Live data from Hacker News

Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

washingtonpost.com

91–100 of 172 posts

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#91

Earlier quoted context omitted.

The only thing these nice commentators are advocating for is not blasting the character of others not conforming to your worldview. You are allowed to have an opinion, but the way you judge the choices of other people is rather unproductive.

All I see here are people going against me without offering a real reason as to why a fragmented world, the status quo, should be promoted.

It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#92
Once again, with feeling:

Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder. That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people compromising random user accounts.

Facebook also operates in a web of contractual and regulatory concerns, including California's breach notification laws. Exploitation of security vulnerabilities on Facebook's public properties outside of the terms of their bug bounty might be legally more akin to attacks than to pro-bono testing. Further, Facebook obviously needs the ability to reliably enforce their terms, lest they provide attackers with ammunition in a court case if they, for instance, Pastebin large amounts of Facebook user data. "Oh, I was just participating in the bug bounty program; I certainly wasn't setting out to sell $CELEBRITY's data to a tabloid."

Jim Denaro is an attorney specializing in stuff on this. We talked to him on Twitter this weekend when the story broke, and he said he would have advised against paying the bounty here too. Maybe we can get him to write a blog post.

I don't know how much "outrage" this has actually generated in the security community (maybe you can find links). The security people I've talked to think what happened makes perfect sense. Facebook didn't freak out, the acknowledged the bug report (once they understood it) and fixed the bug. They're just not paying a reward, because the bugfinder violated what is perhaps the most important term in the bug bounty.

One more thing: people on HN have a lot of strong opinions about Facebook, and while I don't share many of them, I understand and respect them. Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#93

Earlier quoted context omitted.

All I see here are people going against me without offering a real reason as to why a fragmented world, the status quo, should be promoted.

It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.

Again, no counterargument. You're only proving me right.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#94
post #69

Earlier quoted context omitted.

At USENIX this year, Chris Evans gave a talk about how Google does their VRP. Specifically, he mentioned that there weren't many false positive reports at all, way fewer than he expected there would be. In general, most bugs have something to them. Google has a long history of following up on bug reports with little or nothing to go on, because they take their jobs seriously, and aren't antagonistic to community bug…

As I mentioned in the reply above, the engineer's response could've been many times better, but you have to agree the bug submitter gave them practically nothing to work with.

Sure, the guy's bug report was terrible. However, the blame is squarely on FB. It's the security team's job to follow up, and to ask for more information if they don't have all the details.

Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#95
post #49
post #35

Earlier quoted context omitted.

The problem here is that if FB took every single bug report that they got 100% seriously, they'd never get to the real bug reports, but would just constantly be sifting through the spam. You have to make educated guesses on whether or not a report is just useless spam. This report, the way it read, shoots off a lot of spam flags. I understand why he got dismissed so easily and frankly it is his fault. Nobody has enou…

Replying "this is not a bug" is equivalent to saying "I have read and understood your report, and this is not a bug, it is a feature." First off, it's not a dismissal, it's an acknowledgement. Second, since it's not a bug but rather a feature, then how does using the feature violate the ToS? The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug r…

Exactly! In any kind of support role the number one pattern you observe is that there is always a lack of information. Maybe they are flooded to the point where they really cannot respond to these reports, but from what I've seen over 2/3 of support requests and bug reports require extracting more information from the submitter (even when the form specifically states to provide as much detail as possible with examples).

I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#96
post #35

Earlier quoted context omitted.

I don't think it is as cut and dry as that. The reply that 'this is not a bug' showed a lack of concern that the reporter may have been having difficulties correctly submitting information about what would be a very significant defect, if true. A community member taking the time and interest to try and go through proper channels to submit a vulnerability should, IMO, be given more respect than was shown by FB.

The problem here is that if FB took every single bug report that they got 100% seriously, they'd never get to the real bug reports, but would just constantly be sifting through the spam. You have to make educated guesses on whether or not a report is just useless spam. This report, the way it read, shoots off a lot of spam flags. I understand why he got dismissed so easily and frankly it is his fault. Nobody has enou…

Hardly anyone files a bug for fun. I can't imagine that the masses would file bugs since they don't know what they are in the first place. So when anyone files a bug and attach their name with it, they should be taken seriously. What was more important was that he made it clear that he made a post on someone else's timeline without him being friends with them. Red flag right there.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#97
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital.

But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital.

I look forward to Jim Denaro's blog post. Perhaps my viewpoint on this completely wrong and could be corrected, but for now this stinks of a cop-out behind red tape.

Edit: Further clarification below ... https://news.ycombinator.com/item?id=6240105.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#98
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

Being real and very smart does not preclude you from being an asshole.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#99

Earlier quoted context omitted.

It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.

Again, no counterargument. You're only proving me right.

Since you seem intent on furthering this conversation, here's an honest suggestion for you if you want to truly think about what you are arguing. Extensive academic thought already exists related to the argument you are trying to make -- in short, that it is worth restricting diversity in order to normalize cultures across the globe:

http://en.wikipedia.org/wiki/Postcolonialism

Postcolonialism, and especially postmodernism, are very complex concepts that require a great deal of study to grasp, but it may be worth your while if you want a serious challenge to your argument.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#100
post #75
post #44

Earlier quoted context omitted.

The mainstream media spent twenty years trying to turn the word "hacker" into some sort of unholy cross between thief, terrorist, child pornographer, and teenager. They'd better be getting the sense that hacker == criminal by now!

Your replies in this thread have been piss poor, anti-corporation, anti-media, hyperbolic shitposting. Please take it back to /r/technology.

If the media hasn't consistently presented "hacker" as negative, why is it seen as such? After all, everyone who actually knows what hacking is a: sees it as positive, and b: is irritated at the media presentation.

Facts is facts, man. Sorry if you don't like the snark, but I'm not sorry for telling the truth.

Post reply on HN