Live data from Hacker News

Security Community Raises Money for Researcher Snubbed by Facebook Bounty

wired.com

11–20 of 37 posts

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#11

Earlier quoted context omitted.

In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

You're being a bit silly about this. The actual harm was nil.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#12

Earlier quoted context omitted.

In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

it might be technically correct, but people don't behave like machines, so the expected outcome in the future is not clear.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#13
Going to research it a bit to make sure he will get the funds and then I am also donating http://www.gofundme.com/3znhjs

I am concerned "gofundme" will not be able to pay out to Palestine , I don't think paypal will work there and I don't even think USPS will deliver there? I know Israel will not allow Palestine to mail out internationally.

   update: they will NOT likely be able to pay out
https://gofundme.zendesk.com/entries/22590777-Is-my-country-...

https://www.paypal-community.com/t5/Getting-started/Palestin...

Palestine is not listed -> https://www.paypal.com/worldwide/

----

Guy lives in a place with 22% unemployment and has not been able to work in two years.

Watch this interview if you have not already http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-f...

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#14

Earlier quoted context omitted.

In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

> "create account, use"

You mean create a fake account? Isn't that against TOS?

> "use on established test account"

Where the instructions are in English, even after changing language?

> He was wrong, period, to post to a user's page

Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#15
post #5

And he lives in Hebron in Palestine. How will they give him the money? Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.

[deleted]

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#16

Earlier quoted context omitted.

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.

The initial proof of concept post went to another user, not Mark Z. That was Facebook's basis for denying the claim.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#17

Earlier quoted context omitted.

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.

The initial proof of concept post went to another user, not Mark Z. That was Facebook's basis for denying the claim.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#19

Earlier quoted context omitted.

Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.

> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.

>You mean create a fake account? Isn't that against TOS?

FB allows the creation of test accounts for security research https://www.facebook.com/whitehat/accounts/

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#20

I don't understand how someone could discover a security exploit in the first place without breaching the Facebook ToS. Doesn't that give them a getout for anything that's reported to them?

facebook have a well-established program to allow anyone to look for security-related bugs. There are indeed terms and conditions associated with it however, including not interfering with real data/people.
Post reply on HN