Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

181–190 of 301 posts

Re: Facebook vulnerability 2013

#182

I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…

second email points about that he and Sarah are not friends. "the vulnerability allow's facebook users to share posts to non friends facebook users "

Re: Facebook vulnerability 2013

#183

I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…

I'm surprised you're not taking him to task for his poor grammar, sentence structure and obvious misspellings. To say "replay" when he means "reply", how the hell did his accent make it into his writing? Quite obviously his reports were ignored.

Most certainly, this chap should have followed proper decorum by consistently petitioning Facebook to pay heed, by filling out the necessary forms and ensuring a stamped, self-addressed envelop was also included should they choose to write to him at a later time.

And then to go and expound his savagery to the Noble CEO's account, an utter insult to civility indeed! (Yes! I'm being sarcastic)

Re: Facebook vulnerability 2013

#184
post #137

Earlier quoted context omitted.

And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option. And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not sm…

Primary reason for Dubai office - 0% taxes

Secondary reason for Dubai office - "Business" Trips

Re: Facebook vulnerability 2013

#185
post #169
post #77

Earlier quoted context omitted.

Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…

"Can't pay him" sounds like bureaucracy BS. I'd argue that it's in their best interest to find a way to pay him. Why make people jump through hoops to report an exploit in your product? However, it also sounds to me like an opportunity for a bug / exploit reporting proxy business that validates, reproduces, and polishes reports in bulk. You most certainly could extract a much higher bounty per report.

"Can't pay him" doesn't sound like bureaucracy BS, they don't pay him because he violated the TOS, it's on purpose. We could argue this is stupid and the TOS should be changed, but I can understand why they specify that in the process of reporting a bug you use a test account. Violating a real user privacy to report a bug isn't the proper way to report a bug. If they made an exception with this guy then they would have to make more exceptions and possibly set a bad precedent.

Re: Facebook vulnerability 2013

#186
post #179

Earlier quoted context omitted.

What surprises me the most is how bad they are handling the incident! The behavior reflects that of a classic old and inflexible corporation that hides some details in their small prints to screw their customers over. It reflects incredibly bad on their relationship with the tech community and I am sure we will see some superficial backpedaling very soon.

> The behavior reflects that of a classic old and inflexible corporation that hides some details in their small prints to screw their customers over. You act as if corporations maliciously "screw their customers over". See the responses below and you'll see that in this specific case FB actually wins out when they pay more to their whitehats. I hate to single out your specific response, but it's comments like this (a…

Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad.

This is like getting PR advise from a lawyer when there is trouble coming your way. Sure, the lawyer will tell you to repeat "no comment" or deny any involvement over and over again. That might be the right strategy in a legal sense and work out fine when nobody is watching.

But you are loosing in the court of public opinion when the public perceives your actions as unfair. And denying some kid a few hundred bucks even so he found a legit hack just because he didn't follow some proper corporate policy guideline does definitely reflect negatively on Facebook.

Re: Facebook vulnerability 2013

#187
post #174

Earlier quoted context omitted.

It looks like preserving the integrity of their ToS to me. If you believe it is because of $500, you are a total idiot and I will not talk to you.

If you think good hackers report security bugs for $500, I am tempted to call you a total idiot too (though I will not). Consider what motivates people more deeply.

That is a vague reply with no apparent relevance to anything I said except the amount $500 which was not to be taken literally. My point was that facebook isn't doing this to save money and believing so is idiotic.

Re: Facebook vulnerability 2013

#188
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

f u

Re: Facebook vulnerability 2013

#189
post #174

Earlier quoted context omitted.

If you think good hackers report security bugs for $500, I am tempted to call you a total idiot too (though I will not). Consider what motivates people more deeply.

That is a vague reply with no apparent relevance to anything I said except the amount $500 which was not to be taken literally. My point was that facebook isn't doing this to save money and believing so is idiotic.

My point is that people asking for a monetary reward might indirectly be asking for recognition, not the money per se.

Thinking otherwise might be idiotic too, but that's besides the point.

Post reply on HN