Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

121–130 of 301 posts

Re: Facebook vulnerability 2013

#121
post #78
post #45

Earlier quoted context omitted.

Pay the man. He stumbled around a bit trying to work out how to help, but he brought a flaw to your attention in what he thought was a polite way. If unleashed, this bug could've been used to wreak havoc on Facebook and damage the company's reputation. $500 is the very least FB should be paying.

Is it even lawful for them to pay people that knowingly invade other people's accounts?

Why wouldn't it be? At worst, wouldn't facebook be the aggrieved party, and not another user of facebook?

Suppose I hacked into a bank and stole money from some account. Would the person whose account was hacked be able to have some legal recourse against me? I'd imagine it would be the bank.

If this is the case, then surely facebook could just choose not to press charges, and if so, what would be unlawful paying him in that case?

Re: Facebook vulnerability 2013

#122
post #76

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

So if a security bug was discovered using methods that are against the TOS then the information about the bug is worthless for them and it's better to sold it elsewhere.

Re: Facebook vulnerability 2013

#123
post #82

Earlier quoted context omitted.

They're not "denying him the reward". He demonstrated the vulnerability on someone's actual account. They can't pay people to fuck with other people's accounts. That's not what bug bounties are about. Only on a message board is this hard to understand.

"Paying people to fuck with people's accounts" is a pretty dishonest way to frame this.

He didn't f* up Zuck's account. Just making a wall post on some account doesn't f* that account in any way.

Re: Facebook vulnerability 2013

#124
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

You apologise and pay the guy. Then you write it up as a public case study in very simple English. At each step point out what he should have done. That means the next people know what to do, and everything comes out positively from this.

At the moment the loud and clear message is that there are far more welcome places than Facebook to report found issues.

Re: Facebook vulnerability 2013

#125
post #120

Long time ago a friend and me once submitted a whitehat bug that allowed the user to send messages to anyone even if they disabled messages from non-friends, i don't think this option still exists but anyways Facebook told us this wasn't a bug, we didn't even argue, suckers! i now wish i did the Same as Khalil and recorded the bug.

Well, if you have the email, just reply to it and re-open the conversation and see what happens. If you can explain it correctly, they might be able to research if the bug indeed existed and was fixed. I did a follow up on a bug that I submitted before the whitehat program was in place and that I never got a response on. They looked up the bug, replied to me and paid me. Very diligent.

Re: Facebook vulnerability 2013

#126
post #87
post #77

Earlier quoted context omitted.

Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…

Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? Second, does reason not come into play here? You don't have to write a policy to compensate people for violating privacy - however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there?

This is like... the textbook definition of a hack.

> however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

I love that this statement is downthread of a Facebook engineer's comment that states he considers the guidelines reasonable. It's as if you're just a drone following written orders without the ability to make compromises.

Re: Facebook vulnerability 2013

#128
post #106
post #33

Earlier quoted context omitted.

He couldn't have proved without doing that .

He could have made test accounts with appropriate privacy settings. He could have just told the security team, "Your server does not validate permissions when posting to walls, so if you change this specific HTML form value to anyone else's profile ID, it will post to their wall."

It's pretty freaking obvious there was a language barrier problem here. He knew of the whitehat program, but not the ability within it to create test accounts: he asks the security team to set up a test account so he can post to it to show them the problem.

Re: Facebook vulnerability 2013

#129
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

So can I report the same bug under the guidelines and get paid for it, or did you rob him and patch it already? Just pay the man, as a programmer a simple bug like this is a huge no no in the engineers part, and not rewarding the user for his conduct is plain selfish of the company.

Re: Facebook vulnerability 2013

#130
post #122
post #76

Earlier quoted context omitted.

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

So if a security bug was discovered using methods that are against the TOS then the information about the bug is worthless for them and it's better to sold it elsewhere.

An argument could be made it wasn't so much the discovery of the bug but rather the manner of reporting it that was a ToS violation.
Post reply on HN