Live data from Hacker News

Facebook security hole allows viewing of private photos

forum.bodybuilding.com

111–120 of 143 posts

Re: Facebook security hole allows viewing of private photos

#111
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

Knowing about your special page for reporting privacy holes would not change my decision to post it here. I think more good will come when media picks it up and some Facebook users realize that a company with your record of terrible privacy decisions and incompetence should not be used for posting anything private or even at all. If you were a startup stretched for resources or if this hole could've been exploited to install malware, I'd of course attempt to contact you first. $500 for reporting security holes for a company of your size is also insulting, BTW.

Re: Facebook security hole allows viewing of private photos

#112
post #46

This is a security hole and nothing more. Developers make mistakes. This is not some vast conspiracy by Facebook to undermine your privacy. Why, of all places, is HackerNews unable to comprehend this?

Is Facebook not hiring some of the most talented developers in the industry? This is a ridiculous mistake that should have been tested for prior to production.

No. I went to school with someone who now works at Facebook. To describe him as "most talented" at anything would be a mistake. However, he did have no regard for others or their work.

Re: Facebook security hole allows viewing of private photos

#113
post #107
post #93

Earlier quoted context omitted.

Yep it is, the drink of choice for people who don't want a particularly cheap bottle and pay for label not taste.

Sorry, that's utter bullshit. Blue Label is a perfectly delicious scotch.

It kind of is the Bose Audio of scotch; you can get much better for the price, regardless of how delicious it is.

(I'm pretty much done with scotch these days, though --- tastes like burnt trees --- so I'd defer to strong disagreement).

Re: Facebook security hole allows viewing of private photos

#114
post #105
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

It is great that you have a page specifically for reporting security issues. For some companies I had to resort to reporting security issues to the main contact address where it landed at some first-level support guy's desk who had no idea what to do and in the end I gave up and the security hole stayed open. One thing though: Your bounty of $500 is quite low. I bet this whole incident did/does a lot more damage than…

Glad you like it! $500 is actually just the base bounty - I've seen payouts for quite a bit more depending on how nasty the bug is.

At least for me personally, it's not the posting of one person's private photos that is most frustrating - it's public posting of repro instructions so that script kiddies can exploit a bug. That just seems irresponsible.

Re: Facebook security hole allows viewing of private photos

#115
post #109
post #107

Earlier quoted context omitted.

Sorry, that's utter bullshit. Blue Label is a perfectly delicious scotch.

It's not nasty but it's a drink that's blended to taste reasonably bland, designed for drinking alcohol not designed for enjoying the taste. Its target market is people who don't want anything particularly interesting. Don't get me wrong, it's much nicer than a £20 bottle of blended stuff, but nowhere near good enough to justify the price tag, and is the huge majority of scotch drinkers (at least a huge majority of t…

What's the blended scotch you prefer to Johnnie Walker? I tried to avoid the trap of saying "yeah but you can get Springbank for half the price".

Re: Facebook security hole allows viewing of private photos

#116
post #109

Earlier quoted context omitted.

It's not nasty but it's a drink that's blended to taste reasonably bland, designed for drinking alcohol not designed for enjoying the taste. Its target market is people who don't want anything particularly interesting. Don't get me wrong, it's much nicer than a £20 bottle of blended stuff, but nowhere near good enough to justify the price tag, and is the huge majority of scotch drinkers (at least a huge majority of t…

What's the blended scotch you prefer to Johnnie Walker? I tried to avoid the trap of saying "yeah but you can get Springbank for half the price".

Personally I would always chose a single malt, and as such I'm not an expert in blends. That said, plenty of people tell me that blends can be pretty good, so I try not to judge them too much - although truthfully I do think of them worse objectively as well. A great blend might be better than a poor scotch, but I think the worse and best of blends are lower than the worst and best of scotches.

Re: Facebook security hole allows viewing of private photos

#117
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

Knowing about your special page for reporting privacy holes would not change my decision to post it here. I think more good will come when media picks it up and some Facebook users realize that a company with your record of terrible privacy decisions and incompetence should not be used for posting anything private or even at all. If you were a startup stretched for resources or if this hole could've been exploited to…

The idea with responsible disclosure is that you want to maximize safety of the public by incentivizing vendors to fix problems while not letting malicious actors exploit them: http://en.wikipedia.org/wiki/Responsible_disclosure. Once the vendor has fixed the flaw (or refused to, or taken longer than a reasonable time to do so), it's generally accepted as OK to publish details. You can of course get whatever media coverage you want at that point.

I'm curious - do you think responsible disclosure is a bad idea? Or is the "badness" of this bug small enough (compared to malware) that you think it's better for the common good to publicly post the repro instructions and enable many users to exploit it?

I think having a bug bounty program is actually a lot better than the vast majority of sites / vendors that don't even have a whitehat disclosure program, let alone a bug bounty program. It's worth noting that this is just the base bounty - I've seen us pay out a lot more for good discoveries. $500 is also the base that Google and Mozilla offer for their programs (http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w..., http://www.mozilla.org/security/bug-bounty.html). What would be a good price, do you think? I'm not hooked in enough to know what black market prices are like for bugs like this.

Re: Facebook security hole allows viewing of private photos

#118
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

Knowing about your special page for reporting privacy holes would not change my decision to post it here. I think more good will come when media picks it up and some Facebook users realize that a company with your record of terrible privacy decisions and incompetence should not be used for posting anything private or even at all. If you were a startup stretched for resources or if this hole could've been exploited to…

Ah, just realized you're the OP. I don't think there's anything particularly irresponsible about posting an already-public disclosure to HN or other aggregators. It's the first person posting it publicly without first privately disclosing that I find irresponsible.

Re: Facebook security hole allows viewing of private photos

#119

Earlier quoted context omitted.

Maybe that was true in the past, but today when you delete your data it is gone. Trust me, I wrote it myself. The law enforcement guidelines that have been circulating recently corroborate this.

Is this true for all data - account details and whatnot? I deleted (not deactivated) my account a few months ago and just assumed everything would remain somewhere in FB's system.

Delete generally means gone forever. If you wanted your account gone (but not permanently) you should use the deactivate option.

Re: Facebook security hole allows viewing of private photos

#120
post #108
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

If people submit via that whitehat feature, do you publisize "XY was possible until 20XX-XX-XX"? I consider that important information.

I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat). Of course, once we've fixed the bug, the reporter is free to write about the exploit, how long it was live, etc.
Post reply on HN