Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

231–240 of 301 posts

Re: Facebook vulnerability 2013

#231
post #169

Earlier quoted context omitted.

"Can't pay him" sounds like bureaucracy BS. I'd argue that it's in their best interest to find a way to pay him. Why make people jump through hoops to report an exploit in your product? However, it also sounds to me like an opportunity for a bug / exploit reporting proxy business that validates, reproduces, and polishes reports in bulk. You most certainly could extract a much higher bounty per report.

"Can't pay him" doesn't sound like bureaucracy BS, they don't pay him because he violated the TOS, it's on purpose. We could argue this is stupid and the TOS should be changed, but I can understand why they specify that in the process of reporting a bug you use a test account. Violating a real user privacy to report a bug isn't the proper way to report a bug. If they made an exception with this guy then they would ha…

I disagree. I don't think that making a case by case assessment is opening the floodgates (that argument is exactly what I would call bureaucracy BS). For an exploit of this severity I would expect them to be grateful to someone who was obviously not being malicious regardless of some silly policy.

Re: Facebook vulnerability 2013

#232

Have to agree with everyone here. The first email gives enough information to base a case on. Enough to simply do a quick search and verify these people aren't friends. I get less information than this from users for a product we support, it's frustrating, but if you don't investigate each lead as a potential you run the risk of having it snowball. Shame on Facebook for dismissing this guy's reward due to the lazy ac…

How does the first email contain enough information to base a case on? All he says is that he can post links to other people's walls. He makes absolutely no mention of not being the target's friend.

Hmm well the implication made sense to me. It would have taken a few seconds to see that these people weren't friends. And all the engineer had to do was ask at least one question to probe for more information instead of a dismissal.

Edit: I'm sure Facebook engineers have something a bit more advanced that this:

https://www.facebook.com/zuck?and=khalil.shr

This link works if they know each other. Try going to your profile and adding ?and=zuck for instance

Re: Facebook vulnerability 2013

#233
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

What is needed is an onion site that offers the same amount of money that facebook does for real facebook exploits. So if Facebook ever does this again, just give them the one shot at it, then go post it to the onion site and get paid.

Re: Facebook vulnerability 2013

#234
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Clear message here- Whitehats don't bother to submit your finds to FB bc they'll find anyway to try to get out of paying!:)

Re: Facebook vulnerability 2013

#235
post #191

Earlier quoted context omitted.

Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad. This is like getting PR advise from a lawyer when there is trouble coming your way. Sure, the lawyer will tell you to repeat "no comment" or deny any involvement over and over again. That might be the right strategy in a legal sense and work out fine when nobody is watching. But you are loosing in the court of…

> Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad. And what do you propose the alternative? A legalised document that outlines every "if this"-"then that", in every language, continent, dialect, etc.? You know how that story goes... > And denying some kid a few hundred bucks even so he found a legit hack just because he didn't follow some proper corporate pol…

What is worse, a harmless facebook message on the CEOs wall or this exploit getting in the hands of malicious spammers.

Re: Facebook vulnerability 2013

#236
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

A very smooth way how copyright thieves do their tricks of the trade. 1st they deny you that your work isn't good or just like here, you say "IT'S NOT A BUG". Then they they get your work, re-edit it and claim that it's their own. On this matter, the whitehat proved that there was a bug, then I'm pretty sure you tried to look further into his report and then figured out to identify the issue. Stole the idea from the whitehat and had it fixed.

Re: Facebook vulnerability 2013

#237
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Rules are meant to be broken. Pay the man, he saved the company money.

Re: Facebook vulnerability 2013

#238
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Does it concern you that ultimately the way the OP got your attention is by posting to MZ's account? Are you sure you'd have ever "discovered" it if he hadn't? I agree that the OP didn't do a great job, but if he's submitting a vulnerability that you really want to hear about and you're ignoring him because of some miscommunication and you ding him for doing the one thing that gets your attention, you're creating an…

It's plain simple corporativism. The guy escalated the issue to their boss and they are not happy. Since this is probably a failure at multiple levels, they will fight back. It really sucks but it's all very unexpected.

Re: Facebook vulnerability 2013

#239
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

This is crap and you're embarrassing yourself and Facebook.

You all are lucky that people are sharing this stuff with you guys for $500 instead of on the black market for much more. You're also lucky that people are doing the job that highly-paid Facebook engineers should have done. And if I read between the lines of your post, you and your team think that you're pretty clever.

The right thing to do is to cut this guy a check for $500 and keep your mouth shut, before people stop reporting security bugs to you.

I know I'm already discouraged--if I find anything, the last thing I want to deal with is a mediocre engineer telling me I didn't fill out the TPS form the right way.

Re: Facebook vulnerability 2013

#240
post #42

Earlier quoted context omitted.

Does it concern you that ultimately the way the OP got your attention is by posting to MZ's account? Are you sure you'd have ever "discovered" it if he hadn't? I agree that the OP didn't do a great job, but if he's submitting a vulnerability that you really want to hear about and you're ignoring him because of some miscommunication and you ding him for doing the one thing that gets your attention, you're creating an…

I think there's a spectrum between letting whitehats do anything (including violating privacy, hurting real user accounts, etc) vs. suing everyone who changes a GET param somewhere. Having a whitehat program with (IMO reasonable) guidelines around not impacting unsuspecting real users seems to me like a good balance and is fairly close to the first part of the spectrum. Obviously I don't love the end outcome, and thi…

But a member of your team was in control of the outcome and messed up. This guy really wanted to make sure that you guys saw the issue in spite of a member of your team screwing up.

You should be rewarding him, not discouraging him.

I know arguing with someone as stubborn as you is useless, but what can I say?

Post reply on HN