Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

61–70 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#61

Earlier quoted context omitted.

>>> If Facebook does pay you for the bug, it is just setting a bad example and will be encouraging similar behaviour. I strongly disagree. Despite not following the process by the book, I think it is clear that he attempted to act in good faith and had trouble with language/cultural issues. It's not like he posted porn or something on Zuckerberg's profile. I think that going out of their way to stiff this guy out of…

I want to step in here - Facebook is in no-way trying to save a few bucks. I've reported a few bugs to Facebook and they go out of their way to pay you greater sums depending on the severity. You just have to be professional and disclose in-detail with steps to reproduce.

Nobody would disagree with you that the disclosure message was poorly written.

Though the Facebook engineer conceivably could have offered to give the guy's email to a native speaker or tried to get more detail from him, I don't blame the initial Facebook engineer for dismissing it on the spot given that he probably had a few dozen other messages like that on the same day to review and deal with.

But it's all about perception here. The end result of this is a big PR loss for Facebook if they want to protect their users and get people to submit bug reports without having to fear that they'll lose out on money.

The next time an inexperienced foreigner discovers an exploit they'll research this topic and see that Facebook answered this guy with a "thanks for working for us for free" message. So what will happen is that when some spammer comes around with a few thousand dollars in cash vs the uncertainty of dealing with Facebook, odds are the exploit will go to him rather than Facebook. They won't read about the hundreds of times that Facebook did pay up, but the couple of times they didn't.

So this is just a big loss for the internet because Facebook made it that much more likely that people will sell their exploits to all kinds of nefarious people.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#62
post #24

Earlier quoted context omitted.

Denying bounty to a hacker on some bullshit "Terms of Service" violation excuse defeats the whole purpose of the bounty program. Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting.

It's not "bullshit Terms of Service" - Facebook clearly lays out the terms of the Whitehat program. There was no bait and switch - it's very explicitly stated that he should not be exploiting the vulnerability, and that it needs to be clearly explained. I respect that he found a vulnerability, but he still needs to adhere to a website's terms and conditions. If the security team he reports a bug to doesn't "get it" t…

It's not "bullshit Terms of Service", it's "bullshit excuse". There is a difference.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#63

Earlier quoted context omitted.

This isn't a good summary of the events. His "lingua franca" is technically illegal, and violates Facebook's explicit and easily accessible Terms of Service. There's nothing obfuscated about this. It's very straightforward. Yes, he found a security vulnerability. That doesn't earn you points "just cause." You still need to report it with responsible disclosure and not exploit it for the lulz and attention. He could h…

In another thread it was mentioned that the terms of service aren't available in Arabic.

I believe that was referring to the terms of service of the whitehat program not Facebook's TOS itself.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#64
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

What a load of crap. I understand that English is not your first language (no I don't; I'll deride your command of it at every turn, going forward) and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken the time to clearly explain the steps (every whitehat reporter CAN NOT be expected to understand how or wha…

Very informative commentary with your "lol" and "idiot" brackets.

Maybe Facebook sucks and can't be bothered with helping the reporter.

That does not make it ok for the reporter to go ahead and exploit it.

And for what it's worth, I'm not a English speaker either so I can understand and forgive someone for not being a English speaker too.

His report is very short and lazily written. It's not about the level of language skills. It's about the time and effort he put in on disclosing the vulnerability.

Using simple language he could have written a step by step guide explaining the problem.

The point is, regardless of Facebook's behavior, it is not ok for him to go ahead and exploit the bug on two different users one of them being the CEO of the company. And he did not put in enough effort to make them understand what he's talking about. He could have given it another shot with more details.

Facebook is not trying to "save" money on the bounty program. The budget is already allocated and no one is sitting there crying over the couple of thousands of dollars and trying to stop people from getting it.

If anything, he has caused damage to Facebook's image and reputation due to the negative publicity, greater than the amount he was going to be paid.

So yes, if you post on Mark Zuckerberg's profile and create a news shit-storm of negative publicity against Facebook they are not going to thank you and pay you money.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#65

Earlier quoted context omitted.

I want to step in here - Facebook is in no-way trying to save a few bucks. I've reported a few bugs to Facebook and they go out of their way to pay you greater sums depending on the severity. You just have to be professional and disclose in-detail with steps to reproduce.

Nobody would disagree with you that the disclosure message was poorly written. Though the Facebook engineer conceivably could have offered to give the guy's email to a native speaker or tried to get more detail from him, I don't blame the initial Facebook engineer for dismissing it on the spot given that he probably had a few dozen other messages like that on the same day to review and deal with. But it's all about p…

You are completely ignoring the fact that the reporter initially created massive negative PR for Facebook by posting on Mark's profile.

The bounty for Facebook is like a chocolate bar. They don't care about that.

And the message is not "thanks for working for us for free".

The message is "thanks...but next time remember not to exploit the bug you found".

The PR damage that he has caused for Facebook is probably many times greater than the bounty he was going to be paid.

