Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

201–210 of 301 posts

Re: Facebook vulnerability 2013

#201

I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…

I'm surprised you're not taking him to task for his poor grammar, sentence structure and obvious misspellings. To say "replay" when he means "reply", how the hell did his accent make it into his writing? Quite obviously his reports were ignored. Most certainly, this chap should have followed proper decorum by consistently petitioning Facebook to pay heed, by filling out the necessary forms and ensuring a stamped, sel…

I don't know why you are being sarcastic. I don't make one mention of Khalil's grammar. I understand that everyone's first language isn't english, but Khalil isn't even making an effort to be clear or accurately communicate what the problem is.

In the comments of the blog post, Khalil admits that it isn't that he has a poor understanding of the english language, it is just that he doesn't care.

> whatever , i dont care for miss spelling , just the idea , i never correct an underline red word ;)

So we have a guy that doesn't give a crap about communicating correctly, who then complains when he is not understood.

Re: Facebook vulnerability 2013

#203

I'm not sure how Facebook was supposed to know this was a vulnerability. If you look at the actual conversation it looks like Khalil is reporting the ability to post on other people's walls as a vulnerability. In the first email, Khalil simply says that he can post to Sarah Goodin's facebook wall. He makes no mention of the fact that he and Sarah Goodin aren't friends. The Facbook engineer replies that he is unable t…

second email points about that he and Sarah are not friends. "the vulnerability allow's facebook users to share posts to non friends facebook users "

You are correct, I completely missed that. However, he again fails to provide any sort of explanation of what he did to perform the attack. Even if he had reverted back to his native language, he never even attempts to explain what he did to perform the attack.

Re: Facebook vulnerability 2013

#204
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Matt you are a lazy spoiled jerk. No doubt.

Re: Facebook vulnerability 2013

#205

Jim Denaro, @CipherLaw on Twitter, a lawyer specializing in these issues and someone who has studied bug bounty programs, twerped earlier at me: Paying out a bounty in that situation would be legally risky. Would advise against it. Facebook's ToS forbid you to compromise other users accounts in any way. Its bug bounty terms require the consent of any accountholder used to search for bugs. It's also bound by Californi…

Don't pay the bounty for the bug then. Pay it for identifying the weak links in the security-reporting chain. The links that shrugged the bug reporter off, from the start; didn't have, at the very least, some boilerplate to guide the reporter; didn't have avenues or rules for non-English speakers.

For all we know, the reporter might have thought, "This will never work" or is not up to speed on or didn't understand the rules. Facebook certainly didn't help him, at every turn, including the last email "Sorry, l2p."

Re: Facebook vulnerability 2013

#206
post #76

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

Well according to Facebook, "this is not a bug". Which means the feature works as intended. If he is using Facebook as it is intended, then how can he be breaking the TOS?

When an employee whose job it is to evaluate security issues says "this is not a bug", that determination carries the force of law the same way as if it appeared in the TOS. You cannot rely on people to follow some nebulous "spirit of the TOS" when meanwhile your employees have already made a contrary specific determination for how it applies to this particular bug.

Re: Facebook vulnerability 2013

#207

Earlier quoted context omitted.

after being treated this way, i doubt this man (probably everyone who read this) will ever report bugs to facebook anymore.

i said that many times , agreed

You're doing good work. Don't be discouraged. You clearly have some talent, and you can do positive good with it. Large companies are wedded to their rules, terms, and systems. As you work more on these sort of things, the process will get easier. As you can see, there are many supportive people here.

Re: Facebook vulnerability 2013

#208
post #76

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

Creating a test account is also kind of a violation of the TOS anyway:

"You will not provide any false personal information on Facebook, or create an account for anyone other than yourself without permission.

You will not create more than one personal account."

Re: Facebook vulnerability 2013

#209
post #69

Earlier quoted context omitted.

You seem to be making an awful lot of excuses to not just pay someone who brought to light a critical exploit. Do you work on the security team or are you a lawyer (maybe with a panicking accountant looking over your shoulder) trying to find fine print reasons say, "Aha! We can save money to our bottom line in this instance!" ? Do you know how silly it looks for you to make these excuses?

This is pretty silly. Facebook obviously doesn't care about the dollars here; if anything, I'd imagine they want to be paying more bounties.

I remember a comment by you saying that most exploits are not that valuable. How valuable would this one have been?

Re: Facebook vulnerability 2013

#210
post #199

Earlier quoted context omitted.

You're right; I am officially derisive of this discussion. You know I'm not making an argument by trying to characterize this person's actions as malicious, but you keep raising that idea as an issue, because you actively don't want to understand what's happening in this situation, but would prefer instead to demonize Facebook's security team.

Demonize the security team? I never implied that anywhere - please don't "put words in my mouth."

I think you are here: https://news.ycombinator.com/item?id=6231466 . And please don't bother defending, just dropping by.
Post reply on HN