Live data from Hacker News

Recent reports on our whitehat program

facebook.com

1–10 of 43 posts

Re: Recent reports on our whitehat program

#3
Facebook, at least send the guy a new laptop.

You don't even have to tell anyone you did it if you are worried about "rewarding non-preferred behavior".

Mute the commercial and watch this video to meet this guy and realize he was trying to help and you were being idiots:

http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-f...

He hasn't worked in two years and his laptop is missing 5 keys.

Re: Recent reports on our whitehat program

#4
I am the only person out there that agrees he shouldn't receive a bounty?!

Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

Re: Recent reports on our whitehat program

#5
After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him.

In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.

Re: Recent reports on our whitehat program

#6
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

> just a case of a foolish newbie who failed to follow the rules

How was he foolish? Also the rules weren't written in his first language. Intent matters[1]. Facebook needs to be the first place people like him go, and be welcoming.

Facebook could do many things that don't involve paying a bounty directly. For example they could make a donation of the same amount to a suitable school or charity in his area.

[1] For example we do that when people are killed http://en.wikipedia.org/wiki/Murder_(United_States_law)#Degr...

Re: Recent reports on our whitehat program

#7
They should pay the guy, not because it's the "right" thing to do, but because it maximises future bug reporting.

If people see that facebook back out of paying for legitimate, reported bugs, they'll seek other options to monetize them.

Re: Recent reports on our whitehat program

#8
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

You have to remember why these bounty programs exist in the first place. The whole point is to discourage people from selling the exploits to more unscrupulous parties. This guy had good intentions and he made a mistake because he wasn't as familiar with the ToS as he should have been. They should warn him about following the ToS in the future, and then they should give him his bounty. Foolish newbies with noble intentions deserve second chances.

Re: Recent reports on our whitehat program

#9
post #5

After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him. In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.

facebook's communication skills were not stellar either ('this is not a bug').

If you are taking reports from users about security problems, treat every one as real until proven otherwise.

Re: Recent reports on our whitehat program

#10
post #4

I am the only person out there that agrees he shouldn't receive a bounty?! Facebook's stance is akin to "we don't negotiate with terrorists". Although obviously this wasn't malicious (or "terrorism"); just a case of a foolish newbie who failed to follow the rules.

> just a case of a foolish newbie who failed to follow the rules

He did follow the rules. Just that he didn't know to express them. And what made you think he is foolish?

Post reply on HN