Earlier quoted context omitted.
The only thing these nice commentators are advocating for is not blasting the character of others not conforming to your worldview. You are allowed to have an opinion, but the way you judge the choices of other people is rather unproductive.
All I see here are people going against me without offering a real reason as to why a fragmented world, the status quo, should be promoted.
Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
91–100 of 172 posts
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#92Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder. That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people compromising random user accounts.
Facebook also operates in a web of contractual and regulatory concerns, including California's breach notification laws. Exploitation of security vulnerabilities on Facebook's public properties outside of the terms of their bug bounty might be legally more akin to attacks than to pro-bono testing. Further, Facebook obviously needs the ability to reliably enforce their terms, lest they provide attackers with ammunition in a court case if they, for instance, Pastebin large amounts of Facebook user data. "Oh, I was just participating in the bug bounty program; I certainly wasn't setting out to sell $CELEBRITY's data to a tabloid."
Jim Denaro is an attorney specializing in stuff on this. We talked to him on Twitter this weekend when the story broke, and he said he would have advised against paying the bounty here too. Maybe we can get him to write a blog post.
I don't know how much "outrage" this has actually generated in the security community (maybe you can find links). The security people I've talked to think what happened makes perfect sense. Facebook didn't freak out, the acknowledged the bug report (once they understood it) and fixed the bug. They're just not paying a reward, because the bugfinder violated what is perhaps the most important term in the bug bounty.
One more thing: people on HN have a lot of strong opinions about Facebook, and while I don't share many of them, I understand and respect them. Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#93Earlier quoted context omitted.
All I see here are people going against me without offering a real reason as to why a fragmented world, the status quo, should be promoted.
It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#94Earlier quoted context omitted.
At USENIX this year, Chris Evans gave a talk about how Google does their VRP. Specifically, he mentioned that there weren't many false positive reports at all, way fewer than he expected there would be. In general, most bugs have something to them. Google has a long history of following up on bug reports with little or nothing to go on, because they take their jobs seriously, and aren't antagonistic to community bug…
As I mentioned in the reply above, the engineer's response could've been many times better, but you have to agree the bug submitter gave them practically nothing to work with.
Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#95Earlier quoted context omitted.
The problem here is that if FB took every single bug report that they got 100% seriously, they'd never get to the real bug reports, but would just constantly be sifting through the spam. You have to make educated guesses on whether or not a report is just useless spam. This report, the way it read, shoots off a lot of spam flags. I understand why he got dismissed so easily and frankly it is his fault. Nobody has enou…
Replying "this is not a bug" is equivalent to saying "I have read and understood your report, and this is not a bug, it is a feature." First off, it's not a dismissal, it's an acknowledgement. Second, since it's not a bug but rather a feature, then how does using the feature violate the ToS? The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug r…
I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#96Earlier quoted context omitted.
I don't think it is as cut and dry as that. The reply that 'this is not a bug' showed a lack of concern that the reporter may have been having difficulties correctly submitting information about what would be a very significant defect, if true. A community member taking the time and interest to try and go through proper channels to submit a vulnerability should, IMO, be given more respect than was shown by FB.
The problem here is that if FB took every single bug report that they got 100% seriously, they'd never get to the real bug reports, but would just constantly be sifting through the spam. You have to make educated guesses on whether or not a report is just useless spam. This report, the way it read, shoots off a lot of spam flags. I understand why he got dismissed so easily and frankly it is his fault. Nobody has enou…
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#97Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…
But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital.
I look forward to Jim Denaro's blog post. Perhaps my viewpoint on this completely wrong and could be corrected, but for now this stinks of a cop-out behind red tape.
Edit: Further clarification below ... https://news.ycombinator.com/item?id=6240105.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#98Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#99Earlier quoted context omitted.
It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.
Again, no counterargument. You're only proving me right.
http://en.wikipedia.org/wiki/Postcolonialism
Postcolonialism, and especially postmodernism, are very complex concepts that require a great deal of study to grasp, but it may be worth your while if you want a serious challenge to your argument.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#100Earlier quoted context omitted.
The mainstream media spent twenty years trying to turn the word "hacker" into some sort of unholy cross between thief, terrorist, child pornographer, and teenager. They'd better be getting the sense that hacker == criminal by now!
Your replies in this thread have been piss poor, anti-corporation, anti-media, hyperbolic shitposting. Please take it back to /r/technology.
Facts is facts, man. Sorry if you don't like the snark, but I'm not sorry for telling the truth.