Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

41–50 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#41
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

I thought the whole idea behind whitehat reports was to keep these exploits off the hands of malicious hackers.

Whoever made the decision not to pay this guy should check with Mark Zuckerberg. If Mark is still adhering to "the hacker way" he should embrace such clever ways of reporting exploits and invite any whitehat to test them on his or better, {the idiot who decided not to pay}'s profile.

Hacking and finding exploits requires thinking outside the box, by imposing rules and "terms of service" on them, Facebook might be defeating the whole purpose of the whitehat program.

Any exploit violates Facebook's terms anyways. By not paying, Facebook is telling the whitehat community "go ahead, do our QA for us, we will only pay you if we feel like it"

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#43
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

Oh come on. This is such a corporate PR stand. The guy had taken the perfect step by posting the exploit on Mark's wall. He tried twice with best way available to him to report the bug. Is Facebook saying he should have adhered to a particular way for doing a service to them? Good luck in making him paint in the bad light. Next person will simply upload the video on Youtube and won't even bother reporting anything.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#44
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

I thought the whole idea behind whitehat reports was to keep these exploits off the hands of malicious hackers. Whoever made the decision not to pay this guy should check with Mark Zuckerberg. If Mark is still adhering to "the hacker way" he should embrace such clever ways of reporting exploits and invite any whitehat to test them on his or better, {the idiot who decided not to pay}'s profile. Hacking and finding exp…

That's not true. There was a very easy way to find and demonstrate this bug without violating the TOS. The TOS clearly says, you can't target someone with your hack without their permission.

The hacker could have created two accounts he owned and controlled, who are not Facebook friends. He could have used one to post to the other's wall. Viola, bug proven and bounty collected.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#45
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

>>> If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour.

I strongly disagree.

Despite not following the process by the book, I think it is clear that he attempted to act in good faith and had trouble with language/cultural issues. It's not like he posted porn or something on Zuckerberg's profile.

I think that going out of their way to stiff this guy out of a few bucks makes it all the more likely that any future vulnerabilities that are discovered by foreigners will just be sold to spammers/hackers. And this makes the internet a worse place.

Facebook saved a few bucks but just lost a big PR war here that Facebook will reward you for disclosing vulnerabilities.

Facebook should have paid the guy and used this event as a reminder about the best practices and procedures to follow.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#46

Re: "We are unfortunately not able to pay you for this vulnerability because your actions violated our Terms of Service." Poor Zuck, literally poor poor Zuck. #Sarcasm Prediction: People will start finding holes, shorting the stock, exploiting the holes, then going public with the exploit and making their money once the stock dips. Done correctly, that probably pays pretty damn well, yes?

No, not really. You need to risk a lot of capital to make any money at all. For instance, to make even $10,000 on a 5% drop in Facebook stock, you would need to sell short $200,000 in Facebook stock and would need to have $100,000 in cash deposited with a broker (initial margin). If the stock goes up by even a penny, you would need additional margin to cover that. A young hacker with no money cannot make any by short…

You could create a much more leveraged position with options. With a put option buy, your maximum loss is capped, so you wouldn't need any additional margin.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#47

Earlier quoted context omitted.

I thought the whole idea behind whitehat reports was to keep these exploits off the hands of malicious hackers. Whoever made the decision not to pay this guy should check with Mark Zuckerberg. If Mark is still adhering to "the hacker way" he should embrace such clever ways of reporting exploits and invite any whitehat to test them on his or better, {the idiot who decided not to pay}'s profile. Hacking and finding exp…

That's not true. There was a very easy way to find and demonstrate this bug without violating the TOS. The TOS clearly says, you can't target someone with your hack without their permission. The hacker could have created two accounts he owned and controlled, who are not Facebook friends. He could have used one to post to the other's wall. Viola, bug proven and bounty collected.

Yeah, and he breaks their terms of service even there, since you're only supposed to create a single personal account under your true name.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#48

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides s…

Oh, and just to clarify, I'm not coming at this from the perspective of "BigCo hatred". It is in Facebook's best interests to treat white hat reported security issues seriously, even if they don't initially understand them.

What are the chances that this security researcher ever reports another bug to Facebook, given how he was treated? Selling future exploits to spammers wouldn't be the ethical thing to do, but if I know "Emrakul" in Facebook Security is just going to tell me to F-off, I start to justify it.....

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#49

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides s…

you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once.

Well he tried twice, and they told him it wasn't a bug both times. After that, what's wrong with selling "not an exploit" to the highest bidder?

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#50

i cant reply to all of these comments , but i can say that i love facebook security team when they ignored me ;) thank you for your support . regards .

Don't worry about your English, just continue to do what you are doing. But understand one thing, what you are doing is only worth to learn one or two. If FB is paying you are not is not really matters!

I was little irritated your English was criticized heavily! And it's more irritating when a security team misses to understand a security issue when I was able to understand

Post reply on HN