Earlier quoted context omitted.
Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really…
Publicly releasing a vulnerability is not a crime, even if FB would prefer I didn't.
I Hacked into Facebook's Legal Department Admin Panel
291–300 of 301 posts
Re: I Hacked into Facebook's Legal Department Admin Panel
#292Earlier quoted context omitted.
That’s why you would need an agent. Yes Facebook will brush it off if a random hacker anonymously contacts them, but if they’re approached by serious man in a suit with experience in the field, they’ll take it seriously, and, if not, you hire a social media expert to kick up a big fuss
No, they won't. They won't even talk to the weirdo in the suit. The magical powers of suits are much overstated and, in the last 20 years, greatly diminished.
Re: I Hacked into Facebook's Legal Department Admin Panel
#293Earlier quoted context omitted.
We have lots of that already, but it's more "protect the rich" than "protect our IT workers"
I hate to break it to you but the people saying things like "eat the rich" lump Bezos/Zuckerberg and the programmers/IT folks working for them into roughly the same bucket.
Re: I Hacked into Facebook's Legal Department Admin Panel
#294Earlier quoted context omitted.
You can demand whatever you want. You have no leverage. You can't sell the bug to anyone else (there's no semi-anonymous liquid market for random serverside bugs in line-of-business software, so you're going to end up culpable for whatever the rando who buys it --- for much less than $7000 --- does with it†). You can disclose to Twitter, but you can do that anyways; all you're doing is foregoing the bounty. You can t…
Why don't state actors that are explicitly aligned against the USA have public bug buying programs? Like a Russian website where you can go and submit your bug and get $250K.
Re: I Hacked into Facebook's Legal Department Admin Panel
#295Re: I Hacked into Facebook's Legal Department Admin Panel
#296How on Earth did this endpoint pass code review at Facebook? The person who wrote it probably was working under the assumption that the calling user was logged in, but still....
You have an unrealistically high expectation of code review.
But it seems that this was third-party code, which I guess explains it.
Re: I Hacked into Facebook's Legal Department Admin Panel
#297Earlier quoted context omitted.
Negotiating is above-board in its own right, which means you've got the right to say, "No, that price is too low," and walk away from the exchange. But, in a broad sense, I'd argue it becomes an issue when you say, "If you don't pay me, I'm going to facilitate crime with this data (or at least make it easy for others to do so)!" Because it's contemptuous of the law—not to mention it's a power dynamic that can really…
Publicly releasing a vulnerability is not a crime, even if FB would prefer I didn't.
Re: I Hacked into Facebook's Legal Department Admin Panel
#298Earlier quoted context omitted.
I hate to break it to you but the people saying things like "eat the rich" lump Bezos/Zuckerberg and the programmers/IT folks working for them into roughly the same bucket.
Who said to eat anyone?
Re: I Hacked into Facebook's Legal Department Admin Panel
#299Earlier quoted context omitted.
But there are people who generally research vulnerabilities in academia and your “term of art” doesn’t really apply there. Point being - “vulnerability researcher” means one thing talking to a PhD student at CMU vs talking to someone in the industry.
No, Ph.D students doing vuln research understand that they are researchers in two different senses. Talk to some of them. They're not confused about this.
The fact that you are saying “they are researchers in two different senses” means you already know the overlap of terminology and it requires context to disambiguate, which is my entire fucking point. The “vulnerability research” that people hunting for bug bounties are doing is not “vulnerability research” in the academic sense.
Re: I Hacked into Facebook's Legal Department Admin Panel
#300Earlier quoted context omitted.
No, Ph.D students doing vuln research understand that they are researchers in two different senses. Talk to some of them. They're not confused about this.
I’ve worked in sec academia and, if they don’t know they are interacting with someone from industry, using the term “vulnerability research” absolutely does not mean what you’re talking about. The fact that you are saying “they are researchers in two different senses” means you already know the overlap of terminology and it requires context to disambiguate, which is my entire fucking point. The “vulnerability researc…
I'm honestly a little lost about what the dispute even is here. Obviously, the term "vulnerability research" is old, and means pretty much what I said it meant in the previous paragraph. What's the confusion? It sounds almost as if you're trying to say "vulnerability research" means "academic security research". Obviously, it does not. Are you just trying to say it should mean that?