Live data from Hacker News

Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

arabcrunch.com

71–80 of 81 posts

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#71
post #67

Earlier quoted context omitted.

> After they said it is not a bug, it is clear that they have misunderstood you because you failed to communicate clearly. You could write a more detailed report and tell them that they have misunderstood you. Right. He could also make a detailed flow diagram, or maybe fly to US and demonstrate in loco how it works. Give me a break... If I send a bug report and some lazy engineer replies back in laconic fashion with…

A lazy engineer doesn't automatically result in a warrant for exploiting the bug on the CEO's (or anyone's) profile. No corporation will come forward and say "thank you for exploiting two of our users including our CEO and generating lots of negative PR for us. Here have this money for being a good boy and not selling the bug in the black market". That's not how whitehat works.

You talk as if raising awareness of the issue directly to the CEO of the company because his employee was incompetent at handling the issue in the first place is a bad thing.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#72

Earlier quoted context omitted.

1. I agree, Facebook probably could have been more tactful in their reply. Your example reply looks good. 2. That said...if you were the security researcher, and you received a "This is not a bug." - you would still be fully wrong in selling the exploit to the highest bidder. It's not ethical to do that just because you failed to get a bounty after reporting it, especially if you only tried once. I think both sides s…

Oh, and just to clarify, I'm not coming at this from the perspective of "BigCo hatred". It is in Facebook's best interests to treat white hat reported security issues seriously, even if they don't initially understand them. What are the chances that this security researcher ever reports another bug to Facebook, given how he was treated? Selling future exploits to spammers wouldn't be the ethical thing to do, but if I…

I wasn't talking about you when I spoke about the anti-BigCo sentiment.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#73

Earlier quoted context omitted.

This isn't a good summary of the events. His "lingua franca" is technically illegal, and violates Facebook's explicit and easily accessible Terms of Service. There's nothing obfuscated about this. It's very straightforward. Yes, he found a security vulnerability. That doesn't earn you points "just cause." You still need to report it with responsible disclosure and not exploit it for the lulz and attention. He could h…

In another thread it was mentioned that the terms of service aren't available in Arabic.

That's not Facebook's problem...should they also write Esperanto terms of service and Swahili terms of service just because security researchers exist who speak those languages?

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#74
post #62

Earlier quoted context omitted.

It's not "bullshit Terms of Service" - Facebook clearly lays out the terms of the Whitehat program. There was no bait and switch - it's very explicitly stated that he should not be exploiting the vulnerability, and that it needs to be clearly explained. I respect that he found a vulnerability, but he still needs to adhere to a website's terms and conditions. If the security team he reports a bug to doesn't "get it" t…

It's not "bullshit Terms of Service", it's "bullshit excuse". There is a difference.

You originally said bullshit TOS, which is why I quoted that. It's not a bullshit excuse for all the reasons I already mentioned.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#75

Earlier quoted context omitted.

In another thread it was mentioned that the terms of service aren't available in Arabic.

That's not Facebook's problem...should they also write Esperanto terms of service and Swahili terms of service just because security researchers exist who speak those languages?

Might help if hundreds of millions of people spoke Esperanto.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#76
post #24

Earlier quoted context omitted.

In his first message, he demonstrates that his bug exists by showing that he exploited somebody elses account. This is obviously , never the way to make a bug report. Heck, it's probably even illegal. You shouldn't need to read a sites terms and conditions to know that doing this will be breaking them. It's an expensive lesson. Hopefully it will lead to him being more sensible in future. I have no sympathy.

Denying bounty to a hacker on some bullshit "Terms of Service" violation excuse defeats the whole purpose of the bounty program. Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting.

Replace:

"Next time a hacker will just sell the exploit to somebody else, cash upfront, and wont bother reporting."

With:

"Next time a hacker will make sure they follow the Terms of Service when reporting"

For a much more likely scenario.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#77
post #47

Earlier quoted context omitted.

That's not true. There was a very easy way to find and demonstrate this bug without violating the TOS. The TOS clearly says, you can't target someone with your hack without their permission. The hacker could have created two accounts he owned and controlled, who are not Facebook friends. He could have used one to post to the other's wall. Viola, bug proven and bounty collected.

Yeah, and he breaks their terms of service even there, since you're only supposed to create a single personal account under your true name.

My company creates Facebook apps and have multiple FB accounts for testing purposes. They're not going to kick him off FB for having two accounts, come on.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#78
post #63

Earlier quoted context omitted.

In another thread it was mentioned that the terms of service aren't available in Arabic.

I believe that was referring to the terms of service of the whitehat program not Facebook's TOS itself.

Aren't the whitehat term's of service those that were talking about? They're the most relevant terms to this discussion.

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#79

Earlier quoted context omitted.

In another thread it was mentioned that the terms of service aren't available in Arabic.

That's not Facebook's problem...should they also write Esperanto terms of service and Swahili terms of service just because security researchers exist who speak those languages?

And the bug wasn't this hacker's problem. It's important to remember that this guy went out of his way to help Facebook.

As such, they should be a bit more understanding when someone that speaks Esperanto submits a bug without doing so in a way that perfectly adheres to their terms of service. They should step back and take a subjective view instead of trying to make it black and white. Was he acting maliciously? Did he knowingly violate the terms or was it out of ignorance? Was he trying to hurt Facebook by violating the terms or help them?

Re: Hacker Posts Facebook Bug Report on Mark Zuckerberg’s Wall

#80
post #66
post #59

Earlier quoted context omitted.

It's not just the language barrier or the ethics of disturbing someone's profile though. His emails read like a job application with some vague hints at an exploit that may or may not be real. I'd say he expected a job offer or at least an interview as compensation for eventually revealing the bug. In his perception, going ahead and posting on Zuckerberg's timeline was just another step toward that goal. Breaking the…

By giving him anything they would be encouraging violation of their terms of service. I'm no fan of Facebook but as a corporation they are doing the right thing.

I'm not saying they're doing the wrong thing either.
Post reply on HN