Live data from Hacker News

"White hat" Facebook hacker gets 8 months in jail

bbc.co.uk

81–90 of 120 posts

Re: "White hat" Facebook hacker gets 8 months in jail

#81

"You accessed the very heart of the system of an international business of massive size, so this was not just fiddling about in the business records of some tiny business of no great importance," he said. This is the kind of thing that makes my blood boil.

While "importance" is a pretty subjective (read: bullshit) metric in legal terms, using the dollar value of theft to threshold criminal charges is used around the world. In the U.S. you can press charges for any amount, but depending on the state they have different thresholds between misdemeanor and a felony (grand theft) usually around $500-$1000. Interestingly enough, in some places such as China (where I original…

But that's not what the quote implies at all, at least taken in the context of the article. Instead, it implies that the only reason he is being punished is, not because of the hack, but because he hacked facebook. It implies that, had he done the same on some "tiny business of no great importance" it wouldn't have been such a big deal.

Re: "White hat" Facebook hacker gets 8 months in jail

#82
post #51

Earlier quoted context omitted.

I don't think China does a more prudent job of enforcing responsibility. Rather China occasionally makes an example of the most blatant cases of corruption.

You might be right, but the net effect is that it encourages responsibility regardless.

In specific instances the fact that China kills people where the US does little to the individuals involved feels good. However, the US approach of mostly free press coupled with regular and independent policing of government contracts, coupled with class action lawsuits changes the landscape significantly. In the end you might argue that corruption is endemic of both systems, yet that's the case for any large scale government thought out history.

What the US does well is simply keep things public enough that everyone tries to at-least appear to follow the rules. And if you ever tried to do significant business in China as apposed to a Chinese company you will quickly understand that that in and of it's self is huge.

Re: "White hat" Facebook hacker gets 8 months in jail

#83
post #65

I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid priv…

"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you."

You think you can sue someone for sharing vulnerability information?

Re: "White hat" Facebook hacker gets 8 months in jail

#84
post #65

I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid priv…

"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you." You think you can sue someone for sharing vulnerability information?

Unfortunately, much of the internet industry has an established history of doing just that. This heavy-handed approach to vulnerability disclosure has led to an atmosphere of distrust and is bad for everyone. Facebook's policy is intended to alleviate much of the tension involved with vulnerability disclosure.

If you're curious, the EFF has published a number of great articles on the topic:

https://www.eff.org/issues/coders/vulnerability-reporting-fa...

https://www.eff.org/deeplinks/2010/12/knowledge-power-facebo...

Re: "White hat" Facebook hacker gets 8 months in jail

#85
post #74

Earlier quoted context omitted.

Upvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to y…

Correct me if I'm wrong, but I believe you are not supposed to fish for anything after you are pulled over. Just keep your hands on the wheel. If the officer sees you leaning over trying to find something after you're pulled over he/she could see that as suspicious behavior.

Just to reiterate, it really hurts to see so many people saying "have your ID ready". From the very moment an officer pulls you over they will be anxiously watching your every move, hoping you're not the next one that attempts to pull a gun on them.

Reaching for anything when pulled over is the absolute worst thing you can do to an officer no matter how innocuous you may think you seem.

Please, just keep your hands on the wheel until they're at the window.

Re: "White hat" Facebook hacker gets 8 months in jail

#86
post #26

Earlier quoted context omitted.

Upvoted. Never, ever, talk to the cops.

Upvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to y…

"I've talked my way out of around 9 out of 12 speeding fines"

Wow you must be really good at that. In all my life I never managed to talk myself out of a ticket once I was stopped by the police.

Re: "White hat" Facebook hacker gets 8 months in jail

#87
post #84

Earlier quoted context omitted.

"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you." You think you can sue someone for sharing vulnerability information?

Unfortunately, much of the internet industry has an established history of doing just that. This heavy-handed approach to vulnerability disclosure has led to an atmosphere of distrust and is bad for everyone. Facebook's policy is intended to alleviate much of the tension involved with vulnerability disclosure. If you're curious, the EFF has published a number of great articles on the topic: https://www.eff.org/issues…

I think you are confused. I've been in the security industry for about 10 years. Disclosing a vulnerability is not illegal. Over the years, some companies have tried to sue over this, but these censorship attempts do not turn out well.

Not only is it legal to disclose unfixed vulnerabilities, but it is legal to sell them. Presently, the biggest buyer of them is none other than the US government.

Re: "White hat" Facebook hacker gets 8 months in jail

#88

Earlier quoted context omitted.

Upvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to y…

"I've talked my way out of around 9 out of 12 speeding fines" Wow you must be really good at that. In all my life I never managed to talk myself out of a ticket once I was stopped by the police.

I've avoided 9 out of the past 10 with a simple strategy of pulling over as soon as I feel like a cop might be following be (ideally before the lights come on), turning the dome light on in my car, rolling down the window, putting my hands on the wheels and admitting that I "assume" the cop was going to pull me over "because I was probably speeding".

This is not your best strategy if:

(a) You are driving on a suspended license

(b) You or anyone in your car have anything in the car to hide

(c) You have a radar detector (just give up)

I bring this up because, for me at least, there's no skill involved in "talking my way out of a ticket". There's no magic words, and it doesn't involve charm, just a little mindfulness.

Re: "White hat" Facebook hacker gets 8 months in jail

#89
post #26

Earlier quoted context omitted.

Upvoted. Never, ever, talk to the cops.

That's advice if taken literally is horrible. Never talk to the cops if accused of a SERIOUS crime, always get some sort of legal council. If however you get pulled over for running a stop sign or some other traffic violation/small offense and you know the cop saw you, don't insult their intelligence. Judge the situation I've gotten out of every traffic ticket by being polite and honest. I'll usually try and apologiz…

If it's possible you may be on the hook for something more serious than a traffic ticket, clam up; your implied admission of having done anything in traffic can harm you.

Re: "White hat" Facebook hacker gets 8 months in jail

#90
post #84

Earlier quoted context omitted.

Unfortunately, much of the internet industry has an established history of doing just that. This heavy-handed approach to vulnerability disclosure has led to an atmosphere of distrust and is bad for everyone. Facebook's policy is intended to alleviate much of the tension involved with vulnerability disclosure. If you're curious, the EFF has published a number of great articles on the topic: https://www.eff.org/issues…

I think you are confused. I've been in the security industry for about 10 years. Disclosing a vulnerability is not illegal. Over the years, some companies have tried to sue over this, but these censorship attempts do not turn out well. Not only is it legal to disclose unfixed vulnerabilities, but it is legal to sell them. Presently, the biggest buyer of them is none other than the US government.

Whoah. Whoah. Whoah. You're handwaving around the real issue. It's not legal to find vulnerabilities by testing other people's running web applications without permission, and it never has been.

People obviously do it, all the time, against sites that haven't officially given permission (as Google and Facebook have), and most of the time they get away with it, but they are rolling the legal dice every time they do. People have been getting in trouble for doing this for years.

The people selling vulnerabilities are generally running the software themselves. Huge difference.

Post reply on HN