I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.
Recent reports on our whitehat program
11–20 of 43 posts
Re: Recent reports on our whitehat program
#12After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
Re: Recent reports on our whitehat program
#13Re: Recent reports on our whitehat program
#14After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
facebook's communication skills were not stellar either ('this is not a bug'). If you are taking reports from users about security problems, treat every one as real until proven otherwise.
If you say you will pay 500Bucks per Bug reported, you will have a huge Fail rate, even if the Facebook Support is well Motivated after 3hours working, answering to 100Tickets you might not be able to understand something written in that way:
"Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timeline friends posts shares only with her friends , you need to be a friend of her to see that post or you can use your own authority ."
Re: Recent reports on our whitehat program
#15Re: Recent reports on our whitehat program
#16Now is the time for both sides to make their apologies and for Facebook to reward the hacker.
Re: Recent reports on our whitehat program
#17After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
"lacked the communication skills"... seriously? how do you know? just because English is not his primary language and he had hard time expressing himself in an unfamiliar language does not mean that he "lacked the communication skills".
Facebook gives 500$ per Bug reported, which ends up in a lot of Fail reports if somebody like this gets send:
"Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timeline friends posts shares only with her friends , you need to be a friend of her to see that post or you can use your own authority ."
You might mistake it for.
"You can post something on a friends page and you can't see it if you aren't friend with that person"
Re: Recent reports on our whitehat program
#18This could be soooo easy. Just provide a way to create a temporary account for tests that is not "a real user" and offer it on request. Creating and deleting these should not be a problem - if a report is false, the account won't change anyway.
Re: Recent reports on our whitehat program
#19Facebook, at least send the guy a new laptop. You don't even have to tell anyone you did it if you are worried about "rewarding non-preferred behavior". Mute the commercial and watch this video to meet this guy and realize he was trying to help and you were being idiots: http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-f... He hasn't worked in two years and his laptop is missing 5 keys.
Re: Recent reports on our whitehat program
#20After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
If anything, he had great communication skills. He overcame a non-native language barrier, while being conversationally blocked, and still made his point clearly.
Besides, are communication skills the important skill here? I would say, not.
Facebook do not pay white hat hackers at a level appropriate to their skill and work ($1m total? that's all?!) and now it's also clear they are looking for technicalities to avoid payment.