Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

51–60 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#51

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides s…

I think there are valid legally justifiable reasons for refusing the bounty, however they are outweighed by the reason for the bounty system to exist in the first place.

Not paying someone over minor violations that they only did to get your attention to the fact that something was definitely important to you is not good practice when running a bounty for bugs.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#52
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

What a load of crap.

I understand that English is not your first language (no I don't; I'll deride your command of it at every turn, going forward) and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken the time to clearly explain the steps (every whitehat reporter CAN NOT be expected to understand how or what to adequately include in a PoC; it is _Facebook_ who is shown to be lazy in their responses, failing to point the reporter to the rules, appropriate [localized] steps, and ANYTHING of value to help the reporter). For example you have said "mark profile" instead of "Mark Zuckerberg's profile" (lol, idiot). That's just ambiguous language (see, I really don't understand nor can forgive you for being an English speaker) and confuses the reader. They probably receive a lot of wrong reports every day so if you make mistakes like that you are less likely to be taken seriously (unlike the mistakes made by Facebook; woe is them who can't be arsed to not even have boilerplate guidance and just shrug off reporters; cool story bro).

[...] you failed to communicate clearly (idiot).

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#53
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

>>> If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour. I strongly disagree. Despite not following the process by the book, I think it is clear that he attempted to act in good faith and had trouble with language/cultural issues. It's not like he posted porn or something on Zuckerberg's profile. I think that going out of their way to stiff this guy out of…

I want to step in here - Facebook is in no-way trying to save a few bucks. I've reported a few bugs to Facebook and they go out of their way to pay you greater sums depending on the severity.

You just have to be professional and disclose in-detail with steps to reproduce.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#54
post #20

Earlier quoted context omitted.

The author clearly has a language barrier. Not all bug reports are going to come with sterling reports to back them. In the end, Ḱhalil fell back on the lingua franca of the internet: a working demonstration. The onus is on the organization, not the bug reporter, to vet the information. From what I see, there was more than enough in the report to conclude there was a problem, and follow up. If Facebook security fails…

This isn't a good summary of the events. His "lingua franca" is technically illegal, and violates Facebook's explicit and easily accessible Terms of Service. There's nothing obfuscated about this. It's very straightforward. Yes, he found a security vulnerability. That doesn't earn you points "just cause." You still need to report it with responsible disclosure and not exploit it for the lulz and attention. He could h…

In another thread it was mentioned that the terms of service aren't available in Arabic.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#55
post #47

Earlier quoted context omitted.

That's not true. There was a very easy way to find and demonstrate this bug without violating the TOS. The TOS clearly says, you can't target someone with your hack without their permission. The hacker could have created two accounts he owned and controlled, who are not Facebook friends. He could have used one to post to the other's wall. Viola, bug proven and bounty collected.

Yeah, and he breaks their terms of service even there, since you're only supposed to create a single personal account under your true name.

They have special whitehat accounts which you are allowed to set up for testing. You can have as many of those as you like.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#56

Earlier quoted context omitted.

>>> If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour. I strongly disagree. Despite not following the process by the book, I think it is clear that he attempted to act in good faith and had trouble with language/cultural issues. It's not like he posted porn or something on Zuckerberg's profile. I think that going out of their way to stiff this guy out of…

I want to step in here - Facebook is in no-way trying to save a few bucks. I've reported a few bugs to Facebook and they go out of their way to pay you greater sums depending on the severity. You just have to be professional and disclose in-detail with steps to reproduce.

Who said that only professionals can find vulnerabilities? The guy is clearly inexperienced, but catching the bug is no lesser favor to Facebook. They are being dicks. And they deserve the bad press.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#57
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

> After they said it is not a bug, it is clear that they have misunderstood you because you failed to communicate clearly. You could write a more detailed report and tell them that they have misunderstood you.

Right. He could also make a detailed flow diagram, or maybe fly to US and demonstrate in loco how it works. Give me a break...

If I send a bug report and some lazy engineer replies back in laconic fashion with "It's not a bug" I would also have exploited the CEO profile. They should be thankful he didn't simply sold the exploit, it had the potential to be huge.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#58

Earlier quoted context omitted.

I thought the whole idea behind whitehat reports was to keep these exploits off the hands of malicious hackers. Whoever made the decision not to pay this guy should check with Mark Zuckerberg. If Mark is still adhering to "the hacker way" he should embrace such clever ways of reporting exploits and invite any whitehat to test them on his or better, {the idiot who decided not to pay}'s profile. Hacking and finding exp…

That's not true. There was a very easy way to find and demonstrate this bug without violating the TOS. The TOS clearly says, you can't target someone with your hack without their permission. The hacker could have created two accounts he owned and controlled, who are not Facebook friends. He could have used one to post to the other's wall. Viola, bug proven and bounty collected.

Hackers don't read TOS nor manuals.

Facebook should not expect from whitehats the same standards of bug reporting of their QA department. Most hackers are self-taught, one of the reason they are able to think outside the box and find exploits.

The whitehat program's priority should be to FIND EXPLOITS so they can be patched. Not having every single hacker in the world expend hours reading TOS and instructions on how to properly report such exploit.

Here is a thought: pay him less for not following procedures, but pay him anyways. Or better: pay a bonus to reports that follow proper procedures.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#59
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

It's not just the language barrier or the ethics of disturbing someone's profile though.

His emails read like a job application with some vague hints at an exploit that may or may not be real. I'd say he expected a job offer or at least an interview as compensation for eventually revealing the bug. In his perception, going ahead and posting on Zuckerberg's timeline was just another step toward that goal.

Breaking the rules is a somewhat glorified thing in hacker circles, and this may have contributed to his attitude. Of course, what they don't tell you when they say "break all the rules" is that only works out if you actually win in the end. And winning is an event often contingent on getting someone important to like you.

For what it's worth, all of that probably wasn't done in bad faith, but it wasn't a constructive process either. It's something someone very inexperienced would do if they were desperate for a job in the USA. It's understandable behavior, and if I was on the relevant FB team I'd at least given him something to recognize his efforts. If in doubt, do the generous thing (and be it only for publicity's sake).

Post reply on HN