Earlier quoted context omitted.
I chose my words carefully.
Invading means to enter, and he didn't enter anything. He posted a link through Facebook's buggy system. The end.
Facebook vulnerability 2013
181–190 of 301 posts
Re: Facebook vulnerability 2013
#182I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…
Re: Facebook vulnerability 2013
#183I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…
Most certainly, this chap should have followed proper decorum by consistently petitioning Facebook to pay heed, by filling out the necessary forms and ensuring a stamped, self-addressed envelop was also included should they choose to write to him at a later time.
And then to go and expound his savagery to the Noble CEO's account, an utter insult to civility indeed! (Yes! I'm being sarcastic)
Re: Facebook vulnerability 2013
#184Earlier quoted context omitted.
And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option. And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not sm…
Primary reason for Dubai office - 0% taxes
Re: Facebook vulnerability 2013
#185Earlier quoted context omitted.
Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…
"Can't pay him" sounds like bureaucracy BS. I'd argue that it's in their best interest to find a way to pay him. Why make people jump through hoops to report an exploit in your product? However, it also sounds to me like an opportunity for a bug / exploit reporting proxy business that validates, reproduces, and polishes reports in bulk. You most certainly could extract a much higher bounty per report.
Re: Facebook vulnerability 2013
#186Earlier quoted context omitted.
What surprises me the most is how bad they are handling the incident! The behavior reflects that of a classic old and inflexible corporation that hides some details in their small prints to screw their customers over. It reflects incredibly bad on their relationship with the tech community and I am sure we will see some superficial backpedaling very soon.
> The behavior reflects that of a classic old and inflexible corporation that hides some details in their small prints to screw their customers over. You act as if corporations maliciously "screw their customers over". See the responses below and you'll see that in this specific case FB actually wins out when they pay more to their whitehats. I hate to single out your specific response, but it's comments like this (a…
This is like getting PR advise from a lawyer when there is trouble coming your way. Sure, the lawyer will tell you to repeat "no comment" or deny any involvement over and over again. That might be the right strategy in a legal sense and work out fine when nobody is watching.
But you are loosing in the court of public opinion when the public perceives your actions as unfair. And denying some kid a few hundred bucks even so he found a legit hack just because he didn't follow some proper corporate policy guideline does definitely reflect negatively on Facebook.
Re: Facebook vulnerability 2013
#187Earlier quoted context omitted.
It looks like preserving the integrity of their ToS to me. If you believe it is because of $500, you are a total idiot and I will not talk to you.
If you think good hackers report security bugs for $500, I am tempted to call you a total idiot too (though I will not). Consider what motivates people more deeply.
Re: Facebook vulnerability 2013
#188Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#189Earlier quoted context omitted.
If you think good hackers report security bugs for $500, I am tempted to call you a total idiot too (though I will not). Consider what motivates people more deeply.
That is a vague reply with no apparent relevance to anything I said except the amount $500 which was not to be taken literally. My point was that facebook isn't doing this to save money and believing so is idiotic.
Thinking otherwise might be idiotic too, but that's besides the point.