or infrastructure in exchange for some kind of recognition or award. The terms of Facebooks bounty are here: https://www.facebook.com/whitehat Based on a cursory glance and the fact that thi…
If you are genuinely trying to find exploits in good faith, and are acting within the parameters spelled out in their bug bounty program, it’s all good. You also may get paid.
This blog entry sort of dramatized what happened for clicks. I actually think it’s unwise to characterize any exploit like this, because it adds a PR dimension consumer companies just don’t want or need.
It sort of creates a sense of adversarial relationship which isn’t really what FB is after.
But it sounds like a risky endeavor put this way and probably helps get retweets attention in the short term.