Is Facebook Bug Bounty Bogus?
1–10 of 13 posts
Re: Is Facebook Bug Bounty Bogus?
#2Re: Is Facebook Bug Bounty Bogus?
#3Bug bounty programs are as legitimate as the company wants them to be by providing the time of engineers to analyze the bugs and the funds to reward researches. I don't think they can be bogus exactly, they are what they are.
Now, the reason they exist is because bugs have a value outside the bounty program. So you, as a researcher, either have something you can profit from (in which case the choice to report to the bounty is your personal choice and there are others should you have to reanalyze) or you have a worthless curiosity and you can't really complain that no one is giving you money.
It sounds like you spent time entering a 'marketplace' that you don't have the capability to fully participate in, if you're all hung up on Facebook turning over a reward.
Re: Is Facebook Bug Bounty Bogus?
#4There could be a few things going on here, maybe your bug was classified as low pri, maybe we misdiagnosed the bug.
Speculation but I would call into question your assertion that we fixed something based on your submission and then attempted to hide/delay it. We have not and would not do such a thing.
Re: Is Facebook Bug Bounty Bogus?
#5Any bug bounty program suffers from tons of junk mail from people who copy paste definitions from owasp and misunderstand whats going on. Bug bounty programs are as legitimate as the company wants them to be by providing the time of engineers to analyze the bugs and the funds to reward researches. I don't think they can be bogus exactly, they are what they are. Now, the reason they exist is because bugs have a value…
Re: Is Facebook Bug Bounty Bogus?
#6I work at facebook on the bug bounty program, if you have an email, name or ticket id I can look into it for you. There could be a few things going on here, maybe your bug was classified as low pri, maybe we misdiagnosed the bug. Speculation but I would call into question your assertion that we fixed something based on your submission and then attempted to hide/delay it. We have not and would not do such a thing.
Re: Is Facebook Bug Bounty Bogus?
#7I work at facebook on the bug bounty program, if you have an email, name or ticket id I can look into it for you. There could be a few things going on here, maybe your bug was classified as low pri, maybe we misdiagnosed the bug. Speculation but I would call into question your assertion that we fixed something based on your submission and then attempted to hide/delay it. We have not and would not do such a thing.
It may not be intentional but what about unintentional fixes ? What happens to bugs that were valid when posted but fixed (unintentionally) right after a release/code deployment.
We have paid out on such issues before but there is no hard rule. In general we err on paying out if there is any question. We have paid out before when a submission wasn't a bug at all but lead us to some part of the code that we ourselves then found a security bug in.
It is in our best interest to payout whenever possible. More payouts = more submissions = more security bugs found and fixed.
Re: Is Facebook Bug Bounty Bogus?
#8Earlier quoted context omitted.
It may not be intentional but what about unintentional fixes ? What happens to bugs that were valid when posted but fixed (unintentionally) right after a release/code deployment.
I need more information if you want me to look into this issue. We have paid out on such issues before but there is no hard rule. In general we err on paying out if there is any question. We have paid out before when a submission wasn't a bug at all but lead us to some part of the code that we ourselves then found a security bug in. It is in our best interest to payout whenever possible. More payouts = more submissio…
Re: Is Facebook Bug Bounty Bogus?
#9Earlier quoted context omitted.
I need more information if you want me to look into this issue. We have paid out on such issues before but there is no hard rule. In general we err on paying out if there is any question. We have paid out before when a submission wasn't a bug at all but lead us to some part of the code that we ourselves then found a security bug in. It is in our best interest to payout whenever possible. More payouts = more submissio…
I think the report number is 173358208.