Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

211–220 of 301 posts

Re: Facebook vulnerability 2013

#211
post #76

Earlier quoted context omitted.

They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.

Creating a test account is also kind of a violation of the TOS anyway: "You will not provide any false personal information on Facebook, or create an account for anyone other than yourself without permission. You will not create more than one personal account."

They specifically allow accounts to be created for whitehat purposes at https://www.facebook.com/whitehat/accounts/

Re: Facebook vulnerability 2013

#212
post #137
post #5

Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.

And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option. And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not sm…

Yes, right. The security team will ask the management to locate an Arabic speaking employee to handle a cryptic email, and do so for every email! That will surely scale. And employees love handling email exceptionally well.

Re: Facebook vulnerability 2013

#213
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

From a PR perspective, here are the rules: 1. Apologize 2. Pay the guy 3. Spell out in clear,vanilla English the steps to take to report bugs. Don't be a fucking macho/idiot. No need to dig in your heels when u already shot yourself in the foot by saying right out of the gate that it was not a bug.

Re: Facebook vulnerability 2013

#214
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Bug profit flowchart:

You discover a bug on FB just by being a normal user not a "whitehat" security user:

* You discovered it by doing "something" to someone else account --> FB will not pay : SELL on black market.

* You think the bug isn't really a bug but then it happens again --> FB will not pay : SELL on black market.

* You have a life that you don't want to waste with reading through legalese and filling out forms. FB says it is not a bug. Maybe they are right? You don't want to spend the time arguing about it over email --> SELL on black market

* You are not a lawyer, or do not do security testing full-time on FB. Or you are a normal user who has not kept on the FB ToS now that we are on the 100 billionth version --> You probably did something wrong. --> FB will not pay : SELL on black market.

* You are a US citizen and do not want to be charged with CFAA violations as a hacker --> SELL on black market.

Otherwise,

FB might give you some money.

Re: Facebook vulnerability 2013

#215

Earlier quoted context omitted.

I'm surprised you're not taking him to task for his poor grammar, sentence structure and obvious misspellings. To say "replay" when he means "reply", how the hell did his accent make it into his writing? Quite obviously his reports were ignored. Most certainly, this chap should have followed proper decorum by consistently petitioning Facebook to pay heed, by filling out the necessary forms and ensuring a stamped, sel…

I don't know why you are being sarcastic. I don't make one mention of Khalil's grammar. I understand that everyone's first language isn't english, but Khalil isn't even making an effort to be clear or accurately communicate what the problem is. In the comments of the blog post, Khalil admits that it isn't that he has a poor understanding of the english language, it is just that he doesn't care. > whatever , i dont ca…

My views below are not directed at you individually.

Through my sarcasm I was trying to convey the often imperialistic (and in my opinion useless douchebaggery) view we tend to take on certain matters and people, which, I believe, hinders communication and progress in general. It's not just a language barrier, it's a cultural barrier. One that exists even between people who speak the same language. (Don't know if the social media movie scene with Zuckerburg being reprimanded by Harvard was based on real events or pure fantasy, but that's a good example)

So he ignored some squiggly red lines, maybe his command of English is marginal. Maybe he's worried about bullets possibly flying over his head in a few minutes or in a situation that many of us in the west couldn't fathom. I've had to communicate in Spanish before and I know I probably slaughtered the grammar, spelling and more, but at that time I was trying to convey an important message. Fortunately the people I was speaking with were very kind and patient. They listened and somehow understood the sentences and symbols I had cobbled together.

We have this whole attitude that if someone doesn't fit our cultural context in language or behavior, their are somehow inferior, is absolute BS. I have seen programmers with a an accent perceived as being "dumb", while in fact they were far better than their peers. I myself have been subjected to this type of bias, when I forgot to follow some proper decorum somewhere, simply because I was broke and had more important things on my mind. This is typical of out-of-touch monolithic institutions and the type of thinking that goes with it. It's outright absurd and funny, just like my sarcastic comment :)

Re: Facebook vulnerability 2013

#216
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

First, who starts a sentence with the word "ok"? Second, "we have paid out over $1 million..." to "hundreds of reporters..." true that would be 1000000/500 = 200.

How hard can it be to have an algorithmic approach to report submission? That is, please make sure your report is reproducible and/or give a link to video or other media for demonstrating the bug.

Also, given the resources of FB, can't they receive bug info in the natural language of the submitter? Why force everyone to use English? Its not like the FB company suffers for a lack of resources.

And yeesh, not paying out $500? Wow that is cheap.

Re: Facebook vulnerability 2013

#217
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

rffinnegan: am simply thrilled to find someone who works for facebook in a dialogue. I am certainly glad that his issue was resolved, but I have been trying for months to find a route of communication other than your many multiple forms to communicate what has happened to my wife's account that was apparently hacked- who or how can I communicate about this?

Re: Facebook vulnerability 2013

#218
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

I realize this is about a post on Mr. Zukerberg's page, but I am simply thrilled to find someone from faebook in a dialogue. I have been struggling for months to find a way to communicate about my wife's difficulties after her account was hacked. Who- not what form- do I communicate with about that, PLEASE?!

Re: Facebook vulnerability 2013

#219
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

The attention this guy is getting is worth dramatically more than the $500, whether he intended this impact or not.

Re: Facebook vulnerability 2013

#220
post #145

The Social Network - Ad Board Chairwoman: Mr. Zuckerberg, this is an Administrative Board hearing. You're being accused of intentionally breaching security, violating copyrights, violating individual privacy by creating the website, www.facemash.com. You're also charged with being in violation of the University's policy on distribution of digitized images. Before we begin with our questioning you're allowed to make a…

It's funnier when FB points to some fine print and acts like bigger douches then those administrator. I would've half expected FB to have engaged this person in a whole differrent spirit, with all the well publicized "we're cool & paying whitehat hackers" PR & new articles.

Exactly. The tables have turned.
Post reply on HN