10 ms·
Facebook PHP Source Code from August 2007
- thrusong 7y agoIt wasn't actually stolen as it says in the README. It was a misconfigured Apache server which leaked raw, unprocessed PHP code. I received the code to home.php and profile.php but I didn't save it at the time (I was very very new to learning PHP and didn't realize the significance of what I was looking at). Still really cool to see.
- ChristianBundy 7y agoI want to be clear: I don't care, and I doubt Facebook cares. But legally, I think this code was stolen. Facebook owns the copyright to the source code, so copying and distributing is theft in the same way that copying and distributing database contents is theft. But again:
- jaywalk 7y agoYour definition of theft is wrong. Legally, this was not stolen.
- shawnz 7y agoAre you a lawyer?
- webkike 7y agoare you?
- ampersandy 7y agoDoes it matter? How is a random person on the internet sufficiently qualified to define theft in a complex domain like digital copyright and intellectual property? You don't have to be a lawyer to be skeptical of what someone says online.
- webkike 7y agoMy point is if they replied “yes” where would you be? It’s not inappropriate to be skeptical but asking a person for credentials online is next to useless.
- nineteen999 7y agoEven if they were a lawyer, lawyers are frequently wrong in their interpretation of law, which is why they argue the relevant points in court, and a judge gets to decide which of them is right.
- disconnected 7y agoYou don't have to be a lawyer to understand that subtraction and multiplication are two completely different operations.
- shawnz 7y agoAre you sure? https://legalbeagle.com/8608294-difference-between-larceny-theft.html https://legalbeagle.com/8608294-difference-between-larceny-t... > In many states, "theft" is an umbrella term that includes all different kinds of criminal taking. This is the case in New York. Under the New York Codes, theft can be any type of taking, like identity theft, theft of intellectual property, theft of services and theft of personal property
- LeifCarrotson 7y agoIf you're a mathematician and not a lawyer you might think those are different operations. But lawyers, judges, and juries have a unique capacity to argue that you're guilty of subtraction even if you only multiplied. To a lawyer, bits have color: https://ansuz.sooke.bc.ca/entry/23 https://ansuz.sooke.bc.ca/entry/23.
- naniwaduni 7y agoYou can totally find a mathematician to convince you that those are the same operation! Probably easier than the lawyer, even.
- krsdcbl 7y agoCopyright infringement and theft are two completely different things, legally. I know specially the film and music industry put a lot of effort to equalise those terms in the media, yet they remain two separate things.
- nicky0 7y agoCopyright infringement =/= Theft.
- therein 7y agoSame happened to me. I knew the significance the moment I saw the `<?php` but force of habit, I had already pressed shift + F5 by the time my brain registered. Somehow never got the code again, maybe some sort of load balancer was leaking something that was cached but just barely.
- tmpz22 7y agoFrom index.php, an if statement for one particular user // Merman's Admin profile always links to the Merman's home if (user_has_obj_attached($user)) { redirect('mhome.php', 'www'); }
- epriest 7y ago"Merman" was an internal project codename, not an individual user. I think it was a very early version of the feature that eventually became "Pages".
- shimylining 7y agoAmazing that they initially wrote this code and now to join FB you need to answer questions based on backtracking and dynamic programming. :) I wonder if they could do the questions themselves back then.
- asdfman123 7y agoI didn't read it carefully and I don't know much PHP, but is the code really that bad? There's all kinds of worse code out there running everything. As long as it's relatively well organized, you can worry about refactoring as you scale up.
- nobleach 7y agoI used to know PHP, and this code is very indicative of the imperative style that was popular during that era. I believe the PHP crowd has mostly gone deeply into OOP. With that said, Facebook mostly worked remarkably well. My bank, on the other hand has their web presence written in Java. And it works about 80% of the time. Sometimes one just has to try twice. So, "good code", "bad code" will always take a back seat to "working code". (Not that I'd want to maintain this beast)
- asdfman123 7y agoI guess what's really at play is whether or not the code is sloppy because the developers are making a conscious decision to not refactor yet, or it's sloppy because they don't know what they're doing. I've found lots of great developers write huge, sloppy, 300 line methods, if it gets the job done. I love clean code, but too much abstraction is a liability unless there's a good reason to introduce it. Part of expertise is knowing when it's okay to break the rules.
- barbarbar 7y agoSo the bank would be better of with php?
