Live data from Hacker News

"White hat" Facebook hacker gets 8 months in jail

bbc.co.uk

71–80 of 120 posts

Re: "White hat" Facebook hacker gets 8 months in jail

#71
post #51

Earlier quoted context omitted.

While "importance" is a pretty subjective (read: bullshit) metric in legal terms, using the dollar value of theft to threshold criminal charges is used around the world. In the U.S. you can press charges for any amount, but depending on the state they have different thresholds between misdemeanor and a felony (grand theft) usually around $500-$1000. Interestingly enough, in some places such as China (where I original…

I don't think China does a more prudent job of enforcing responsibility. Rather China occasionally makes an example of the most blatant cases of corruption.

You might be right, but the net effect is that it encourages responsibility regardless.

Re: "White hat" Facebook hacker gets 8 months in jail

#72
post #63
post #22

> "He added that when Mangham was arrested he made "copious" admissions to police about what he had done." Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything , no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney. Of course the classic video needs to be linke…

Have you ever submitted this as a post? I don't want to steal your submission, and I think this deserves to see the front page.

Submit away.

Re: "White hat" Facebook hacker gets 8 months in jail

#73
post #22

> "He added that when Mangham was arrested he made "copious" admissions to police about what he had done." Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything , no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney. Of course the classic video needs to be linke…

There is an article written in the latest 2600 on exactly what to do if the cops bust down your door one day, from beginning to end.

When you are first arrested, you should plead the fifth (or the British equivalent thereof), and ask to see a lawyer.

Re: "White hat" Facebook hacker gets 8 months in jail

#74
post #26

Earlier quoted context omitted.

Upvoted. Never, ever, talk to the cops.

Upvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to y…

Correct me if I'm wrong, but I believe you are not supposed to fish for anything after you are pulled over. Just keep your hands on the wheel. If the officer sees you leaning over trying to find something after you're pulled over he/she could see that as suspicious behavior.

Re: "White hat" Facebook hacker gets 8 months in jail

#75
post #26
post #22

> "He added that when Mangham was arrested he made "copious" admissions to police about what he had done." Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything , no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney. Of course the classic video needs to be linke…

Upvoted. Never, ever, talk to the cops.

That's advice if taken literally is horrible. Never talk to the cops if accused of a SERIOUS crime, always get some sort of legal council. If however you get pulled over for running a stop sign or some other traffic violation/small offense and you know the cop saw you, don't insult their intelligence. Judge the situation I've gotten out of every traffic ticket by being polite and honest. I'll usually try and apologize as soon as the cop walks over "i'm sorry officer i don't know what i was thinking going that fast" i've caught cops off guard saying stuff like that, they will usually reply "uh so you know why i pulled you over" a simple "yes" and an ashamed look will work wonders. Also use your judgment, if the weather is bad always have your license and paperwork ready before the cop walks over, "I know you're just doing your job i didnt wanna make you wait in the rain" has gotten me out of a few speeding tickets too. ;)

As stated above though, if you're accused of something serious just keep your mouth shut.

Re: "White hat" Facebook hacker gets 8 months in jail

#76
post #70
post #65

I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid priv…

His attempt to access data... How much data did he access?

I don't know the specific amount of data (as a percentage or bytes) accessed, but I think there are two main reasons you might want to know:

If you're wondering whether it affected the privacy of data created by people who use Facebook, the referenced article has a statement that it was not, but it appears this was added after the article was published, so you may have missed it.

If you're wondering whether it might be a small amount that a security researcher might collect to verify their report, from what I understand it was more than that.

Re: "White hat" Facebook hacker gets 8 months in jail

#77
post #62
post #41

Earlier quoted context omitted.

The title of this submission is completely inaccurate: the person in question is in no way a "white hat": http://www.guardian.co.uk/technology/2011/aug/17/facebook-ha... > Between 17 April and 9 May he is accused of downloading a computer program "to secure unauthorised access" to Facebook; of attempting to hack into Facebook's "Mailman" server; of using PHP script to secure access to another Facebook server, dubbed…

This is deeply disturbing to me. I'm a participant in Facebook's whitehat program ( http://facebook.com/whitehat ) and have been awarded a cash prize several times. These accusations are things that I've either done, attempted to do, or succeeded in doing myself with the goal of getting paid for discovering a vulnerability. >> downloading a computer program "to secure unauthorised access" to Facebook Any basic securi…

Did you consider if you should have shared this admission of what probably amounts to criminal activity in USA?

The FB "whitehat" pages to my reading are in no way giving you a right to "security test" their servers. Their statement appears more like an amnesty, akin to "if you did happen to shoplift from Walmart and you choose to return the goods unspoilt, packaged and in saleable condition, then we won't prosecute you".

They also say, FWIW, that "Security bugs in third-party applications" are not included in the program; so that would rule out attempting to compromise Mailman.

Moreover they say "Security bugs in Facebook's corporate infrastructure" are ruled out from their program which to my mind rules out compromises on Phabricator - it's not a part of the publicly facing Facebook site but instead is a backend tool.

knock knock

If you were in the UK you'd be getting an extradition order for this based on recent history.

Re: "White hat" Facebook hacker gets 8 months in jail

#78
post #31
post #18

Earlier quoted context omitted.

While it is indeed despicable to imagine that there's a different law for big and small companies, it is long known that the size of actual and potential harm is considered when crime and punishment is being discussed. One would probably get different punishment for stealing $10 and stealing $100K (though if you manage to steal $100M you may actually get away with it, but that's another story). If his lawyer would ar…

You do realize there are people in jail in California for life for stealing very small amounts, due to the "3 strikes law", where as the people responsible for sucking billions out of the US economy... well, none of them have gone to jail. (I did read about someone that did go to jail, but he was a low-level actor... it was clear it was a sacrificial lamb).

Even sacrificing lambs is useful - with time, the bigger fish will find very hard to get enough sacrificial lambs and the lambs themselves may start demanding larger rewards for their sacrifice.

Wondering if lamb fat is good to fry large fish.

Re: "White hat" Facebook hacker gets 8 months in jail

#79

https://www.facebook.com/whitehat Facebook themselves have a policy of tolerance toward white hat hackery (basically `give us a reasonable amount of time before releasing to the public' and `do what you can to protect other users' privacy). I want to hear their side of this.

> I want to hear their side of this.

Scroll up a bit and check arice's post:

https://news.ycombinator.com/item?id=3605343

Re: "White hat" Facebook hacker gets 8 months in jail

#80
post #62

Earlier quoted context omitted.

This is deeply disturbing to me. I'm a participant in Facebook's whitehat program ( http://facebook.com/whitehat ) and have been awarded a cash prize several times. These accusations are things that I've either done, attempted to do, or succeeded in doing myself with the goal of getting paid for discovering a vulnerability. >> downloading a computer program "to secure unauthorised access" to Facebook Any basic securi…

Did you consider if you should have shared this admission of what probably amounts to criminal activity in USA? The FB "whitehat" pages to my reading are in no way giving you a right to "security test" their servers. Their statement appears more like an amnesty, akin to "if you did happen to shoplift from Walmart and you choose to return the goods unspoilt, packaged and in saleable condition, then we won't prosecute…

Facebook's Responsible Disclosure Policy applies to all Facebook properties. The exceptions you outlined specifically apply to our bounty program. Basically, we may not pay a cash reward for a security issue reported in Mailman (an open source tool), but we still appreciate the responsible disclosure and you absolutely shouldn't be worried about a lawsuit.
Post reply on HN