Earlier quoted context omitted.
They can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.
Creating a test account is also kind of a violation of the TOS anyway: "You will not provide any false personal information on Facebook, or create an account for anyone other than yourself without permission. You will not create more than one personal account."
Facebook vulnerability 2013
211–220 of 301 posts
Re: Facebook vulnerability 2013
#212Note to security response teams everywhere: Not all vulnerability reporters speak perfect English, nor are they all experienced in writing up details on how to exploit issues. It is your responsibility to obtain details from reporters, after the initial report, to avoid situations like this. Facebook should give a bug bounty here, due to their lack of due diligence in following up with the initial responses.
And to go further, Facebook has an office in Dubai. [0] Are you telling me if language was not a barrier, they could not find a single Arabic-speaking employee? They could even save money on the collect calls, if Facebook was not an option. And hats off to Khaled. Hebron is not a fun place to grow up, and making it that far, a B.S. that is, is an accomplishment. I grew up with far more privilege and I am still not sm…
Re: Facebook vulnerability 2013
#213Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#214Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
You discover a bug on FB just by being a normal user not a "whitehat" security user:
* You discovered it by doing "something" to someone else account --> FB will not pay : SELL on black market.
* You think the bug isn't really a bug but then it happens again --> FB will not pay : SELL on black market.
* You have a life that you don't want to waste with reading through legalese and filling out forms. FB says it is not a bug. Maybe they are right? You don't want to spend the time arguing about it over email --> SELL on black market
* You are not a lawyer, or do not do security testing full-time on FB. Or you are a normal user who has not kept on the FB ToS now that we are on the 100 billionth version --> You probably did something wrong. --> FB will not pay : SELL on black market.
* You are a US citizen and do not want to be charged with CFAA violations as a hacker --> SELL on black market.
Otherwise,
FB might give you some money.
Re: Facebook vulnerability 2013
#215Earlier quoted context omitted.
I'm surprised you're not taking him to task for his poor grammar, sentence structure and obvious misspellings. To say "replay" when he means "reply", how the hell did his accent make it into his writing? Quite obviously his reports were ignored. Most certainly, this chap should have followed proper decorum by consistently petitioning Facebook to pay heed, by filling out the necessary forms and ensuring a stamped, sel…
I don't know why you are being sarcastic. I don't make one mention of Khalil's grammar. I understand that everyone's first language isn't english, but Khalil isn't even making an effort to be clear or accurately communicate what the problem is. In the comments of the blog post, Khalil admits that it isn't that he has a poor understanding of the english language, it is just that he doesn't care. > whatever , i dont ca…
Through my sarcasm I was trying to convey the often imperialistic (and in my opinion useless douchebaggery) view we tend to take on certain matters and people, which, I believe, hinders communication and progress in general. It's not just a language barrier, it's a cultural barrier. One that exists even between people who speak the same language. (Don't know if the social media movie scene with Zuckerburg being reprimanded by Harvard was based on real events or pure fantasy, but that's a good example)
So he ignored some squiggly red lines, maybe his command of English is marginal. Maybe he's worried about bullets possibly flying over his head in a few minutes or in a situation that many of us in the west couldn't fathom. I've had to communicate in Spanish before and I know I probably slaughtered the grammar, spelling and more, but at that time I was trying to convey an important message. Fortunately the people I was speaking with were very kind and patient. They listened and somehow understood the sentences and symbols I had cobbled together.
We have this whole attitude that if someone doesn't fit our cultural context in language or behavior, their are somehow inferior, is absolute BS. I have seen programmers with a an accent perceived as being "dumb", while in fact they were far better than their peers. I myself have been subjected to this type of bias, when I forgot to follow some proper decorum somewhere, simply because I was broke and had more important things on my mind. This is typical of out-of-touch monolithic institutions and the type of thinking that goes with it. It's outright absurd and funny, just like my sarcastic comment :)
Re: Facebook vulnerability 2013
#216Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
How hard can it be to have an algorithmic approach to report submission? That is, please make sure your report is reproducible and/or give a link to video or other media for demonstrating the bug.
Also, given the resources of FB, can't they receive bug info in the natural language of the submitter? Why force everyone to use English? Its not like the FB company suffers for a lack of resources.
And yeesh, not paying out $500? Wow that is cheap.
Re: Facebook vulnerability 2013
#217Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#218Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#219Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Re: Facebook vulnerability 2013
#220The Social Network - Ad Board Chairwoman: Mr. Zuckerberg, this is an Administrative Board hearing. You're being accused of intentionally breaching security, violating copyrights, violating individual privacy by creating the website, www.facemash.com. You're also charged with being in violation of the University's policy on distribution of digitized images. Before we begin with our questioning you're allowed to make a…
It's funnier when FB points to some fine print and acts like bigger douches then those administrator. I would've half expected FB to have engaged this person in a whole differrent spirit, with all the well publicized "we're cool & paying whitehat hackers" PR & new articles.