Security Community Raises Money for Researcher Snubbed by Facebook Bounty
1–10 of 37 posts
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#2Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period.
Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help demonstrate vulnerabilities. It is even mentioned many times on the page where you go to find the address to report issues to and learn about the bounty program.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#3Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#4Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…
1. Report to vendor and do not publicly discuss until they've fixed it
2. Demonstrate the exploit in public to prove that it works
3. Sell on the black market to Mafia/NSA/etc
The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefully to pursue option (1) first? Sure. But Facebook should have asked him for more information, perhaps pointing him to the guidelines.
So next he went to option (2). Facebook found the bug, and fixed it. Option (2) is infinitely better than option (3). I think Facebook should be extremely grateful to this guy - he even apologised for having to take this option in his post on MZ's wall, after (1) failed. Regardless of his & facebook's mistakes, they still should be thankful for him reporting it.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#5Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#6And he lives in Hebron in Palestine. How will they give him the money? Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#7Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…
In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…
He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#8Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…
If you want responsible disclosure, the guy just did the first step, reporting to your security team privately. Guide him, learn the thing, reward and move on.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#9Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…
If there had been a small bounty on the line and it would have played out the same way, I'm not sure how I would have handled it. I'm all for responsible disclosure and wouldn't have any interest in posting it online or exploiting it. But what is the correct response if money is owed and you've already shared the exploit with the vendor?
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#10Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…