Live data from Hacker News

Security Community Raises Money for Researcher Snubbed by Facebook Bounty

wired.com

1–10 of 37 posts

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#2
Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure.

Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period.

Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help demonstrate vulnerabilities. It is even mentioned many times on the page where you go to find the address to report issues to and learn about the bounty program.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#3
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

Lets not forget Mark himself was charged with breaching security, violating copyrights, and violating individual privacy by Harvard's disciplinary board for students - he turned out ok.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#4
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

In order of desirability, the methods of dealing with a discovered exploit are:

1. Report to vendor and do not publicly discuss until they've fixed it

2. Demonstrate the exploit in public to prove that it works

3. Sell on the black market to Mafia/NSA/etc

The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefully to pursue option (1) first? Sure. But Facebook should have asked him for more information, perhaps pointing him to the guidelines.

So next he went to option (2). Facebook found the bug, and fixed it. Option (2) is infinitely better than option (3). I think Facebook should be extremely grateful to this guy - he even apologised for having to take this option in his post on MZ's wall, after (1) failed. Regardless of his & facebook's mistakes, they still should be thankful for him reporting it.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#5
And he lives in Hebron in Palestine. How will they give him the money?

Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#6
post #5

And he lives in Hebron in Palestine. How will they give him the money? Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.

Bitcoin's here, to save the day!

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#7
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account".

He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#8
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

There's a difference between "This is not a bug" and "We don't have enough information to proceed with your report. Can you please follow the guidelines here for a more detailed one? Thanks for your help."

If you want responsible disclosure, the guy just did the first step, reporting to your security team privately. Guide him, learn the thing, reward and move on.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#9
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

I'm torn on this one. A while back I reported an exploit I'd found to a vendor to also get a back a "not a bug" response. Next version in their software had it fixed. They didn't have a bug bounty and I didn't have much interest in it past that I'd rather if fixed that not.

If there had been a small bounty on the line and it would have played out the same way, I'm not sure how I would have handled it. I'm all for responsible disclosure and wouldn't have any interest in posting it online or exploiting it. But what is the correct response if money is owed and you've already shared the exploit with the vendor?

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#10
post #2

Hopefully BeyondTrust will use the opportunity to also train him in responsible disclosure. Regardless of the response you get from a vendor, you don't make use of an exploit against a vulnerable target. That is the line that separates the good guys from the bad. Period. Facebook has invested heavily in sandbox environments and automated generation of test accounts with test data explicitly for researchers to help de…

In all fairness he did attempt to report it. Although very poorly. He an email saying in essence 'I found a bug' instead of 'If you change the id on the submit function of the post button you can submit to other walls.' If we would have sent the latter I think they would have paid more attention to him.
Post reply on HN