Live data from Hacker News

"White hat" Facebook hacker gets 8 months in jail

bbc.co.uk

61–70 of 120 posts

Re: "White hat" Facebook hacker gets 8 months in jail

#61
post #48

If facebook was involved in helping prosecute this guy, sounds like they were, makes me want to boycott facebook. I only get online once every 2-3 days, but this is too much.

Why so?

If someone breaks into a company's system, surely the company has a very real obligation to help prosecute the law-breaker? While I can see where there's an argument to made in favour of not prosecuting someone who really is a white-hat hacker (although I'm personally loathe to apply that label to anyone who doesn't have a track record of responsible security research and pen testing as opposed to J. Random Hacker who happens to tell the company after the fact), this guy pretty clearly doesn't fall into that category.

While the article was light on the details (being as it was that it was about the sentencing rather than the crime), it does seem as though he both copied some of Facebook's source code or other internal data (as it mentions it being copied to an external hard drive), and it does not seem as though he reported the hole to Facebook along with any details of how he penetrated their system.

Given that, why should Facebook not help to prosecute him?

Re: "White hat" Facebook hacker gets 8 months in jail

#62
post #41

https://www.facebook.com/whitehat Facebook themselves have a policy of tolerance toward white hat hackery (basically `give us a reasonable amount of time before releasing to the public' and `do what you can to protect other users' privacy). I want to hear their side of this.

The title of this submission is completely inaccurate: the person in question is in no way a "white hat": http://www.guardian.co.uk/technology/2011/aug/17/facebook-ha... > Between 17 April and 9 May he is accused of downloading a computer program "to secure unauthorised access" to Facebook; of attempting to hack into Facebook's "Mailman" server; of using PHP script to secure access to another Facebook server, dubbed…

This is deeply disturbing to me. I'm a participant in Facebook's whitehat program (http://facebook.com/whitehat) and have been awarded a cash prize several times. These accusations are things that I've either done, attempted to do, or succeeded in doing myself with the goal of getting paid for discovering a vulnerability.

>> downloading a computer program "to secure unauthorised access" to Facebook

Any basic security auditing tool falls into this category and this is something I've done all the time. Wish they would more clearly state what made his access unauthorized when my hacking attempts are welcomed.

>> attempting to hack into Facebook's "Mailman" server

I've attempted this too. It's a great target since it's 3rd party code, Facebook runs an out of date version, and some versions have publicly known vulnerabilities.

>> using PHP script to secure access to another Facebook server, dubbed "Phabricator"

I've attempted to do this and just yesterday was considering another attempt. It's a great target since it doesn't go through Facebook's normal release process, it's a large project, and it's open source.

>> sharing a PHP script intended to hack into that Facebook server

I've done this. Sometimes I need another set of experienced eyes to help me get a proof of concept working. Of course it was someone I trusted to keep my discovery confidential.

>> securing "repeated" access to another Facebook server.

I've done this too, both before and after Facebook announced their whitehat program. Before the program they thanked me and sent me swag, after introducing the whitehat program they started awarding me cash on prepaid debit cards.

I can only assume that this guy was prosecuted instead of thanked because he didn't tell Facebook promptly about his discoveries, or perhaps he used them to do something like stealing source code out of Phabricator (Facebook's code review tool). I wish the reporting of this did a better job of covering the details.

Re: "White hat" Facebook hacker gets 8 months in jail

#63
post #22

> "He added that when Mangham was arrested he made "copious" admissions to police about what he had done." Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything , no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney. Of course the classic video needs to be linke…

Have you ever submitted this as a post? I don't want to steal your submission, and I think this deserves to see the front page.

Re: "White hat" Facebook hacker gets 8 months in jail

#64
post #26

Earlier quoted context omitted.

Upvoted. Never, ever, talk to the cops.

Upvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to y…

This is very true. The main difference is that these are not criminal charges - unlike what the professor says in the video, this is something the officer can and and often will let you get away with if you evoke enough empathy.

The important thing to keep in mind of course is that with a speeding ticket, at worse you'll have to pay a few bucks for something you maybe even didn't do. This is as opposed to spending a few years in jail for a crime you did not commit...

Re: "White hat" Facebook hacker gets 8 months in jail

#65
I manage Facebook's Whitehat program (https://www.facebook.com/whitehat). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly:

"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you."

His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.

Re: "White hat" Facebook hacker gets 8 months in jail

#66
post #62
post #41

Earlier quoted context omitted.

The title of this submission is completely inaccurate: the person in question is in no way a "white hat": http://www.guardian.co.uk/technology/2011/aug/17/facebook-ha... > Between 17 April and 9 May he is accused of downloading a computer program "to secure unauthorised access" to Facebook; of attempting to hack into Facebook's "Mailman" server; of using PHP script to secure access to another Facebook server, dubbed…

This is deeply disturbing to me. I'm a participant in Facebook's whitehat program ( http://facebook.com/whitehat ) and have been awarded a cash prize several times. These accusations are things that I've either done, attempted to do, or succeeded in doing myself with the goal of getting paid for discovering a vulnerability. >> downloading a computer program "to secure unauthorised access" to Facebook Any basic securi…

I've participated in the program as well (and I'm going to be interning with Facebook's Security team this summer). This incident doesn't worry me personally and I hope it doesn't worry anybody else. But if you want clarity, I think arice's comment sums up this particular situation very well:

http://news.ycombinator.com/item?id=3605343

> His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.

Re: "White hat" Facebook hacker gets 8 months in jail

#67
post #65

I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid priv…

  ...insulting to the community of responsible security researchers
Bravo.

Re: "White hat" Facebook hacker gets 8 months in jail

#68

What it sounds like from the article isn't that he destroyed $200,000 worth of property; it's that $200k is what it cost Facebook to fix a security hole he discovered. Meaning it was money they needed to spend on security before someone with truly malicious intentions found it. Does Facebook seriously think that sending kids to jail is a viable substitute for building good security into their product, or that it will…

In general, the time to fix an identified security hole is dwarfed by the time to investigate a breech.

You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind.

If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth.

In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done.

(I work at Facebook, but not in one of the teams involved in this investigation.)

Re: "White hat" Facebook hacker gets 8 months in jail

#69
post #66
post #62

Earlier quoted context omitted.

This is deeply disturbing to me. I'm a participant in Facebook's whitehat program ( http://facebook.com/whitehat ) and have been awarded a cash prize several times. These accusations are things that I've either done, attempted to do, or succeeded in doing myself with the goal of getting paid for discovering a vulnerability. >> downloading a computer program "to secure unauthorised access" to Facebook Any basic securi…

I've participated in the program as well (and I'm going to be interning with Facebook's Security team this summer). This incident doesn't worry me personally and I hope it doesn't worry anybody else. But if you want clarity, I think arice's comment sums up this particular situation very well: http://news.ycombinator.com/item?id=3605343 > His attempt to access data was outside our whitehat guidelines, had clear malici…

Ah, that certainly clarifies it. Thanks!

Re: "White hat" Facebook hacker gets 8 months in jail

#70
post #65

I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid priv…

His attempt to access data...

How much data did he access?

Post reply on HN