Earlier quoted context omitted.
I guess next time he should just sell the exploit on the black market then.
If he's the kind who would sell the exploit next time, Facebook isn't interested in rewarding him anyways. Bounty programs are not there to create a more appealing market and out-bid the black hat hackers.
Recent reports on our whitehat program
31–40 of 43 posts
Re: Recent reports on our whitehat program
#32I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.
Re: Recent reports on our whitehat program
#33Earlier quoted context omitted.
If he's the kind who would sell the exploit next time, Facebook isn't interested in rewarding him anyways. Bounty programs are not there to create a more appealing market and out-bid the black hat hackers.
That's exactly what they're there for. They encourage and reward a white-hat culture.
The purpose of bounty is to encourage white hat hackers to challenge one specific application instead of millions of other applications out there that the white hat hacker could spend his/her time on.
So it's saying "Hey...instead of working on that random application why don't you try to hack us because hey you could earn some money too".
It's assumed that the person is a white hat hacker who would not sell the bug in black market anyways, even if there was no bounty.
Re: Recent reports on our whitehat program
#34Re: Recent reports on our whitehat program
#35If you could create your own "non-friend" user mock object and demonstrate the bug, no one has to parse your bad language. He proved the bug through a live test - doesn't it make sense to provide this kind of testing ground to whitehats?
I'm not a hacker, just a plain old developer. But in my world, when I want to explain something, I do it with test-case code and live examples, not through long-winded emails or bug reports.
Re: Recent reports on our whitehat program
#36After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
> lacked the communication skills necessarily to make a useful bug report If anything, he had great communication skills. He overcame a non-native language barrier, while being conversationally blocked, and still made his point clearly. Besides, are communication skills the important skill here? I would say, not. Facebook do not pay white hat hackers at a level appropriate to their skill and work ($1m total? that's a…
Re: Recent reports on our whitehat program
#37This could be soooo easy. Just provide a way to create a temporary account for tests that is not "a real user" and offer it on request. Creating and deleting these should not be a problem - if a report is false, the account won't change anyway.
Facebook already has the ability to create test accounts: https://www.facebook.com/whitehat/accounts/
Re: Recent reports on our whitehat program
#38I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.
Technically, he did follow the rules. Exactly. And was expressly told by a Facebook Security person that what he was doing was not a bug.
Re: Recent reports on our whitehat program
#39It makes way more sense to offer some sort of sandbox to prove bugs to filter this kind of thing (instead of having less-than-stellar bug responders like the "this is not a bug" guy). If you could create your own "non-friend" user mock object and demonstrate the bug, no one has to parse your bad language. He proved the bug through a live test - doesn't it make sense to provide this kind of testing ground to whitehats…
Re: Recent reports on our whitehat program
#40They're not going to pay him. To do so would be legally risky, and set a precedent that could be helpful to actual malicious attackers in civil litigation. "Don't use accounts without accountholder consent" is the single most important term in a bug bounty; if you don't honor it, you're not participating in the bug bounty, but rather doing something else.