Live data from Hacker News

Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

washingtonpost.com

111–120 of 172 posts

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#111
post #65

Earlier quoted context omitted.

I definitely agree with you on this. The response from the engineer could've been better. Some sort of canned response would have worked. IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.

Embarrassment is a very relative thing - it looks to me like the majority of comments on this HN post are saying the guy was in the wrong for breaking the TOS and I have to say I agree. Facebook haven't been embarrassed, they've just upheld a policy which says that they won't pay anyone who doesn't play by the rules. Quite fair, in my opinion.

It is within our right however to protest against Facebook's decision, especially with the way it conducted itself before with the 'This is not a bug' response it gave.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#112
post #92

Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…

I understand your position in this, and after reading the full story, I even agree... but I also know a few independent security researchers (i.e. people who don't do this professionally) who do not. They, rightfully or not, see an independent who was ignored and then persecuted for trying to responsibly report a bug. It's given Facebook a black eye to more than just the HN crowd, and people will probably be thinking…

I don't see how you get from the facts of what happened to "persecution". Could you go a little further into that?

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#113

I don't really understand what significance there is in stating that he is "unemployed." Does that somehow make his actions better/worse or the "hack" more/less tolerable?

I think he was displaying his skill to facebook while giving them a hint as to what to do about it ;)

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#114

Earlier quoted context omitted.

Again, no counterargument. You're only proving me right.

Ok fine, you've drawn me in. The main counter argument is that you simply have no right dictate how others communicate, despite your declarations of improved efficiency and increased idea proliferation. I think people who spend tons of money on clothes and other trappings are wasting resources and contributing to unhealthy societal development, yet I do not go around demonizing these people. I kindly share my view to…

That's not a counterargument, that's just a bunch of hypotheses. Namely: we might lose diversity of thinking, we might get translation technologies in the future, while I presented only facts:

-translations cost a huge amount of money

-a fragmented world slows down the spreading of information

-the most influential pieces of writing are written in English

In addition, if you say "let's get some translators instead of learning English because learning is hard" that's laziness. There's no way around, it's not like I think you're just being lazy, it's just that you are being lazy.

Lazy:

adjective

-unwilling to work or use energy

-characterized by lack of effort or activity

All I got so far are a bunch of downvotes, what I didn't get is an opinionated, fact-based counterargument.

And I'm sad to say it, but I'm frankly disappointed that a community of engineers (for the most part) exhibits this kind of hidebound mindset.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#115
post #75
post #44

Earlier quoted context omitted.

The mainstream media spent twenty years trying to turn the word "hacker" into some sort of unholy cross between thief, terrorist, child pornographer, and teenager. They'd better be getting the sense that hacker == criminal by now!

Your replies in this thread have been piss poor, anti-corporation, anti-media, hyperbolic shitposting. Please take it back to /r/technology.

"Today, mainstream usage of 'hacker' mostly refers to computer criminals, due to the mass media usage of the word since the 1980s."

Source: Wikipedia, "hacker".

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#116

I think we should crowd-source $5k to that guy and make Zuck sure we don't really need him for anything. I'm ready to toss $10.

You would prove nothing other than that crime pays.

No, rather it would be assisting those talented engineers those who cannot speak fluent English and are discriminated against in that sense.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#117
post #81
post #68

Earlier quoted context omitted.

He posted on Mark's wall, not as him. Also, relative to other places you could be spending your time, FB security issues yield relatively little in the blackhat market because of their highly responsive abuse and security teams.

He posted on Mark's wall, not as him. Sure this bug was like that. But what if someone discovers a bug that allows you to post as the person?

What if I was able to send a fake press release on behalf of a company?[1]

What if I hacked the Twitter account of a major press organization?[2]

Eventually the SEC will require traders to seek independent verification before executing based on social data, or put stops in place similar to the flash crash protections.

1. http://www.sec.gov/news/press/2009/2009-226.htm 2. http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twit...

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#119
post #110

Earlier quoted context omitted.

Now, in the present, we live in a world where English is the dominant language (again, having a huge number of speakers it's a whole different thing) so, as a citizen, you have to adapt. Secondly, at a no point I said anything against this guy, he at least put in the effort and is commendable. My whole point was that thinking about resorting to translators instead of thinking about how to improve the number of Englis…

Just because everyone on the web corrects everyone else, English is not the most spoken language in the world. It is the third most while Arabic is the fifth to my surprise: http://en.wikipedia.org/wiki/List_of_languages_by_number_of_...

Jesus, now I know why everyone is so lazy to learn a new language: you're lazy enough to not read a comment let alone learn an entire language.

I already said it: yes, English it's not the most spoken language, but it's the dominant in that it transcends cultures and countries. Saying that Chinese is the dominant language because is the most spoken is like saying that ants are the most influential beings because they're the species most prevalent on earth.

Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

#120
post #107

Earlier quoted context omitted.

You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? No, I do not. I am sure they are as smart as you say they are. More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people. They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).

Your previous comment is right there for anyone to read.

Added to that comment for clarity ...

In this conversation, you appear to be defending the FB appsec team for the work they do other than _this particular incident_ and I have no contention with that.

When it comes to _this particular incident_, a lot of things went awry. (a) FB did not appear to have a process in place for handling bug reports from non-native english speakers (or non-speakers for that matter). (b) A bug did eventually get resolved, which otherwise may not have happened. The fact that the bug-reporter had to resort to extreme tactics was due to the breakdown of communication and not any malicious intent on part of the bug reporter (c) The infinitesimally small bug-bounty payout was denied on a technicality, that also appears to people other than me to be no more than a bureaucratic bitch-slap out of spite for the bug reporter resorting to extreme tactics (see (b)).

In summary, FB messed up by not providing the needed (language) resources to handle such an issue in the first place and is making a lousy situation worse by not paying the (token) bug-bounty that would have just put a kibosh on the whole situation exploding all over the internet, from the get go. All of this leaves FB (the company, not the smart appsec people) looking like the bad guys.

Post reply on HN