Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

191–200 of 301 posts

Re: Facebook vulnerability 2013

#191
post #179

Earlier quoted context omitted.

> The behavior reflects that of a classic old and inflexible corporation that hides some details in their small prints to screw their customers over. You act as if corporations maliciously "screw their customers over". See the responses below and you'll see that in this specific case FB actually wins out when they pay more to their whitehats. I hate to single out your specific response, but it's comments like this (a…

Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad. This is like getting PR advise from a lawyer when there is trouble coming your way. Sure, the lawyer will tell you to repeat "no comment" or deny any involvement over and over again. That might be the right strategy in a legal sense and work out fine when nobody is watching. But you are loosing in the court of…

> Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad.

And what do you propose the alternative? A legalised document that outlines every "if this"-"then that", in every language, continent, dialect, etc.? You know how that story goes...

> And denying some kid a few hundred bucks even so he found a legit hack just because he didn't follow some proper corporate policy guideline does definitely reflect negatively on Facebook.

You know what makes Facebook look even more negative? The future precedence set when good-will hackers think it's OK to use a non-test account and drop the exploit on the CEO's page.

I know it's hard for the HN community to do so, but let's try practicing some empathy with both sides before we pick up the pitchfork.

Re: Facebook vulnerability 2013

#192
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

"and we have paid out over $1 million to hundreds of reporters"

So each reporter received approx. $1000? That's all?... Heh, Facebook is very greedy company.

Re: Facebook vulnerability 2013

#193
post #148

Earlier quoted context omitted.

Invading means to enter, and he didn't enter anything. He posted a link through Facebook's buggy system. The end.

Yeah this sounds like a super productive discussion.

Especially when you start using argument tactics like belittling.

Re: Facebook vulnerability 2013

#194
There are no excuses. Facebook should expect that hackers with english as a second language (or not even that) will find bugs in the system and that they will not be able to communicate the way the Facebook team expects.

They should stop finding excuses and start to focus their efforts on making sure that people with no communication skills can report any bug.

Suggestion: Facebook could create a new "Facebook_security" system, which can be used to report bugs. The system would have the same production version, but the terms and conditions would be flexible. It would be used only for security purposes, and if someone finds a bug, they could record the exploit and send to the facebook team. By doing this, they would make sure that any type of bug could be reported.

Re: Facebook vulnerability 2013

#195

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

https://www.facebook.com/legal/terms?locale=ar_AR It's translated. I believe it requires you to be in a local to get this page to display automatically. It certainly exists for people creating accounts in arabic, and absolutely includes the relevant lines.

Does that page include the whitehat programme TOS, or is it just the general TOS?

Re: Facebook vulnerability 2013

#196
post #193

Earlier quoted context omitted.

Yeah this sounds like a super productive discussion.

Especially when you start using argument tactics like belittling.

You're right; I am officially derisive of this discussion. You know I'm not making an argument by trying to characterize this person's actions as malicious, but you keep raising that idea as an issue, because you actively don't want to understand what's happening in this situation, but would prefer instead to demonize Facebook's security team.

Re: Facebook vulnerability 2013

#197
post #152

Earlier quoted context omitted.

In as much as he posted on another account's timeline without permission, he "hacked" it in the "unauthorized access" sense of hacked. re: reason; where does his reason come into play? It does not seem reasonable to post to M.Z.'s timeline, I'd guess he did that because he was P.O.ed at being dis'ed by the support people. In the bureaucratic theory I am aware, if you have rules (policies, proceudres, standards etc.)…

I believe you're comprehending his actions wrongly. He stated before he'd be able to post even onto M.Z.'s timeline, to announce that this isn't a narrow scope issue, and that it was to gain attention. I see no malicious or angered. If of course M.Z. all of a sudden sees some guy, who isn't a friend, posting to his wall - you think he might actually look into it, right? Yeah, rules that don't take into account reason…

Rules that are not applied consistently are arbitary.

No one said anything about a crime. Denial of the bounty is not brutal.

Re: Facebook vulnerability 2013

#199
post #193

Earlier quoted context omitted.

Especially when you start using argument tactics like belittling.

You're right; I am officially derisive of this discussion. You know I'm not making an argument by trying to characterize this person's actions as malicious, but you keep raising that idea as an issue, because you actively don't want to understand what's happening in this situation, but would prefer instead to demonize Facebook's security team.

Demonize the security team? I never implied that anywhere - please don't "put words in my mouth."

Re: Facebook vulnerability 2013

#200
Jim Denaro, @CipherLaw on Twitter, a lawyer specializing in these issues and someone who has studied bug bounty programs, twerped earlier at me:

Paying out a bounty in that situation would be legally risky. Would advise against it.

Facebook's ToS forbid you to compromise other users accounts in any way. Its bug bounty terms require the consent of any accountholder used to search for bugs. It's also bound by California laws regarding breach notifications. And over the long term, it must retain the ability to enforce its own ToS. These are just the objections I can think of.

If you're going to participate in a bug bounty program --- and you should --- don't use non-consenting accounts to do it. This is a simple issue that's been blown out of proportion by message board pathology.

Post reply on HN