Live data from Hacker News

Recent reports on our whitehat program

facebook.com

41–43 of 43 posts

Re: Recent reports on our whitehat program

#41
post #40
post #34

They're not going to pay him. To do so would be legally risky, and set a precedent that could be helpful to actual malicious attackers in civil litigation. "Don't use accounts without accountholder consent" is the single most important term in a bug bounty; if you don't honor it, you're not participating in the bug bounty, but rather doing something else.

I don't see why paying him would necessarily have legal consequence: Facebook could make a discretionary payment while making it clear it's outside the scope of the bug bounty terms (indeed, by stating that he was doing something else).

Should (will) the next person to post on MZ's wall expect a "discretionary payment" for "doing something else"?

Re: Recent reports on our whitehat program

#42

Earlier quoted context omitted.

Technically, he did follow the rules. Exactly. And was expressly told by a Facebook Security person that what he was doing was not a bug.

His initial bug report included a link to a post he made, using the exploit, on a user's account that was not a friend. The timeline of all that makes it very clear that he violated the TOS, thus the whitehat program rules, prior to reporting the bug.

I know the timeline. As explained by the security person at Facebook, it was not a bug. They were mistaken. However, the fact is, he wasn't penalized for that incident. Rather, the incident with MZ's account.

So, by statement still stands. Unless you want to contend that we should assume we know better than Facebook Security and ignore what they says is and isn't a violation/bug?

Re: Recent reports on our whitehat program

#43

Earlier quoted context omitted.

His initial bug report included a link to a post he made, using the exploit, on a user's account that was not a friend. The timeline of all that makes it very clear that he violated the TOS, thus the whitehat program rules, prior to reporting the bug.

I know the timeline. As explained by the security person at Facebook, it was not a bug. They were mistaken. However, the fact is, he wasn't penalized for that incident. Rather, the incident with MZ's account. So, by statement still stands. Unless you want to contend that we should assume we know better than Facebook Security and ignore what they says is and isn't a violation/bug?

You said: Technically, he did follow the rules. Exactly.

But the rules exactly say not to mess with real users. So there is not really any "technically following the rules" when he so clearly did NOT follow the rules.

Despite the many headlines talking about the guy who hacked Zuckerburg's Facebook account, I am unaware of any report that specifically calls out the violation of Zuck's account as the reason he is not getting paid. What I've seen are simply citing the fact that Facebook will not pay the bounty if you mess with real users, per the whitehat program's rules. He messed with a real user prior to Zuck... so one can rightfully assume that even if he had not messed with Zuck, he still would not have been paid the bounty. But he also would not have received the press he did.

Post reply on HN