Earlier quoted context omitted.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
So the security person who said "This is not a bug," - what's happening there? If they had guided the guy reporting the bug, asked for more information or directed him to the expected methods for reporting, then this would have likely gone completely differently, right?
Facebook vulnerability 2013
141–150 of 301 posts
Re: Facebook vulnerability 2013
#142Earlier quoted context omitted.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
What a cunt reply. The slave masters have trained you well.
Re: Facebook vulnerability 2013
#143Did someone post this to Reddit yet? This guy should get the bounty.
http://www.reddit.com/r/netsec/comments/1kkvei/user_reports_...
Re: Facebook vulnerability 2013
#144Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.
Your answer - 'its not a bug its a feature'
Re: Facebook vulnerability 2013
#145Ad Board Chairwoman: Mr. Zuckerberg, this is an Administrative Board hearing. You're being accused of intentionally breaching security, violating copyrights, violating individual privacy by creating the website, www.facemash.com. You're also charged with being in violation of the University's policy on distribution of digitized images. Before we begin with our questioning you're allowed to make a statement. Would you like to do so?
Mark Zuckerberg: I've... [Mark stands up to make his statement]
Mark Zuckerberg: You know I've already apologized in the Crimson to the ABHW, to Fuerza Latina and to any women at Harvard who may have been insulted as I take it that they were. As for any charges stemming from the breach of security, I believe I deserve some recognition from this Board.
Ad Board Chairwoman: I'm sorry?
Mark Zuckerberg: Yes.
Ad Board Chairwoman: I don't understand.
Mark Zuckerberg: Which part?
Ad Board Chairwoman: You deserve recognition?
Mark Zuckerberg: I believe I pointed out some pretty gaping holes in your system.
----
The similarity is uncanny.
Re: Facebook vulnerability 2013
#146Re: Facebook vulnerability 2013
#147Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#148Re: Facebook vulnerability 2013
#149Earlier quoted context omitted.
So the security person who said "This is not a bug," - what's happening there? If they had guided the guy reporting the bug, asked for more information or directed him to the expected methods for reporting, then this would have likely gone completely differently, right?
By the time he'd reported it, he had already used the exploit to post on a live, non-friend, account. As far as I understand , that's already a violation of the TOS.
Re: Facebook vulnerability 2013
#150Earlier quoted context omitted.
Yeah, I wonder why the guy who said "This is not a bug." isn't actually the one getting in trouble. Clearly I understand why not - but then his actions lead to the person reporting to escalate their actions to get attention. If the "This is not a bug." guy actually helped guide the person reporting to the proper, expected actions, then this would have likely gone completely differently.
Surely that person is in trouble, or will be once the relevant bureaucracy gets back on Monday morning. This is just a huge embarassment, and exactly the opposite of proper security analysis. But no one is going to admit that externally until all the internal work has been done.