Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

21–30 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#23
post #8

In my opinion..I think they should compensate him.They said he violated their terms...Their terms on the whitehat page is not even localised for other Languages. Too Bad.

While the instructions to report bugs on the whitehat page are not localized, the terms Facebook is referring to (https://www.facebook.com/legal/terms) are.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#24
post #8

In my opinion..I think they should compensate him.They said he violated their terms...Their terms on the whitehat page is not even localised for other Languages. Too Bad.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously , never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

Denying bounty to a hacker on some bullshit "Terms of Service" violation excuse defeats the whole purpose of the bounty program.

Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#25

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

That would work great, in a James Bond movie.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#26

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

Uh, no. How many security exploits do you think would impact Facebook's stock? This one? Investors do not care about minor bugs that are fixed quickly.

This bug is a spammers paradise though, free advertising by posting on other people walls about products. Gold

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#27

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

Uh, no. How many security exploits do you think would impact Facebook's stock? This one? Investors do not care about minor bugs that are fixed quickly.

Simultaneously use the exploit on many investors' FB pages, perhaps starting with their children and families. Nobody cares about an exploit used on Zuck's wall and fixed soon after, but the perception would change if it was more personal and widespread.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#28
post #15

Earlier quoted context omitted.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously , never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

He also gave no technical information at all. He gave more info on his education than the bug he found.

It's a cultural thing. This should signal most likely some form of competency and credibility upfront.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#29

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

No, not really. You need to risk a lot of capital to make any money at all.

For instance, to make even $10,000 on a 5% drop in Facebook stock, you would need to sell short $200,000 in Facebook stock and would need to have $100,000 in cash deposited with a broker (initial margin). If the stock goes up by even a penny, you would need additional margin to cover that. A young hacker with no money cannot make any by shorting stocks.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#30
post #20
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

The author clearly has a language barrier. Not all bug reports are going to come with sterling reports to back them. In the end, Ḱhalil fell back on the lingua franca of the internet: a working demonstration. The onus is on the organization, not the bug reporter, to vet the information. From what I see, there was more than enough in the report to conclude there was a problem, and follow up. If Facebook security fails…

I agree, and in the end, they finally broke the language barrier and comprehended the bug which I am sure they are working on fixing. They were able to get all the benefit of his work, why screw him on a measly little bounty?
Post reply on HN