Live data from Hacker News

Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

washingtonpost.com

101–110 of 172 posts

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#101
post #97
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital. But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital. I look forward to Jim Denaro's blog post. Perhaps my viewp…

How does this make any sense at all? You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? They're appsec people spending their team trying to tackle one of the hardest appsec problems in basically the whole world.

Who would even have time for ceremony in a situation like that?

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#102

Earlier quoted context omitted.

Crime does pay, that's rather the point of crime, it doesn't really need proving.

In that case, crowdsourcing a way to pay this guy $5k for the vulnerability he found and abused would be counterintuitive.

abused

Really? Just because FB's security team was dismissive of a real bug report due to a language barrier they could have overcome with the tiniest bit of due diligence?

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#103
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

Being real and very smart does not preclude you from being an asshole.

Whatever set of things you are obviously doesn't preclude you from calling people you don't know "assholes" either, does it?

This is all you have to say?

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#104

Earlier quoted context omitted.

Crime does pay, that's rather the point of crime, it doesn't really need proving.

In that case, crowdsourcing a way to pay this guy $5k for the vulnerability he found and abused would be counterintuitive.

WOW WOW you say "abused"... strong language there. He was trying to show the bug to them. This guy looks like he never read the TOS in the first place so he wasn't going after abusing. He didn't communicate properly is the way I would put it.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#105

Earlier quoted context omitted.

It is one thing to point out the benefits of certain ideas that differ from the status quo, but being dogmatic and rude will gain you no points.

Again, no counterargument. You're only proving me right.

Ok fine, you've drawn me in.

The main counter argument is that you simply have no right dictate how others communicate, despite your declarations of improved efficiency and increased idea proliferation. I think people who spend tons of money on clothes and other trappings are wasting resources and contributing to unhealthy societal development, yet I do not go around demonizing these people. I kindly share my view to receptive listeners, while also attempting to recognize my own biases and inability to perfectly understand this massively complex world. Do you also go around proselytizing SUV owners for their massive waste of gasoline? Why not?

Lastly, it would be impossible to quantify this, but I wonder how much cultural richness, diversity of thinking, etc we would be losing if all of the sudden everyone was forced to only use English? My bet is that it would not be a trivial loss.

Anyways, I wouldn't be surprised if translation technologies make this discussion completely moot in the next couple decades.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#106
post #10

Why don't people just send things in their native language? If the platform for communication is serious (like a place to report security vulnerabilities), I would imagine they would spend the time/money to get a real translation if one was needed. Even Google Translate probably could've done a better job than this guy's original report.

Whatever language he was going to send it in was not going to get parsed anyways since he barely communicated any relevant information in his emails. The Facebook employee who replied to the email handled it very poorly, but the guy who found this bug also handled it very poorly by not actually sending any details about what he did.

Also he did mention on whose wall he posted and that they are not friends so this should have been a red flag on its own.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#107
post #97

Earlier quoted context omitted.

Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital. But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital. I look forward to Jim Denaro's blog post. Perhaps my viewp…

How does this make any sense at all? You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? They're appsec people spending their team trying to tackle one of the hardest appsec problems in basically the whole world. Who would even have time for ceremony in a situation like that?

You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats?

No, I do not. I am sure they are as smart as you say they are.

More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people.

They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#108
post #107

Earlier quoted context omitted.

How does this make any sense at all? You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? They're appsec people spending their team trying to tackle one of the hardest appsec problems in basically the whole world. Who would even have time for ceremony in a situation like that?

You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? No, I do not. I am sure they are as smart as you say they are. More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people. They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).

Your previous comment is right there for anyone to read.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#109
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

I understand your position in this, and after reading the full story, I even agree... but I also know a few independent security researchers (i.e. people who don't do this professionally) who do not.

They, rightfully or not, see an independent who was ignored and then persecuted for trying to responsibly report a bug. It's given Facebook a black eye to more than just the HN crowd, and people will probably be thinking twice about disclosing security bugs, particularly if they get "working as intended" as their initial response.

Also, consider the guidelines that go into developing a UI. The more roadblocks you put in someone's way to register for your site, the fewer people will register. Apply that to this, and the more roadblocks you put into reporting a bug correctly (requesting special accounts, fighting to convince staff that your bug is an actual issue), the fewer bug reports you're going to get. That's not a good thing for Facebook in the long run.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#110

Earlier quoted context omitted.

you know that the biggest advances in Maths are made in japanese, russian and french, right? You know that english got a status of lingua franca only gradually, meaning that for a long time there was actually no reason whatsoever to learn it. And now the best one, you know that thanks to the US money sent to Israel, Palestine is voluntarily maintained a third world country by its neighbor who impairs any form of educ…

Now, in the present, we live in a world where English is the dominant language (again, having a huge number of speakers it's a whole different thing) so, as a citizen, you have to adapt. Secondly, at a no point I said anything against this guy, he at least put in the effort and is commendable. My whole point was that thinking about resorting to translators instead of thinking about how to improve the number of Englis…

Just because everyone on the web corrects everyone else, English is not the most spoken language in the world. It is the third most while Arabic is the fifth to my surprise: http://en.wikipedia.org/wiki/List_of_languages_by_number_of_...
Post reply on HN