- 7y ago
- wonderment 7y agoI always liked Nik's comments and was wondering why he had stopped posting here. https://news.ycombinator.com/threads?id=nikcub https://news.ycombinator.com/threads?id=nikcub https://www.zdnet.com/article/security-consultant-granted-bail-after-hacking-goget-systems/ https://www.zdnet.com/article/security-consultant-granted-ba... https://www.zdnet.com/article/goget-hacker-sentenced-to-400-hours-of-community-service/ https://www.zdnet.com/article/goget-hacker-sentenced-to-400-...
- Supermancho 7y agoI always find this kind of stuff interesting. Albert Gonzales broke into a bunch of my work's servers (for years) at my first job, after a customer of ours pissed him off. I had some AIM coversations and lurked/logged in one of his advertised IRC hangouts. Most of the transcripts went to the secret service, which was very interested in his Credit Card fraud activities (as advertised on IRC). https://usa.kaspersky.com/resource-center/threats/top-ten-greatest-hackers https://usa.kaspersky.com/resource-center/threats/top-ten-gr...
- hyggemonster 7y agoReminds me that they had the poke feature.
- ifaxmycodetok8s 7y agothey still have the poke feature
- joeblau 7y ago> Worth preserving as part of Internet history. Can't Facebook just issue a takedown request and have these files removed?
- riffraff 7y agowhat for? It's not like it would be particularly dangerous to see code which is 13 year old.
- ocdtrekkie 7y agoIt’s worth noting that Windows occasionally is inflicted by discovered vulnerabilities that are over twenty years old. Not sure how applicable that would be to Facebook’s codebase over this much time. But worth noting.
- giarc 7y agoJust look at Swift and all the Cocoa classes. Many are prefixed with NS, which comes from the NeXTSTEP days.
- munk-a 7y agoPretty sure all their code is intensely different now - they did write the HHVM engine in 2011 and I wouldn't be surprised if they ported as much logic as possible to that and added strict typing over it all.
- fkfaduc 7y agoI'm not even sure they could do that. What would be the difference between that and some megacorp issuing a takedown-request for an internal document leaked by the press?
- ceejayoz 7y agoIt wouldn't be worth the cost of the letter. This code's as valuable as a Blockbuster card by now.
- veeralpatel979 7y ago
- alexandercrohde 7y agoOne way to look at this is to say "Hah, how shameful." The other way to look at this is to say "Hah, clearly business success isn't a function of code quality"
- derefr 7y ago> Hah, clearly business success isn't a function of code quality Mind you, early Facebook wasn’t exactly a “tech business”—the code wasn’t making them any money, such that having a bug in the code would make them less money. Really, Facebook only became a “tech business” once they got into 1. Messaging, and 2. Advertising. Then they had SLAs, and breaking those SLAs meant losing users/customers; and their ability to deliver on those SLAs became directly related to the quality of their code.
- prostoalex 7y agoAs a counterpoint, code choices and perceived site slowness contributed to Friendster's and MySpace's decline. Both had messaging and advertising.
- krapp 7y ago>"Hah, clearly business success isn't a function of code quality" They aren't nearly as strongly correlated as many developers might like to believe.
- seppin 7y agoI prefer to think of it as "perfectly coded" projects have 0 commercial value until someone figures out a customer for it.
- danbolt 7y agoI work as a programmer in the games industry and I’ve noticed that frequently as well. Commercially successful games aren’t always a strong indicator of code quality and often it tends to be that the bad code “luckily didn’t matter” in cases of success.
- 7y ago
- rahuldottech 7y ago2013 HN discussion: https://news.ycombinator.com/item?id=6538270 https://news.ycombinator.com/item?id=6538270
- tdevito 7y agoI know it's just two of the files, but taking into account the rest of the pages for the FB app in 2007, it does not seem like a lot of code. One or two people could have written and maintained a project that size. What were all the new hires doing from 2005-2007?
- ahupp 7y agoThe company wasn't very large at that time. Probably less than 100 engineers in 2007. One person could understand the bulk of the codebase in a a reasonable amount of time. There was way more code than you're seeing here though, note all the includes at the top.
- iudqnolq 7y agoCan someone explain to a newbie why this code is so bad? Reading through it it seemed to generally make sense and not be too complicated.
- ceejayoz 7y agoIt's not really bad for the time it was written, but today you wouldn't want to write PHP code like this. Lots of global variables that can clobber each other (if one bit of code, even in one of the includes, redefines $user, everything explodes), no classes, no code autoloader...
- cosmotic 7y agoHow are classes are a sign of superior code? How is an autoloader a sign of superior code? Keep in mind, this is old PHP and those things were new or nonexistent.
