Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

241–250 of 301 posts

Re: Facebook vulnerability 2013

#241

Wow, upvoting this and I really hope it goes viral and FB gets called out for it. Hopefully he can get the bug bounty he deserves. That's incredibly sleazy of FB to treat him this way.

Just saw this on the front page of Google News, on CNet - looks like we've done it! Good for Khalil for getting the exposure he deserves, and I hope FB backtracks on their idiocy.

Re: Facebook vulnerability 2013

#242
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Whatever! Facebook should pay him for figuring out the BUG in the system.

Re: Facebook vulnerability 2013

#243

Earlier quoted context omitted.

Creating a test account is also kind of a violation of the TOS anyway: "You will not provide any false personal information on Facebook, or create an account for anyone other than yourself without permission. You will not create more than one personal account."

They specifically allow accounts to be created for whitehat purposes at https://www.facebook.com/whitehat/accounts/

Interestingly, from that page:

"Please use a test account instead of a real account when investigating security vulnerabilities. When you are unable to reproduce a security vulnerability with a test account, it is acceptable to use a real account, except for automated testing."

Re: Facebook vulnerability 2013

#244
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

shame on both sides. especially on you mkjones! you failed your responsibility and still blabla!

Re: Facebook vulnerability 2013

#245
post #82

Earlier quoted context omitted.

The situation is the guy in good faith tried to give them repro steps and report a critical bug. Technically he fucked up and didn't do it on a white hat account. No harm was intended or done. They are denying him his reward based on a technicality. If that FB employee is not some lawyer trying to cover their asses, then he should want to pay this person and make it happen via some exception. If they truly didn't car…

They're not "denying him the reward". He demonstrated the vulnerability on someone's actual account. They can't pay people to fuck with other people's accounts. That's not what bug bounties are about. Only on a message board is this hard to understand.

It's understandable it's just not the right mentality towards someone that hacks for profit and bug bounties generally target this ($500 though is hilarious). Effort and time is supposed to be directly related to payout, if it takes more effort and time for less of a payout then the bug reporting is broken.

Re: Facebook vulnerability 2013

#246
post #231

Earlier quoted context omitted.

"Can't pay him" doesn't sound like bureaucracy BS, they don't pay him because he violated the TOS, it's on purpose. We could argue this is stupid and the TOS should be changed, but I can understand why they specify that in the process of reporting a bug you use a test account. Violating a real user privacy to report a bug isn't the proper way to report a bug. If they made an exception with this guy then they would ha…

I disagree. I don't think that making a case by case assessment is opening the floodgates (that argument is exactly what I would call bureaucracy BS). For an exploit of this severity I would expect them to be grateful to someone who was obviously not being malicious regardless of some silly policy.

How would you feel if he found an exploit that allowed him to make all your private messages public and proceeded to report this by leaking your inbox?

I'm no fan of Facebook, but even I can see why they can't ever encourage such irresponsible behaviour.

Re: Facebook vulnerability 2013

#247
post #191

Earlier quoted context omitted.

> Yes, but it is exactly these kind of policies that let enterprises, corporations or organizations look bad. And what do you propose the alternative? A legalised document that outlines every "if this"-"then that", in every language, continent, dialect, etc.? You know how that story goes... > And denying some kid a few hundred bucks even so he found a legit hack just because he didn't follow some proper corporate pol…

What is worse, a harmless facebook message on the CEOs wall or this exploit getting in the hands of malicious spammers.

I suppose I didn't articulate that point correctly. Facebook has a policy that basically says "if you find an exploit don't do it to real people, use a test account to reproduce it". So regardless of whether it's the CEO or Jane Doe, it sets a bad precedence that reproducing the exploit in a (real) environment is a very dangerous thing.

Re: Facebook vulnerability 2013

#248
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

In all fairness, he was also braking the rules of eligibility regarding his country. It states one must love in a country not currently under any US sanctions. I'm pretty sure there is no such country as Palestine in Zuckerbergs map, let alone in the official US world atlas.

Re: Facebook vulnerability 2013

#249
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

you are mistaken as to what is the more important issue here. a friendly demonstration for your consideration because you ignored the lack before or the potential invasion of privacy for the millions of users of facebook? stop being so full of yourselves.

Re: Facebook vulnerability 2013

#250
post #213
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

From a PR perspective, here are the rules: 1. Apologize 2. Pay the guy 3. Spell out in clear,vanilla English the steps to take to report bugs. Don't be a fucking macho/idiot. No need to dig in your heels when u already shot yourself in the foot by saying right out of the gate that it was not a bug.

WELL SAID!!!! FULLY AGREE
Post reply on HN