Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

31–40 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#31
post #24

Earlier quoted context omitted.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously , never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

Denying bounty to a hacker on some bullshit "Terms of Service" violation excuse defeats the whole purpose of the bounty program. Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting.

It's not "bullshit Terms of Service" - Facebook clearly lays out the terms of the Whitehat program.

There was no bait and switch - it's very explicitly stated that he should not be exploiting the vulnerability, and that it needs to be clearly explained.

I respect that he found a vulnerability, but he still needs to adhere to a website's terms and conditions. If the security team he reports a bug to doesn't "get it" the first time he should try again, not publicize it on Hacker News and attract negative publicity by putting it on Mark Zuckerberg's wall.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#32
post #22

I made a facebook security vulnerbility report Friday afternoon and have recieved absolutley no response from them.... its getting rather disgusting

Give them a few days? Companies like Microsoft receive 200,000 bug reports each day, and each one has to be examined to determine authenticity. Plus, you sent it before the weekend.

It's not "disgusting"...you just need to be patient.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#33
If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of:

    "This is not a bug" (essentially, "go away")
...they could have said:

    "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we will have a native speaker help translate."

If I was the researcher, the callous "go away" response would have convinced me that it would be more fruitful to sell the exploit to a spammer (who would pay HANDSOMELY to be able to post to anyone's wall).

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#34
post #22

I made a facebook security vulnerbility report Friday afternoon and have recieved absolutley no response from them.... its getting rather disgusting

Join the club...I've never received a response from them about basic issues.

Now I am a Facebook advertiser with a $30k monthly budget...I thought surely then I'd get some responses from them (for example, when I was unable to make changes to my ad campaign, including daily budget, for WEEKS, due to a javascript bug), but still left completely in the dark.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#35
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

Excellent summary, thanks. I don't think most of the people raising an outcry over Khalil not receiving any bounty understand that the Terms and Conditions are explicit and easily accessible. They also can't just set a precedent.

"Oh, if we don't understand your bug report, just post it on our founder/CEO's Facebook wall and it'll shoot right up to the top on our priority list."

I know everyone hates big companies but come on...the argument for Khalil to not be paid is very reasonable. I respect him for being able to find the bug but it's not a conspiracy. He could have sent back an email trying to be more clear, or ask for an Arabic-speaking employee.

Plus, Facebook is not a stingy company when it comes to paying security researchers. Just look at their Hall of Fame. It includes HN's 'homakov (Egor Homakov), who wrote an excellent blog post about finding a vulnerability in Facebook and his primary language isn't English. But he still found a way to report the vulnerability through responsible disclosure and he is very happy with the bounty he received.

Everyone thinks it's so cool and "sticking it to Facebook" and that Facebook is just some big bad company who doesn't care about the small folk. It's not like that at all, change your perspective.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#36
post #20
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

The author clearly has a language barrier. Not all bug reports are going to come with sterling reports to back them. In the end, Ḱhalil fell back on the lingua franca of the internet: a working demonstration. The onus is on the organization, not the bug reporter, to vet the information. From what I see, there was more than enough in the report to conclude there was a problem, and follow up. If Facebook security fails…

This isn't a good summary of the events. His "lingua franca" is technically illegal, and violates Facebook's explicit and easily accessible Terms of Service.

There's nothing obfuscated about this. It's very straightforward. Yes, he found a security vulnerability. That doesn't earn you points "just cause." You still need to report it with responsible disclosure and not exploit it for the lulz and attention.

He could have done things differently - especially, he could have asked to talk to a Facebook employee who understands Arabic. Or tried to put more effort into a second security report.

Frankly, posting on Mark Zuckerberg's wall about this is childish and just attention-grabbing. It's not a responsible disclosure.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#37
There are no excuses. Facebook should expect that hackers with english as a second language (or not even that) will find bugs in the system and that they will not be able to communicate the way the Facebook team expects.

They should stop finding excuses and start to focus their efforts on making sure that people with no communication skills can report any bug.

Suggestion: Facebook could create a new "Facebook_security" system, which can be used to report bugs. The system would have the same production version, but the terms and conditions would be flexible. It would be used only for security purposes, and if someone finds a bug, they could record the exploit and send to the facebook team. By doing this, they would make sure that any type of bug could be reported.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#38

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

I agree with your point but I disagree with your method. I agree that they should also offer a means to communicate in other languages, if they have that capacity.

But, your choice of sentence structure - with clauses and formal social graces - would be hugely more difficult for a non-native speaker to parse correctly.

If the goal is to communicate with a non-native speaker, Facebook's message is appropriate for its clarity.

Bear in mind also that they probably do want incorrect bug reports to "go away" - unless Facebook apply infinite resources to this, some false negative errors are inevitable.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#39

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good.

2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once.

I think both sides should have done things differently. Hacker News is skewed towards BigCo hatred as a whole, and I think it's showing a bit. The majority is siding with Khalil despite the fact that there are valid reasons for him to not receive a bug bounty.

Post reply on HN