Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

111–120 of 301 posts

Re: Facebook vulnerability 2013

#111
Blissful ignorance. Next time guy like this will either do a lot of damage or sell the exploit to those who will pay.

Every security report should be taken seriously regardless it comes from a well known expert or just a guy from Palestine.

Re: Facebook vulnerability 2013

#112
post #87
post #77

Earlier quoted context omitted.

Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…

Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? Second, does reason not come into play here? You don't have to write a policy to compensate people for violating privacy - however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

In as much as he posted on another account's timeline without permission, he "hacked" it in the "unauthorized access" sense of hacked.

re: reason; where does his reason come into play? It does not seem reasonable to post to M.Z.'s timeline, I'd guess he did that because he was P.O.ed at being dis'ed by the support people.

In the bureaucratic theory I am aware, if you have rules (policies, proceudres, standards etc.) you need to apply them consistently. Sometimes the rule will allow for discretion, sometimes not. I don't see room for discretion here.

Re: Facebook vulnerability 2013

#114
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

What a cunt reply. The slave masters have trained you well.

Re: Facebook vulnerability 2013

#115
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

Pay the man!

As many others have said: The TOS was only available in English and that's not his first language. He did the only thing he could to get your attention and fix the problem.

Re: Facebook vulnerability 2013

#116
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

[deleted]

Re: Facebook vulnerability 2013

#117
post #18

The guy gave more info on his education than the exploit he was reporting. How is he surprised that they didn't take him seriously?

My guess is he thought starting by explaining that he has a CS education would make them less likely to assume his comment was from an ignorant foreigner.

Unfortunately, that didn't work either.

Re: Facebook vulnerability 2013

#118
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

You know, I agree with everything you have said.

But couldn't your team be a bit grateful? Though he did post to Zuck's account, he didn't sell the vulnerability as a zero day on the black market, no?

A cheap insurance policy, making the payout, cultivating trust with white hats who are nonetheless decidedly a bit bone headed (if not well meaning).

Re: Facebook vulnerability 2013

#119
post #78
post #45

Earlier quoted context omitted.

Pay the man. He stumbled around a bit trying to work out how to help, but he brought a flaw to your attention in what he thought was a polite way. If unleashed, this bug could've been used to wreak havoc on Facebook and damage the company's reputation. $500 is the very least FB should be paying.

Is it even lawful for them to pay people that knowingly invade other people's accounts?

Posting something on someones wall isn't so much invading as it is leaving a sticky note on their door. By that metric UPS invades peoples homes quite regularly when they fail to deliver a package. Had he actually accessed any non-public details of a users account that might be one thing, but the only data he was able to view was the post he had created himself. In short, it was his data, from his account, it just happened to be located on someone else's page. Honestly it's not even that bad of a vulnerability, more like a mild nuisance.

Re: Facebook vulnerability 2013

#120
Long time ago a friend and me once submitted a whitehat bug that allowed the user to send messages to anyone even if they disabled messages from non-friends, i don't think this option still exists but anyways Facebook told us this wasn't a bug, we didn't even argue, suckers! i now wish i did the Same as Khalil and recorded the bug.
Post reply on HN