- munk-a 7y agoThe lack of `chroot`[1] makes me sad off the bat - for some reason that function seems like a secret, everyone actually wants to use it (or wanted to before autoloading became as easy as it is) but nobody did. Additionally I'd love to see that file split up into smaller chunks simply to lower the scope of thought. It looks like nearly all of those function calls are modifying variables passed by reference instead of resolving the value out via `return` this isn't bad and is indistinguishable at a technical level in terms of functionality, but it's a kind of horrible approach from expressability. They're doing things with datetime that are unsafe and wrong (like assuming 246060 is the number of seconds in a day) but people getting datetime logic wrong is as old as... well time. Oh, and you've got some pretty bizarre looking function signatures - I'm sure there is a reason for this but I'd want to ask some questions about this one... $permissions = privacy_get_reduced_network_permissions($user, $user); It's possible to go through this and nitpick a bunch of stuff, it looks like it's mostly just an older style though. The big problems aren't here though... I'm not seeing any reads into $_POST (and `param_get_slashed` looks like a nice function for sanitizing input) - additionally, I'm not seeing a single line of SQL nor am I seeing any memcached calls, so the data access layer may already be well isolated architecturally. 1. https://www.php.net/manual/en/function.chroot.php https://www.php.net/manual/en/function.chroot.php
- aruggirello 7y ago> is line 89 of search.php valid?? "$user 0 && ..." ? aren't we missing an comparison operator? Good job. And perhaps that's the culprit. Everybody assumed it was a plain syntax error, but I don't think it's possible. Rather, it seems me that: if ($user <something else ... ) { was written here but we'll never know because the browser mistook it for an HTML tag, and the user probably copied page contents instead of saving it. }; if (user_was_working_at_facebook_in_2007()) possibly_confirm('?'); /* lots of missing code may follow... until */ if (who knows what > 0 && ...
- growt 7y agoSo there's an unknown amount of Spaghetti Code still missing from this mess?
- deleted 7y ago[deleted]
- treyp 7y agonot sure what the reason was, but it's simply a missing >. other files were leaked, and you can see the same pattern elsewhere: if ($user > 0 && is_unregistered($user)) searching the web for this comment might be helpful if you'd like more source code: $user can be < 0 in AIM mode, just use 0 there
- warpech 7y agoThis might be due to the code pasted in some markdown editor at a point. This often strips the < and > characters.
- earenndil 7y agoMaybe. I think that's less likely than syntax error, for two reasons. #1, if you look in index.php, there's a < on line 228 and a > on line 258, correctly rendered. Granted, the < is part of a <=, which weakens that argument. #2, if you look at the surrounding code, $user > 0 makes logical sense given what the code is doing (and assuming 0 represents an invalid/nonexistent userid, which I believe it does given that facebook userids increase monotonically).
- jabyess 7y agoFrom the article linked in the gist: > This leak is not good news for Facebook, as it raises the question of how secure a Facebook users private data really is. I don't even think I need to comment on how poorly this has aged.
- trustfundbaby 7y agoCould you elaborate? I thought it was an amazing foreboding of exactly how poor Facebook turned out to be with handling user privacy
- jabyess 7y agoThat's basically what I meant, sorry. It's an insight into what could have been a problem back then, and clearly became a serious problem.
- jszymborski 7y agoSome interesting comments: > // Holy shit, is this the cleanest fucking frontend file you've ever seen?! https://gist.github.com/nikcub/3833406#file-search-php-L72 https://gist.github.com/nikcub/3833406#file-search-php-L72
- deleted 7y ago[deleted]
- sandes 7y agoI think NipAlert of big head had better code.
- sideproject 7y agoIs this Mark Z's code? Wonder why he didn't use a framework and went with pure PHP.
- lubujackson 7y agoI would assume the answer was speed. I was also writing some spaghetti PHP code around 2007 and remember making choices that were the benefit of reducing server stress while making my life harder. No framework was a big one. Remember, Friendster died due to crashing and Facebook, for all its spaghetti code at the time, was remarkably solid and rarely crashed. It is easy to forget how hard the sysadmin side was for a growing startups before we could spin up infinite cloud servers and VC wasn't just an open spigot for anything with growth. Remember the fail whale on Twitter?
- zxcvbn4038 7y agoWhat always strikes me is how sloppy and poorly written commercial code is when it is leaked - esp compared to open source projects. Looks like someone’s CS200 project a lot of the time.
- Lavomk 7y agoLooking at this makes me not missing php but somehow it's like back in time.