2 ms·
Shoot, sorry to hear that. I think our attitude has always been pretty good, but the communications channels a few years ago were just not great or easy to fin
by mkjones 15y ago
Shoot, sorry to hear that. I think our attitude has always been pretty good, but the communications channels a few years ago were just not great or easy to find (it sounds like you were stuck on a "my account was hacked" workflow).
We've improved a lot in the last couple years though - we launched the explicit whitehat program in 2010: http://www.insidefacebook.com/2010/12/22/facebook-security-terms-change-removes-risk-for-those-who-report-problems/ http://www.insidefacebook.com/2010/12/22/facebook-security-t... and the bug bounty in July of this year: https://www.facebook.com/security/posts/238039389561434 https://www.facebook.com/security/posts/238039389561434.
Feel free to respond here or let me know if you ever run into similar issues with the whitehat program (hopefully you'll change your mind about no longer reporting security problems!).
- TallGuyShort 15y agoWell like you said, with an explicit whitehat program, I do think that improves things a lot. The main problem was that I didn't know what to do to not come across as the enemy and/or a nuisance. Next time I find a problem - I'll give the whitehat route a shot - so thanks for sharing.