Earlier quoted context omitted.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
I think we all know the signal-to-noise-ratio on the internet is a bit whack. So it seems entirely plausible that this was all due to an improperly formed submission. That being said I think Facebook could have given the reward and a slap on the wrist at the same time considering the language barrier.
Facebook vulnerability 2013
291–300 of 301 posts
Re: Facebook vulnerability 2013
#292Earlier quoted context omitted.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
You could have just replied with the name of a test account and told him to post to that one to verify the exploit. In that way you would avoid any permission problems with real accounts.
Re: Facebook vulnerability 2013
#293Re: Facebook vulnerability 2013
#294Re: Facebook vulnerability 2013
#295Earlier quoted context omitted.
Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…
Not sure what you mean by "again". > They just can't pay him for having demonstrated a vulnerability by hacking someone's account. I don't see why that is. They already provide the following caveat: > When you are unable to reproduce a bug with a test account, it is acceptable to use a real account, except for automated testing.[1] So I don't think there's some kind of legal issue there, if that's what you mean. And…
Re: Facebook vulnerability 2013
#296Earlier quoted context omitted.
> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? This is like... the textbook definition of a hack. > however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems. I love that this statement is downthread of a Facebook engineer's comment…
>> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? >This is like... the textbook definition of a hack. Perhaps of "hacking FB", but he didn't "hack an account". I don't see what the problems are for FB here. They have a moral obligation to reward him for reporting this bug, especially since their ToS are apparently not available in Arabic. Claiming that he showed any sort o…
The blackhat market for Facebook exploits is not huge because the product is centrally controlled and can be patched at any time. It's not like 0-days for products with individual installations that aren't centrally controlled with forced updates - those are clearly valuable.
Re: Facebook vulnerability 2013
#297Earlier quoted context omitted.
"Paying people to fuck with people's accounts" is a pretty dishonest way to frame this.
He didn't f * up Zuck's account. Just making a wall post on some account doesn't f * that account in any way.
Re: Facebook vulnerability 2013
#298Earlier quoted context omitted.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
Exploiting bugs to impact real users is not acceptable behavior for a white hat It's pretty arrogant of Facebook to redefine the meaning of white hat don't you think? Posting to the Facebook founders page to let them know of a security vulnerability is not malicious, plain and simply, not. Trying to steer the embarrassment of your failings because this guy didn't read your TOS is incredibly hypocritical.
Re: Facebook vulnerability 2013
#299Earlier quoted context omitted.
Exploiting bugs to impact real users is not acceptable behavior for a white hat It's pretty arrogant of Facebook to redefine the meaning of white hat don't you think? Posting to the Facebook founders page to let them know of a security vulnerability is not malicious, plain and simply, not. Trying to steer the embarrassment of your failings because this guy didn't read your TOS is incredibly hypocritical.
Using a bug to post to said founder's page against his will is definitely not white hat behaviour. Period.
Re: Facebook vulnerability 2013
#300Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…