How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
I Hacked into Facebook's Legal Department Admin Panel
91–100 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#92$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.
Re: I Hacked into Facebook's Legal Department Admin Panel
#93$7500 seems low for this bug. If I were Facebook i would raise it. Why? Cost/benefit analysis tells me I could probably get a lot more for this bug going to some more nefarious actors. $7500 is a drop in the ocean for a company like FB who has a reputation to keep intact.
Re: I Hacked into Facebook's Legal Department Admin Panel
#94How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
Re: I Hacked into Facebook's Legal Department Admin Panel
#95You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…
Re: I Hacked into Facebook's Legal Department Admin Panel
#96You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
Re: I Hacked into Facebook's Legal Department Admin Panel
#97You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
Re: I Hacked into Facebook's Legal Department Admin Panel
#98You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
> I'd demand Facebook pay out $75,000 minimum Wouldn't demanding money be blackmailing? A story from one of my startups: A student reached out to us regarding a security vulnerability on the website, demanding money for it. He refused to say what it was or provide evidence at first, so we couldn't assess it. He said he'd disclose it to others if we didn't. I definitely felt blackmailed. I am not a lawyer but it felt…
Re: I Hacked into Facebook's Legal Department Admin Panel
#99You brilliant guys need to find a way to extract more than $7500 for solutions to problems that less than what, 2%?, of the worlds population can solve. If I were your tech agent I'd demand Facebook pay out $75,000 minimum for this specific problem.
2%? You have an interesting idea of the world's population. Just think about what that means. It means 2 out of 100 people can hack into Facebook's Legal Department Admin Panel. I mean if we are talking "mentally capable to achieve that within a decade if the person does nothing else but strive to that goal"... Perhaps. If we are talking "sit down right now and do it", then it's more like what... 10,000-100,000 peopl…
Re: I Hacked into Facebook's Legal Department Admin Panel
#100How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
You have an unrealistically high expectation of code review.