Live data from Hacker News

Facebook vulnerability 2013

khalil-sh.blogspot.com

291–300 of 301 posts

Re: Facebook vulnerability 2013

#291
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

I think we all know the signal-to-noise-ratio on the internet is a bit whack. So it seems entirely plausible that this was all due to an improperly formed submission. That being said I think Facebook could have given the reward and a slap on the wrist at the same time considering the language barrier.

Considering the language barrier, a slap on the wrist is less appropriate. Facebook could have used this opportunity to publicize explaining to Khalil that his bug finding techniques are not in accordance with the guidelines and garner good will by paying him the $500 as an exception to the rule. The media would be frantically covering how facebook in spite of its guidlines decided to thank the person who reported the bug and overlook an apparently innocent mistake. A missed opportunity on facebook's end.

Re: Facebook vulnerability 2013

#292
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

You could have just replied with the name of a test account and told him to post to that one to verify the exploit. In that way you would avoid any permission problems with real accounts.

Clever solution. You should go work at faacebook.

Re: Facebook vulnerability 2013

#295
post #77

Earlier quoted context omitted.

Again: how exactly do you propose that they write a policy that compensates people for violating the security of their users? Not the security of Facebook, but the integrity of their actual users. We all know this person had good intentions. But good intentions aren't always enough. Facebook doesn't appear to be freaking out at him. They just can't pay him for having demonstrated a vulnerability by hacking someone's…

Not sure what you mean by "again". > They just can't pay him for having demonstrated a vulnerability by hacking someone's account. I don't see why that is. They already provide the following caveat: > When you are unable to reproduce a bug with a test account, it is acceptable to use a real account, except for automated testing.[1] So I don't think there's some kind of legal issue there, if that's what you mean. And…

He didn't try to reproduce the bug with a test account though. If he had and it hadn't worked, the fact that he then used a real account would've been acceptable.

Re: Facebook vulnerability 2013

#296

Earlier quoted context omitted.

> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? This is like... the textbook definition of a hack. > however if you have a human making decisions, and not just a drone following written orders, then the ability to make compromises exist. Just no one at Facebook wants to engage and be human it seems. I love that this statement is downthread of a Facebook engineer's comment…

>> Firstly, no idea how you can conclude he hacked an account. A bit strong of language there? >This is like... the textbook definition of a hack. Perhaps of "hacking FB", but he didn't "hack an account". I don't see what the problems are for FB here. They have a moral obligation to reward him for reporting this bug, especially since their ToS are apparently not available in Arabic. Claiming that he showed any sort o…

Facebook really doesn't need to save $10k by not paying this guy. It's about upholding the terms and not setting a precedent.

The blackhat market for Facebook exploits is not huge because the product is centrally controlled and can be patched at any time. It's not like 0-days for products with individual installations that aren't centrally controlled with forced updates - those are clearly valuable.

Re: Facebook vulnerability 2013

#297
post #123

Earlier quoted context omitted.

"Paying people to fuck with people's accounts" is a pretty dishonest way to frame this.

He didn't f * up Zuck's account. Just making a wall post on some account doesn't f * that account in any way.

It's still a violation of privacy though, and these are viewed as serious by the ToS.

Re: Facebook vulnerability 2013

#298
post #284
post #34

Earlier quoted context omitted.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

Exploiting bugs to impact real users is not acceptable behavior for a white hat It's pretty arrogant of Facebook to redefine the meaning of white hat don't you think? Posting to the Facebook founders page to let them know of a security vulnerability is not malicious, plain and simply, not. Trying to steer the embarrassment of your failings because this guy didn't read your TOS is incredibly hypocritical.

Using a bug to post to said founder's page against his will is definitely not white hat behaviour. Period.

Re: Facebook vulnerability 2013

#299
post #284

Earlier quoted context omitted.

Exploiting bugs to impact real users is not acceptable behavior for a white hat It's pretty arrogant of Facebook to redefine the meaning of white hat don't you think? Posting to the Facebook founders page to let them know of a security vulnerability is not malicious, plain and simply, not. Trying to steer the embarrassment of your failings because this guy didn't read your TOS is incredibly hypocritical.

Using a bug to post to said founder's page against his will is definitely not white hat behaviour. Period.

And you base that on what? Sending someone a message to give them a heads up on their security, no matter the medium used, is not malicious behavior, if you feel it is .. well, the world must be a very scary place for you.

Re: Facebook vulnerability 2013

#300
post #34
post #28

Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…

By him demonstrating something which Facebook clearly stated "...is not a bug" at the time, Facebook can't claim he violated the ToS. If it was not a bug, he was taking advantage of a feature which Facebook gave him the liberation to by stating so. The moment Facebook claims it is a bug, that contradicts what Facebook told him in the email, and thus it is Facebook's fault, not his. Facebook REALLY should not have said "this is not a bug." Facebook then had few options: to leave this as a feature (which is ludicrous), or treat it as a bug and redact what was stated in the email, which means Facebook should pay the damn man. You can't lie in an email and then pull a 180 when it's convenient for you.
Post reply on HN