Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

261–270 of 301 posts

Re: Facebook vulnerability 2013

#261
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

And the lesson we learned here kiddos is?

:Facebook can change, juggle, and ignore your privacy whenever they want to do whatever it is they want to do, but you can't even if it is to help them. So when he found a bug that would be a spammers dream then sell it to the spammers cause they would pay millions where Facebook will dick you out of 500$:

Re: Facebook vulnerability 2013

#262
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Highly unfair that you aren't paying him, TOS or not. Additionally, one could argue that your TOS is bad to begin with. It could be re-written to properly account for this situation. This guy did not have malicious intent - that is the bottom line and all that matters here.

Re: Facebook vulnerability 2013

#263

Earlier quoted context omitted.

"As you can see at https://www.facebook.com/whitehat , in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that…

Yes because if you go to Saudi Arabia and murder someone, you can get away with it because their law is written in Arabic and not English, therefore it doesn't apply to you. Newsflash - it doesn't work that way. The terms can be in Swahili and they still apply to you. Hacking somebody's Facebook to demonstrate a "bug" is black hat and not white hat. This was a real hack of a real person and this guy should be impriso…

Why the hell would a non-US resident be extradited by his home country to the US to face some bogus charges? What's that hillbilly logic? How would US react if foreign countries were asking the US to extradite their own citizens to say, Iran?

Re: Facebook vulnerability 2013

#264
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

You're a fucking idiot. He found a serious error in your system and made a good faith effort to inform you of it despite his language barrier. Instead of showing any sort of gratitude for his discovery and integrity, you chose to dig in your heels and discourage the man and others like him from bringing this to your attention. As a result, you've brought even more damage to the reputation and integrity of Facebook. Way to be an asshole.

Re: Facebook vulnerability 2013

#265
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

This is crap and you're embarrassing yourself and Facebook. You all are lucky that people are sharing this stuff with you guys for $500 instead of on the black market for much more. You're also lucky that people are doing the job that highly-paid Facebook engineers should have done. And if I read between the lines of your post, you and your team think that you're pretty clever. The right thing to do is to cut this gu…

I completely agree!

Re: Facebook vulnerability 2013

#266
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

If you admit that "you should have pushed back asking for more details" than you should also admit that because of that, you are partly liable for the fact that he did go beyond the explicit rules. Now, are those rules also in Arabic? Also, how are you to encourage users to work with you in a quick, efficient manner, if these kinds of things are bogged down with red tape? It's only $500. Perhaps, you should change your rules to make the system for bug reporting easier, efficient, and a bit more egalitarian. Best, LJ

Re: Facebook vulnerability 2013

#267
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Just give the guy a job. He did you a service and if he didn't do it, and others found this hack, they'd hack millions of accounts with personal information and YOU would be held responsible and taken to court! Either pay the man, or give him a job on your security team since he seems to do a better job than half of the team already there.

Re: Facebook vulnerability 2013

#268
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

This is just GARBAGE!!!

He tried to bring this issue to facebook's attention and you guys turned a blind eye to him. He had no choice but to prove to you guys that it was real. So he did what he did.

Yes you guys have a test account and ask people to use it, well atleast pay this guy a portion of what you would have paid him if he would have proved the bug using a test account.

What is going to happen next? The next time a person finds a bug he is going to sale it to the highest bigger and some fool will end up posting on my facebook page embarressing me and my family.

Ever tried contacting Facebook Representatives over the phone and asking them for help with security issues?? I have... It is impossible.... After I would send you guys a ton of emails, no response.

What will likely happen is that Facebook will be taken to court because of the embarressments caused by some hackers and facebook taking too long to correct the issue.

What is just so F'd up is that Facebook could protect their users accounts by paying people a few hundred bucks.

This is just one of my main reasons i am barely on FB anymore. All you guys care about is just the money you all get on advertisments.

Re: Facebook vulnerability 2013

#269
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

That's ridiculous, he didn't use the accounts of real people. Real people wouldn't have elicited the FB security team response within minutes. Real people don't have a "follow" button on their wall. He used the one account that got your attention and was not malicious and he deserves to be paid. You know damn well your terms are meant against maliciousness and spammers. Your stance is petty.

Re: Facebook vulnerability 2013

#270
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Someone may have commented on this: Shreateh could have used/sold the bug to anyone, however he chose to bring it to the attention of FB. Knowing they didn't have enough information [to claim it as a bug or NOT as a bug] from him they could have requested it instead of ignoring it. Despite the fact he used it to post on Z'bergs wall, in his mind he that wa sthe most articulate way for him to show them what it does. Clearly he had no intentions of hacking his account further else he wouldn't have declared who he was. To be outraged by the fact he was desperately bringing this bug to FB's attention is ridiculous and you should be thankful. Instead showing reasons to not pay him are ungrateful and seem deliberate. Dude brought to you a decent hack, sort him out.
Post reply on HN