Live data from Hacker News

Security Community Raises Money for Researcher Snubbed by Facebook Bounty

wired.com

31–37 of 37 posts

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#31

Earlier quoted context omitted.

How will that solve the problem? Great, he'll have a wallet full of bitcoins. How many vendors in Palestine accept them as payment for goods & services?

He can still get online stuff with it. Online subscriptions. Video games. Pornography. Etc.

He could have been gifted online stuff anyway. Get an account, send him the password.

Bitcoins for these services add nothing other than some extra % costs when using them, and still don't solve the problem of getting physical goods where he is.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#32
post #27
post #13

Going to research it a bit to make sure he will get the funds and then I am also donating http://www.gofundme.com/3znhjs I am concerned "gofundme" will not be able to pay out to Palestine , I don't think paypal will work there and I don't even think USPS will deliver there? I know Israel will not allow Palestine to mail out internationally. update: they will NOT likely be able to pay out https://gofundme.zendesk.com/…

Where there's a will, there's a way. They'll be able to get him the money - it just might not be through Paypal.

Yes, I realize (and encourage) that individuals will help him.

But I don't think gofundme will be able to pay out and therefore everyone's donations will have to be refunded.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#33
post #20

I don't understand how someone could discover a security exploit in the first place without breaching the Facebook ToS. Doesn't that give them a getout for anything that's reported to them?

facebook have a well-established program to allow anyone to look for security-related bugs. There are indeed terms and conditions associated with it however, including not interfering with real data/people.

Terms and conditions which are only available in English.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#34
post #23

nice. he made the world a safer place. else { //Meanwhile somewhere in the black market $parent->postFacebook("I'll be early from work today and have lost my key. Leave the key in the flowers."); $child->postFacebook("Ok, no problemos."); }

He hadn't managed to actually impersonate another user, just post on someone's wall who hadn't friended him. Personally, I wouldn't leave my keys in the flowers because a random person I didn't know posted it on my wall.

You wouldn't, but some kid might.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#35
post #33
post #20

Earlier quoted context omitted.

facebook have a well-established program to allow anyone to look for security-related bugs. There are indeed terms and conditions associated with it however, including not interfering with real data/people.

Terms and conditions which are only available in English.

They're available in Arabic and many other languages as well: https://www.facebook.com/legal/terms?locale=ar_AR

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#36

Earlier quoted context omitted.

He can still get online stuff with it. Online subscriptions. Video games. Pornography. Etc.

He could have been gifted online stuff anyway. Get an account, send him the password. Bitcoins for these services add nothing other than some extra % costs when using them, and still don't solve the problem of getting physical goods where he is.

Don't you think it would be a bit weird to give the guy a subscription to Anal Magazine? Give him money, even if he can't get it physically, he can still use it online.

Re: Security Community Raises Money for Researcher Snubbed by Facebook Bounty

#37
post #35
post #33

Earlier quoted context omitted.

Terms and conditions which are only available in English.

They're available in Arabic and many other languages as well: https://www.facebook.com/legal/terms?locale=ar_AR

Those are not the whitehat terms at all.

But that doesn't matter since the argument was ridiculous in the first place. If you cannot understand or read rules, that doesn't meant they don't apply to you. Also, he understands English very well.

Post reply on HN