Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

141–150 of 301 posts

Re: Facebook vulnerability 2013

#141
post #90
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

So the security person who said "This is not a bug," - what's happening there? If they had guided the guy reporting the bug, asked for more information or directed him to the expected methods for reporting, then this would have likely gone completely differently, right?

By the time he'd reported it, he had already used the exploit to post on a live, non-friend, account. As far as I understand , that's already a violation of the TOS.

Re: Facebook vulnerability 2013

#142
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

What a cunt reply. The slave masters have trained you well.

If the content of the reply is so easily objectionable, you should probably be arguing on the basis of what it says.

Re: Facebook vulnerability 2013

#144
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

First someone takes the pain of reporting a security flaw instead of exploiting it to help you out.

Your answer - 'its not a bug its a feature'

Re: Facebook vulnerability 2013

#145
The Social Network -

Ad Board Chairwoman: Mr. Zuckerberg, this is an Administrative Board hearing. You're being accused of intentionally breaching security, violating copyrights, violating individual privacy by creating the website, www.facemash.com. You're also charged with being in violation of the University's policy on distribution of digitized images. Before we begin with our questioning you're allowed to make a statement. Would you like to do so?

Mark Zuckerberg: I've... [Mark stands up to make his statement]

Mark Zuckerberg: You know I've already apologized in the Crimson to the ABHW, to Fuerza Latina and to any women at Harvard who may have been insulted as I take it that they were. As for any charges stemming from the breach of security, I believe I deserve some recognition from this Board.

Ad Board Chairwoman: I'm sorry?

Mark Zuckerberg: Yes.

Ad Board Chairwoman: I don't understand.

Mark Zuckerberg: Which part?

Ad Board Chairwoman: You deserve recognition?

Mark Zuckerberg: I believe I pointed out some pretty gaping holes in your system.

----

The similarity is uncanny.

Re: Facebook vulnerability 2013

#146
In my opinion good faith should be taken into consideration here. It sounds like he didn't understand the TOS as it was not in his native language. This didn't hurt facebook at all and saved them a lot of trouble. I don't get why they don't just pay up and say thank you. As well as giving him a copy of the TOS in Arabic to avoid future misunderstandings.

Re: Facebook vulnerability 2013

#147
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

How come you didn't have unit tests that tested this scenario on the server-side services?

Re: Facebook vulnerability 2013

#149
post #90

Earlier quoted context omitted.

So the security person who said "This is not a bug," - what's happening there? If they had guided the guy reporting the bug, asked for more information or directed him to the expected methods for reporting, then this would have likely gone completely differently, right?

By the time he'd reported it, he had already used the exploit to post on a live, non-friend, account. As far as I understand , that's already a violation of the TOS.

It's fairly obvious he didn't understand the whole whitehat accounts he should have been using. English isn't his first language, so should we fault the guy for that - or Facebook who's an international company - with 1+ billion users? Or should Facebook own up to that they should probably update their documents - or give the guy a fucking break because they haven't done that? This is where you need REASON to react REASONABLY, and not just use a blanket statement to "make their life easy" in decisions like this. That's lazy and inhumane.

Re: Facebook vulnerability 2013

#150
post #92
post #89

Earlier quoted context omitted.

Yeah, I wonder why the guy who said "This is not a bug." isn't actually the one getting in trouble. Clearly I understand why not - but then his actions lead to the person reporting to escalate their actions to get attention. If the "This is not a bug." guy actually helped guide the person reporting to the proper, expected actions, then this would have likely gone completely differently.

Surely that person is in trouble, or will be once the relevant bureaucracy gets back on Monday morning. This is just a huge embarassment, and exactly the opposite of proper security analysis. But no one is going to admit that externally until all the internal work has been done.

It's an assumption that they even care or are looking into it. So far the resulted outcome is they are blaming the guy who didn't follow "their rules" (that wouldn't likely have been clear to him due to a language barrier). This should hit mainstream media though - because if that kind of bug exists, what else exists that Facebook doesn't even know about, that's being taken advantage of?
Post reply on HN