Live data from Hacker News

Recent reports on our whitehat program

facebook.com

31–40 of 43 posts

Re: Recent reports on our whitehat program

#31
post #24
post #11

Earlier quoted context omitted.

I guess next time he should just sell the exploit on the black market then.

If he's the kind who would sell the exploit next time, Facebook isn't interested in rewarding him anyways. Bounty programs are not there to create a more appealing market and out-bid the black hat hackers.

That's exactly what they're there for. They encourage and reward a white-hat culture.

Re: Recent reports on our whitehat program

#32
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

Technically, he did follow the rules. Exactly. And was expressly told by a Facebook Security person that what he was doing was not a bug.

Re: Recent reports on our whitehat program

#33
post #31
post #24

Earlier quoted context omitted.

If he's the kind who would sell the exploit next time, Facebook isn't interested in rewarding him anyways. Bounty programs are not there to create a more appealing market and out-bid the black hat hackers.

That's exactly what they're there for. They encourage and reward a white-hat culture.

Bounty programs do not attempt to compete with black hat markets or outbid black market rates.

The purpose of bounty is to encourage white hat hackers to challenge one specific application instead of millions of other applications out there that the white hat hacker could spend his/her time on.

So it's saying "Hey...instead of working on that random application why don't you try to hack us because hey you could earn some money too".

It's assumed that the person is a white hat hacker who would not sell the bug in black market anyways, even if there was no bounty.

Re: Recent reports on our whitehat program

#34
They're not going to pay him. To do so would be legally risky, and set a precedent that could be helpful to actual malicious attackers in civil litigation. "Don't use accounts without accountholder consent" is the single most important term in a bug bounty; if you don't honor it, you're not participating in the bug bounty, but rather doing something else.

Re: Recent reports on our whitehat program

#35
It makes way more sense to offer some sort of sandbox to prove bugs to filter this kind of thing (instead of having less-than-stellar bug responders like the "this is not a bug" guy).

If you could create your own "non-friend" user mock object and demonstrate the bug, no one has to parse your bad language. He proved the bug through a live test - doesn't it make sense to provide this kind of testing ground to whitehats?

I'm not a hacker, just a plain old developer. But in my world, when I want to explain something, I do it with test-case code and live examples, not through long-winded emails or bug reports.

Re: Recent reports on our whitehat program

#36
post #20
post #5

After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.

> lacked the communication skills necessarily to make a useful bug report If anything, he had great communication skills. He overcame a non-native language barrier, while being conversationally blocked, and still made his point clearly. Besides, are communication skills the important skill here? I would say, not. Facebook do not pay white hat hackers at a level appropriate to their skill and work ($1m total? that's a…

$500 for a bug report. that'll be cheaper than a day's work for one of their developers

Re: Recent reports on our whitehat program

#37
post #22

This could be soooo easy. Just provide a way to create a temporary account for tests that is not "a real user" and offer it on request. Creating and deleting these should not be a problem - if a report is false, the account won't change anyway.

Facebook already has the ability to create test accounts: https://www.facebook.com/whitehat/accounts/

If these accounts were internally tagged as security test accounts and were created automatically and a security researcher had no control over them (think honeypots), Facebook could monitor changes and see if anything on these accounts changes that should not. As the security researcher does not control the account unless an attack is successful, Facebook can grade attacks without human intervention. I can't see anything suggesting they have such a system in place.

Re: Recent reports on our whitehat program

#38
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

Technically, he did follow the rules. Exactly. And was expressly told by a Facebook Security person that what he was doing was not a bug.

His initial bug report included a link to a post he made, using the exploit, on a user's account that was not a friend. The timeline of all that makes it very clear that he violated the TOS, thus the whitehat program rules, prior to reporting the bug.

Re: Recent reports on our whitehat program

#39

It makes way more sense to offer some sort of sandbox to prove bugs to filter this kind of thing (instead of having less-than-stellar bug responders like the "this is not a bug" guy). If you could create your own "non-friend" user mock object and demonstrate the bug, no one has to parse your bad language. He proved the bug through a live test - doesn't it make sense to provide this kind of testing ground to whitehats…

The whitehat program page clearly spells out that you should use test accounts and then links you to a place to view/create test accounts: https://www.facebook.com/whitehat/accounts/

Re: Recent reports on our whitehat program

#40
post #34

They're not going to pay him. To do so would be legally risky, and set a precedent that could be helpful to actual malicious attackers in civil litigation. "Don't use accounts without accountholder consent" is the single most important term in a bug bounty; if you don't honor it, you're not participating in the bug bounty, but rather doing something else.

I don't see why paying him would necessarily have legal consequence: Facebook could make a discretionary payment while making it clear it's outside the scope of the bug bounty terms (indeed, by stating that he was doing something else).
Post reply on HN