Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…
Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital. But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital. I look forward to Jim Denaro's blog post. Perhaps my viewp…
Who would even have time for ceremony in a situation like that?