Live data from Hacker News

Recent reports on our whitehat program

facebook.com

21–30 of 43 posts

Re: Recent reports on our whitehat program

#21
post #14
post #9

Earlier quoted context omitted.

facebook's communication skills were not stellar either ('this is not a bug'). If you are taking reports from users about security problems, treat every one as real until proven otherwise.

If you get over 90% fail rate? If you say you will pay 500Bucks per Bug reported, you will have a huge Fail rate, even if the Facebook Support is well Motivated after 3hours working, answering to 100Tickets you might not be able to understand something written in that way: "Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success…

Yes.

a) it's called triage and b) you won't want to miss that one report that blows your security wide open.

The point is moot now, facebook says they took note and will ask for more details from now on.

Re: Recent reports on our whitehat program

#22

This could be soooo easy. Just provide a way to create a temporary account for tests that is not "a real user" and offer it on request. Creating and deleting these should not be a problem - if a report is false, the account won't change anyway.

Facebook already has the ability to create test accounts: https://www.facebook.com/whitehat/accounts/

Re: Recent reports on our whitehat program

#23
post #17
post #12

Earlier quoted context omitted.

"lacked the communication skills"... seriously? how do you know? just because English is not his primary language and he had hard time expressing himself in an unfamiliar language does not mean that he "lacked the communication skills".

We are not talking about being bad at English we are talking about being difficult to understand. Facebook gives 500$ per Bug reported, which ends up in a lot of Fail reports if somebody like this gets send: "Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timelin…

I could perfectly understand it and English isn't my first language either. This is just Facebook weaseling themselves out of their promise by using bogus arguments. Besides that: If you do not understand a bug report for a security problem you ask for a clarification. That's what professionals do.

Re: Recent reports on our whitehat program

#24
post #11
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

I guess next time he should just sell the exploit on the black market then.

If he's the kind who would sell the exploit next time, Facebook isn't interested in rewarding him anyways.

Bounty programs are not there to create a more appealing market and out-bid the black hat hackers.

Re: Recent reports on our whitehat program

#25
post #23
post #17

Earlier quoted context omitted.

We are not talking about being bad at English we are talking about being difficult to understand. Facebook gives 500$ per Bug reported, which ends up in a lot of Fail reports if somebody like this gets send: "Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timelin…

I could perfectly understand it and English isn't my first language either. This is just Facebook weaseling themselves out of their promise by using bogus arguments. Besides that: If you do not understand a bug report for a security problem you ask for a clarification. That's what professionals do.

Facebook couldn't care less about the amount of bounty paid.

That amount for Facebook is practically like a chocolate bar.

They do not want to pay him because he exploited the bug he found two different times, once on the CEO's profile which has resulted in a very significant and negative PR for Facebook.

Facebook will not say "Thanks for creating shitty PR for our brand and damaging our reputation, here have this money"

Re: Recent reports on our whitehat program

#26
post #5

After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.

Caused the problem? The real problem was that someone could post to any user's wall. That was a problem with Facebook caused by its own developers.

Re: Recent reports on our whitehat program

#27
post #25
post #23

Earlier quoted context omitted.

I could perfectly understand it and English isn't my first language either. This is just Facebook weaseling themselves out of their promise by using bogus arguments. Besides that: If you do not understand a bug report for a security problem you ask for a clarification. That's what professionals do.

Facebook couldn't care less about the amount of bounty paid. That amount for Facebook is practically like a chocolate bar. They do not want to pay him because he exploited the bug he found two different times, once on the CEO's profile which has resulted in a very significant and negative PR for Facebook. Facebook will not say "Thanks for creating shitty PR for our brand and damaging our reputation, here have this mo…

Sure, but the PR will be far more shitty if the reaction of the next hacker is "Sorry, I could have told you about this bug, but I have heard that you don't honor your bounty agreements, so I have sold it to others - Have fun!"

Re: Recent reports on our whitehat program

#28
post #27
post #25

Earlier quoted context omitted.

Facebook couldn't care less about the amount of bounty paid. That amount for Facebook is practically like a chocolate bar. They do not want to pay him because he exploited the bug he found two different times, once on the CEO's profile which has resulted in a very significant and negative PR for Facebook. Facebook will not say "Thanks for creating shitty PR for our brand and damaging our reputation, here have this mo…

Sure, but the PR will be far more shitty if the reaction of the next hacker is "Sorry, I could have told you about this bug, but I have heard that you don't honor your bounty agreements, so I have sold it to others - Have fun!"

Facebook is not worried about that at all.

Whitehat bounty program, as the name implies, is for whitehat hackers.

And whitehat does not mean "Will not sell in black market as long as there's good enough bounty money to be collected".

Facebook is not competing with or outbidding black market rates.

If someone is the kind of hacker who would just go and sell the bug in the black market, Facebook would not want to pay them in the first place.

The purpose of bounty programs is NOT to "encourage black hat hackers to sell their bugs to us instead of black market", but rather it is "encourage white hat hackers to challenge our application instead of millions of other applications out there".

Re: Recent reports on our whitehat program

#29
post #5

After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.

Radle, perhaps more communication skills are needed to understand Facebook's response here:

I've reviewed our communication with this researcher, and I understand his frustration. He tried to report the bug responsibly, and we failed in our communication with him.

Facebook says Facebook failed communication. "He tried, we failed," is pretty cut and dried.

Re: Recent reports on our whitehat program

#30
Facebook can't possibly pay him. Exploiting a bug on the live site is not something they can reward, even if they want to. It would set the wrong kind of precedent, signaling that it's OK to do whatever to demo an exploit on Facebook.

That said, facebook will surely find some deal so they end up with positive PR.

Post reply on HN