Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

151–160 of 301 posts

Re: Facebook vulnerability 2013

#151
post #87

Earlier quoted context omitted.

Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? Second, does reason not come into play here? You don't have to write a policy to compensate people for violating privacy - however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? This is like... the textbook definition of a hack. > however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems. I love that this statement is downthread of a Facebook engineer's comment…

What incentive does the engineer have to look deeper, and more holistically at the situation? None, especially if he doesn't want to create friction within the company - he can just sit comfortably having followed written protocol. A human with compassion can make compromises, someone following orders can't.

Re: Facebook vulnerability 2013

#152
post #87

Earlier quoted context omitted.

Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? Second, does reason not come into play here? You don't have to write a policy to compensate people for violating privacy - however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems.

In as much as he posted on another account's timeline without permission, he "hacked" it in the "unauthorized access" sense of hacked. re: reason; where does his reason come into play? It does not seem reasonable to post to M.Z.'s timeline, I'd guess he did that because he was P.O.ed at being dis'ed by the support people. In the bureaucratic theory I am aware, if you have rules (policies, proceudres, standards etc.)…

I believe you're comprehending his actions wrongly. He stated before he'd be able to post even onto M.Z.'s timeline, to announce that this isn't a narrow scope issue, and that it was to gain attention. I see no malicious or angered. If of course M.Z. all of a sudden sees some guy, who isn't a friend, posting to his wall - you think he might actually look into it, right?

Yeah, rules that don't take into account reason are inhumane. Similarly why we don't just give everyone 10 years in prison because they committed a crime - you take into account all aspects - and not just apply "oh but he committed a crime, so this is the result."

Re: Facebook vulnerability 2013

#153
post #143
post #81

Did someone post this to Reddit yet? This guy should get the bounty.

Yes, and they have a wildly different opinion than HN: http://www.reddit.com/r/netsec/comments/1kkvei/user_reports_...

Well, since you seem to have a top comment there - you don't see an error in the way the initial security responses were? Why didn't they guide him into providing the information they needed, to ask him specifically? Or point him out to the whitehat program, etc? They have no responsibility there - is that what you're implying?

Re: Facebook vulnerability 2013

#154
post #98

Earlier quoted context omitted.

"Paying people to fuck with people's accounts" is a pretty dishonest way to frame this.

No, you just refuse to think about the larger picture. I went out of my way to say that this person wasn't deliberately harming anyone. You're acting as if there's no precedent implicated in Facebook learning of someone violating both their normal ToS and the terms of their bug bounty program by compromising someone else's account, and then paying them a reward. You're wrong about that.

I went out of my way to say that this person wasn't deliberately harming anyone.

Saying someone fucked with another person's account implies otherwise.

Re: Facebook vulnerability 2013

#155
post #58
post #44

Earlier quoted context omitted.

Hmm, wanna report at facebook.com/whitehat with more details? Please include repro instructions :).

Since when did repo stand for "reproduction" in sofware engineering term? Never heard it around here. East coast.

Since forever.

Re: Facebook vulnerability 2013

#157
post #137
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option. And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not sm…

Primary reason for Dubai office - 0% taxes

Re: Facebook vulnerability 2013

#158

Earlier quoted context omitted.

> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? This is like... the textbook definition of a hack. > however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems. I love that this statement is downthread of a Facebook engineer's comment…

>> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? >This is like... the textbook definition of a hack. Perhaps of "hacking FB", but he didn't "hack an account". I don't see what the problems are for FB here. They have a moral obligation to reward him for reporting this bug, especially since their ToS are apparently not available in Arabic. Claiming that he showed any sort o…

I don't think has anything to do with saving money. It really seems like a case of trying to take human judgment out of the equation. Strict adherence to rules is easy for bean-counters to push but frequently problematic for dealing with real world situations because rules are never perfect.

Re: Facebook vulnerability 2013

#159
post #122
post #76

Earlier quoted context omitted.

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

So if a security bug was discovered using methods that are against the TOS then the information about the bug is worthless for them and it's better to sold it elsewhere.

The whitehat page explicitly says that you must “not interact with other accounts without the consent of their owners” in order to qualify for the bounty. So yes, apparently Facebook can deny payment and suspend your account if they can reasonably suspect that you violated someone's privacy during bug discovery.

However, it seems that if you don't give them any clues in your report, they'll close their eyes and won't investigate carefully that possibility.

Re: Facebook vulnerability 2013

#160
post #43

I don't think you guys understand. You can't publicly use the exploit and then back away and use the white hat system after the fact. It clearly shows him spamming some profile before even making the first contact.

Spamming? Edit: It was a tame music video. On the spectrum of demonstrating to a test account all the way through to selling his discovered flaw to actual spammers, I rate this at the low end.

The point is not to individually judge the harmful effects of using an exploit publicly. That would be absurd. You have no right to say that the video posted on the girl's facebook wall was not a big deal. And I have no right to say that it was a big deal. The only sensible thing is to disallow any public usage of exploits whatsoever.
Post reply on HN