Earlier quoted context omitted.
I definitely agree with you on this. The response from the engineer could've been better. Some sort of canned response would have worked. IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.
Embarrassment is a very relative thing - it looks to me like the majority of comments on this HN post are saying the guy was in the wrong for breaking the TOS and I have to say I agree. Facebook haven't been embarrassed, they've just upheld a policy which says that they won't pay anyone who doesn't play by the rules. Quite fair, in my opinion.
Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
111–120 of 172 posts
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#112Once again, with feeling: Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder . That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people comp…
I understand your position in this, and after reading the full story, I even agree... but I also know a few independent security researchers (i.e. people who don't do this professionally) who do not. They, rightfully or not, see an independent who was ignored and then persecuted for trying to responsibly report a bug. It's given Facebook a black eye to more than just the HN crowd, and people will probably be thinking…
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#113I don't really understand what significance there is in stating that he is "unemployed." Does that somehow make his actions better/worse or the "hack" more/less tolerable?
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#114Earlier quoted context omitted.
Again, no counterargument. You're only proving me right.
Ok fine, you've drawn me in. The main counter argument is that you simply have no right dictate how others communicate, despite your declarations of improved efficiency and increased idea proliferation. I think people who spend tons of money on clothes and other trappings are wasting resources and contributing to unhealthy societal development, yet I do not go around demonizing these people. I kindly share my view to…
-translations cost a huge amount of money
-a fragmented world slows down the spreading of information
-the most influential pieces of writing are written in English
In addition, if you say "let's get some translators instead of learning English because learning is hard" that's laziness. There's no way around, it's not like I think you're just being lazy, it's just that you are being lazy.
Lazy:
adjective
-unwilling to work or use energy
-characterized by lack of effort or activity
All I got so far are a bunch of downvotes, what I didn't get is an opinionated, fact-based counterargument.
And I'm sad to say it, but I'm frankly disappointed that a community of engineers (for the most part) exhibits this kind of hidebound mindset.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#115Earlier quoted context omitted.
The mainstream media spent twenty years trying to turn the word "hacker" into some sort of unholy cross between thief, terrorist, child pornographer, and teenager. They'd better be getting the sense that hacker == criminal by now!
Your replies in this thread have been piss poor, anti-corporation, anti-media, hyperbolic shitposting. Please take it back to /r/technology.
Source: Wikipedia, "hacker".
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#116I think we should crowd-source $5k to that guy and make Zuck sure we don't really need him for anything. I'm ready to toss $10.
You would prove nothing other than that crime pays.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#117Earlier quoted context omitted.
He posted on Mark's wall, not as him. Also, relative to other places you could be spending your time, FB security issues yield relatively little in the blackhat market because of their highly responsive abuse and security teams.
He posted on Mark's wall, not as him. Sure this bug was like that. But what if someone discovers a bug that allows you to post as the person?
What if I hacked the Twitter account of a major press organization?[2]
Eventually the SEC will require traders to seek independent verification before executing based on social data, or put stops in place similar to the flash crash protections.
1. http://www.sec.gov/news/press/2009/2009-226.htm 2. http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twit...
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#118Then they don't have to admit they were wrong and don't look like jerks. Best of both worlds.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#119Earlier quoted context omitted.
Now, in the present, we live in a world where English is the dominant language (again, having a huge number of speakers it's a whole different thing) so, as a citizen, you have to adapt. Secondly, at a no point I said anything against this guy, he at least put in the effort and is commendable. My whole point was that thinking about resorting to translators instead of thinking about how to improve the number of Englis…
Just because everyone on the web corrects everyone else, English is not the most spoken language in the world. It is the third most while Arabic is the fifth to my surprise: http://en.wikipedia.org/wiki/List_of_languages_by_number_of_...
I already said it: yes, English it's not the most spoken language, but it's the dominant in that it transcends cultures and countries. Saying that Chinese is the dominant language because is the most spoken is like saying that ants are the most influential beings because they're the species most prevalent on earth.
Re: Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
#120Earlier quoted context omitted.
You imagine Facebook's security team as a bunch of green-shaded pocket-beprotectored bureaucrats? No, I do not. I am sure they are as smart as you say they are. More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people. They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).
Your previous comment is right there for anyone to read.
In this conversation, you appear to be defending the FB appsec team for the work they do other than _this particular incident_ and I have no contention with that.
When it comes to _this particular incident_, a lot of things went awry. (a) FB did not appear to have a process in place for handling bug reports from non-native english speakers (or non-speakers for that matter). (b) A bug did eventually get resolved, which otherwise may not have happened. The fact that the bug-reporter had to resort to extreme tactics was due to the breakdown of communication and not any malicious intent on part of the bug reporter (c) The infinitesimally small bug-bounty payout was denied on a technicality, that also appears to people other than me to be no more than a bureaucratic bitch-slap out of spite for the bug reporter resorting to extreme tactics (see (b)).
In summary, FB messed up by not providing the needed (language) resources to handle such an issue in the first place and is making a lousy situation worse by not paying the (token) bug-bounty that would have just put a kibosh on the whole situation exploding all over the internet, from the get go. All of this leaves FB (the company, not the smart appsec people) looking like the bad guys.