He violated their terms of service and if Facebook just ignores the fact that he exploited it on two different users then the future reporters will expect that too.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#66
post #59
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

It's not just the language barrier or the ethics of disturbing someone's profile though. His emails read like a job application with some vague hints at an exploit that may or may not be real. I'd say he expected a job offer or at least an interview as compensation for eventually revealing the bug. In his perception, going ahead and posting on Zuckerberg's timeline was just another step toward that goal. Breaking the…

By giving him anything they would be encouraging violation of their terms of service.

I'm no fan of Facebook but as a corporation they are doing the right thing.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#67
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

> After they said it is not a bug, it is clear that they have misunderstood you because you failed to communicate clearly. You could write a more detailed report and tell them that they have misunderstood you. Right. He could also make a detailed flow diagram, or maybe fly to US and demonstrate in loco how it works. Give me a break... If I send a bug report and some lazy engineer replies back in laconic fashion with…

A lazy engineer doesn't automatically result in a warrant for exploiting the bug on the CEO's (or anyone's) profile.

No corporation will come forward and say "thank you for exploiting two of our users including our CEO and generating lots of negative PR for us. Here have this money for being a good boy and not selling the bug in the black market".

That's not how whitehat works.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#68
post #64

Earlier quoted context omitted.

What a load of crap. I understand that English is not your first language (no I don't; I'll deride your command of it at every turn, going forward) and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken the time to clearly explain the steps (every whitehat reporter CAN NOT be expected to understand how or wha…

Very informative commentary with your "lol" and "idiot" brackets. Maybe Facebook sucks and can't be bothered with helping the reporter. That does not make it ok for the reporter to go ahead and exploit it. And for what it's worth, I'm not a English speaker either so I can understand and forgive someone for not being a English speaker too. His report is very short and lazily written. It's not about the level of langua…

I am sorry to have used your post as an example, but it's just ludicrous to expect everyone to know the rules. You keep deriding the reporter as lazy or lacking of simple things!

His hack was lame; no one was hurt. Not even Facebook; nine 9s of their users don't won't know or care about such incidents. There's no telling that, had he used a whitehat account to repro the PoC, would they have paid any more attention; assuming the PoC can be performed on a whitehat account. It's not a stretch to think that a PoC against a real user should generate MORE attention.

The point is, Facebook failed to educate the reporter. They can improve their process. As you say, the bounty is really immaterial; I don't even mention it. However, the system is not there to make Facebook's life easier; if they care to only handle and reward pristine reports, they have another thing coming.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#69
post #17

I applaud him for his expertise and finding the bug but here are some points Ḱhalil: - You violated Facebook's terms of service by exploiting the bug on Sarah's profile. You shouldn't have done that. - I understand that English is not your first language and of course that's perfectly fine, people usually don't expect perfect English on the internet. However you have written the report quite lazily and haven't taken…

I thought the whole idea behind whitehat reports was to keep these exploits off the hands of malicious hackers. Whoever made the decision not to pay this guy should check with Mark Zuckerberg. If Mark is still adhering to "the hacker way" he should embrace such clever ways of reporting exploits and invite any whitehat to test them on his or better, {the idiot who decided not to pay}'s profile. Hacking and finding exp…

If a person is whitehat, it is understood, and by definition, they will not use the found bug for a bad purpose or sell it on black market.

Whitehat does not mean "I will responsibly disclose the vulnerability for as long as there's good money and rewards otherwise I will exploit it or sell it to someone else".

Facebook or any other company with bounty programs are not competing against the black market and trying to out-bid the bad guys by attracting the black hat hackers to wear a white hat and disclose the bug to Facebook for some money.

"we will only pay you if we feel like it"

Facebook isn't saying that. They are saying "we can not pay you because you violated our terms of service" which is truly an under-statement. It should be like "we can not pay you because you exploited the bug on our CEO's profile and another one of our users and have created negative PR and damaged our reputation"

But even if they did say "we will only pay you if we feel like it", as far as whitehats are concerned that should not change their incentives and behavior because, again, whitehats, by definition are not those who disclose the bugs for money and rewards.

If you are a grey/black hat only wearing the white hat when the money is good enough then Facebook is not interested in dealing with you in the first place.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#70

If the Facebook security team responded more thoughtfully, we wouldn't even be reading about this as news. Instead of: "This is not a bug" (essentially, "go away") ...they could have said: "Thanks for the report. It seems that English may not be your first language, so to be very clear, in order to check this issue, we will need these pieces of information (A, B, C). Please feel free to reply in your language, and we…

Yes I agree that the Facebook employee could have responded better.

But you are mixing two different issues.

Facebook employee saying "go away" does not automatically result in a warrant for you to go ahead and exploit the bug you found.

If you do that, you no longer meet the definition of a whitehat researcher.

That kind of person is not the type that Facebook wants to reward because Facebook is not competing against the black market prices.

It is simply rewarding those honest reporters who would report the bug even if they were 100% sure that Facebook is not going to pay anything and would not exploit it or sell it even if the Facebook employee said "screw you" or if the black market bids were 6 digit figures.

Post reply on HN