3 ms·
I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat https://www.facebook.com/whit
by mkjones 15y ago
I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat https://www.facebook.com/whitehat). Of course, once we've fixed the bug, the reporter is free to write about the exploit, how long it was live, etc.
- aw3c2 15y agoI did not mean details about the exploit but details about what the exploit enabled an attacker to do/see.
- mkjones 15y agoYeah, after it's been fixed the person who discovered it is welcome to post details about what it would allow an attacker to do / see / etc.
- alastair 15y agoI think what the OP is trying to say, is that Fackbook (as the custodian of our private data) should make available a list of resolved exploits such that we may be aware of potential data leaks. Eg - up until today, and for who knows how long, photos you thought were private may have been accessed by undesireables.
- aw3c2 15y agoYes. In my opinion a website that is open and honest about its caring about privacy would do that.