Live data from Hacker News

Facebook security hole allows viewing of private photos

forum.bodybuilding.com

131–140 of 143 posts

Re: Facebook security hole allows viewing of private photos

#131
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

This was a couple of years back, so maybe the attitude has changed, but... The last time I reported a security problem to Facebook, I got an email warning me about my online activity, telling me that my account might have been hacked, and that my password had been changed as a result. Several weeks later the problem I had been trying to report was still there. I've heard similar experiences from several other people - so even though this guy looks like he was being irresponsible, I personally will no longer report security problems to Facebook because I don't feel like it would get taken seriously, and will probably only inconvenience me further. I'm not sharing this to flame Facebook, I just would honestly like someone on the inside to know this is a problem. I never knew about the whitehat link because all I see on the Help page is targeted towards victims that probably don't know what they're doing.

Re: Facebook security hole allows viewing of private photos

#132
post #98

This was indeed a bug, and shouldn't work any more. We turned off the system that lets you report content through this flow (and thus made this bug's code inaccessible) as soon as we became aware of the issue. In the future, if you find a security / privacy bug on Facebook, feel free to report it via our whitehat program, which will get things looked at more quickly than random blog posts. You can get credit for the…

This was a couple of years back, so maybe the attitude has changed, but... The last time I reported a security problem to Facebook, I got an email warning me about my online activity, telling me that my account might have been hacked, and that my password had been changed as a result. Several weeks later the problem I had been trying to report was still there. I've heard similar experiences from several other people…

Shoot, sorry to hear that. I think our attitude has always been pretty good, but the communications channels a few years ago were just not great or easy to find (it sounds like you were stuck on a "my account was hacked" workflow).

We've improved a lot in the last couple years though - we launched the explicit whitehat program in 2010: http://www.insidefacebook.com/2010/12/22/facebook-security-t... and the bug bounty in July of this year: https://www.facebook.com/security/posts/238039389561434.

Feel free to respond here or let me know if you ever run into similar issues with the whitehat program (hopefully you'll change your mind about no longer reporting security problems!).

Re: Facebook security hole allows viewing of private photos

#133
post #50

Earlier quoted context omitted.

Well, the question is, how far does that go? If I put up photos on a public web server intending them to be private, is that still legal?

It goes as far as is reasonable. The law gets interpreted in a court of law by human beings that make decisions about whether a reasonable person would expect that to be private and the intent of the person that found the images anyway.

Given Facebooks history at accidentally or intentionally making 'private' material quite public, what would a reasonable person expect? A well informed one, anyway.

Re: Facebook security hole allows viewing of private photos

#134
post #130

Earlier quoted context omitted.

response2: Are you kidding? Just a quick note though that if you're opening up the field to whiskey in general , the people who find Johnnie Walker especially drinkable are probably better served by moving to a more drinkable whiskey category in general. Bourbon is as forward as I get these days, and I strongly strongly prefer rye. Either option is bound to be much cheaper than Blue Label, and if you read up on (say)…

I've literally never tried a good Bourbon - just cheap, cheap stuff when out drinking in America, never tried anything that's supposed to be really nice. I used to have the scotch-snob assumption that it must, but I've had enough people whose opinions I value call me an idiot. I will at some point give a few a go, but just haven't got round to it yet.

Bullet bourbon, next time you're around

Re: Facebook security hole allows viewing of private photos

#135

Earlier quoted context omitted.

It kind of is the Bose Audio of scotch; you can get much better for the price, regardless of how delicious it is. (I'm pretty much done with scotch these days, though --- tastes like burnt trees --- so I'd defer to strong disagreement).

> It kind of is the Bose Audio of scotch Does that mean it's the favorite whipping boy of people who like to think of themselves as connoisseurs?

Let's not exaggerate. Charging $300 for the same performance as a $200 or even $150 product is in the same principle as the fashion industry.

Re: Facebook security hole allows viewing of private photos

#136

Earlier quoted context omitted.

This was a couple of years back, so maybe the attitude has changed, but... The last time I reported a security problem to Facebook, I got an email warning me about my online activity, telling me that my account might have been hacked, and that my password had been changed as a result. Several weeks later the problem I had been trying to report was still there. I've heard similar experiences from several other people…

Shoot, sorry to hear that. I think our attitude has always been pretty good, but the communications channels a few years ago were just not great or easy to find (it sounds like you were stuck on a "my account was hacked" workflow). We've improved a lot in the last couple years though - we launched the explicit whitehat program in 2010: http://www.insidefacebook.com/2010/12/22/facebook-security-t... and the bug bounty…

Well like you said, with an explicit whitehat program, I do think that improves things a lot. The main problem was that I didn't know what to do to not come across as the enemy and/or a nuisance. Next time I find a problem - I'll give the whitehat route a shot - so thanks for sharing.

Re: Facebook security hole allows viewing of private photos

#137

Earlier quoted context omitted.

Understandable. I'll check again, a bit later. Thanks again for taking the time to reply.

About 6:20 since deletion, and the images are still accessible at their akamaihd.net addresses. I'll have a look again tomorrow.

We are probably talking days, not hours here. But your underlying photo metadata is already gone.

Re: Facebook security hole allows viewing of private photos

#138
post #124

Earlier quoted context omitted.

So from what I get good blended is more expensive than good pure/single malt? I have never been able to appreciate blended as much as I appreciate pure malt, but my sample is really limited. My favorite so far is Glenlivet 18 years. edit: pure->pure/single

Exact comparison is of course subjective, but I would prefer JW Blue over the cheapest of single malts, but I no-where near 10x as much. And, I would rather buy a £25 of Glenfiddich 12yo (picked because it is available, in my experience, in pretty much every supermarket and bar in the UK), even if the JW Blue was the same price. So, good blended is more expensive than as-good single malt - indeed, it is also more exp…

Green, for example, is considered by many to be nicer than Blue - not just better value, but nicer ignoring price.

I would agree with that. I prefer JW Gold to either, however.

Re: Facebook security hole allows viewing of private photos

#139
post #80
post #36

Earlier quoted context omitted.

No. This shows that Facebook has no robust security model at all. Either they do not have any mandatory access control for private data, or someone approved of circumventing such access control measures for this feature. Both is in my opinion inacceptable for a company holding so much potentially sensitive data.

One example of a hole does not make a bucket into a sieve. For a company of FBs size and personal data contents, I agree, they have a rather scary track record. But saying implies is fallacious, especially when it's also a symptom of through .

Agree. A sieve is generally more useful than a bucket with a hole.

Re: Facebook security hole allows viewing of private photos

#140
post #108

Earlier quoted context omitted.

If people submit via that whitehat feature, do you publisize "XY was possible until 20XX-XX-XX"? I consider that important information.

I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat ). Of course, once we've fixed the bug, the reporter is free to write about the exploit, how long it was live, etc.

I did not mean details about the exploit but details about what the exploit enabled an attacker to do/see.
Post reply on HN