Earlier quoted context omitted.
In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
Security Community Raises Money for Researcher Snubbed by Facebook Bounty
11–20 of 37 posts
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#12Earlier quoted context omitted.
In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#13I am concerned "gofundme" will not be able to pay out to Palestine , I don't think paypal will work there and I don't even think USPS will deliver there? I know Israel will not allow Palestine to mail out internationally.
update: they will NOT likely be able to pay out
https://gofundme.zendesk.com/entries/22590777-Is-my-country-...https://www.paypal-community.com/t5/Getting-started/Palestin...
Palestine is not listed -> https://www.paypal.com/worldwide/
----
Guy lives in a place with 22% unemployment and has not been able to work in two years.
Watch this interview if you have not already http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-f...
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#14Earlier quoted context omitted.
In order of desirability, the methods of dealing with a discovered exploit are: 1. Report to vendor and do not publicly discuss until they've fixed it 2. Demonstrate the exploit in public to prove that it works 3. Sell on the black market to Mafia/NSA/etc The guy attempted approach (1), and didn't do a very good job of it, but it seems this was at least in part due to inexperience. Should he have worked more carefull…
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
You mean create a fake account? Isn't that against TOS?
> "use on established test account"
Where the instructions are in English, even after changing language?
> He was wrong, period, to post to a user's page
Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#15And he lives in Hebron in Palestine. How will they give him the money? Answer: not easily. The financial blocks between that area and the rest of the world are just as real as the geopolitical ones. It will be impressive if they do it, short of a guy meeting him at a checkpoint and throwing an envelope to him.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#16Earlier quoted context omitted.
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#17Earlier quoted context omitted.
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#18Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#19Earlier quoted context omitted.
Option 2 is not "Post on real user's account", option 2 is "create account, use" or "use on established test account". He was wrong, period, to post to a user's page. 100% wrong, and has no right to ask for the money, because of that. Facebook's response is exactly the correct response - fix the miscommunication, but remain firm in the denial of money to someone who broke clear rules.
> "create account, use" You mean create a fake account? Isn't that against TOS? > "use on established test account" Where the instructions are in English, even after changing language? > He was wrong, period, to post to a user's page Mark Z. is not just any user. FB is publicly traded, yes, but he is basically Facebook. It's not like he 'hacked into' someone's account.
FB allows the creation of test accounts for security research https://www.facebook.com/whitehat/accounts/
Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty
#20I don't understand how someone could discover a security exploit in the first place without breaching the Facebook ToS. Doesn't that give them a getout for anything that's reported to them?