8 ms·
"White hat" Facebook hacker gets 8 months in jail
- tstonez 15y ago[Without knowing the full details of the case or proceedings] I don't see how putting this, clearly quite gifted, young person in jail for 8 months is going to help him, Facebook or anyone else for that matter. Surely, there must be other options except jail?! Maybe some form of community service where he would then be an asset rather than a cost to the general public. If he can infiltrate Facebook, I am sure there are government sites and systems with much more sensitive information that he could be testing and identifying security threats. Eight months hard time, plus the stigma of a criminal record, just seem like such a waste.
- veyron 15y agoHe may have found a security hole so disastrous and so ingrained that its easier to jail the kid than to fix the problem.
- troels 15y agoWell, that's true of incarceration in general.
- unreal37 15y agoThe article states that the judge clearly wanted to send a message to other hackers that this type of hacking is not "just fun". To give him a job as a professional security consultant would send the opposite message. Reminds me of the movie War Games.
- koenigdavidmj 15y agohttps://www.facebook.com/whitehat https://www.facebook.com/whitehat Facebook themselves have a policy of tolerance toward white hat hackery (basically `give us a reasonable amount of time before releasing to the public' and `do what you can to protect other users' privacy). I want to hear their side of this.
- nik_0_0 15y agoI found myself wondering if perhaps the 'white-hat' reference is a blunder in the headline. This article woefully lacks any actual details regarding what he did or how he approached communication with Facebook, only stating that he was a white-hat hacker for Yahoo once (which obviously proves nothing).
- skolor 15y agoI searched around a little bit, since I found the lack of details somewhat disturbing. This is the best I found: http://www.seattlepi.com/news/article/Facebook-hack-lands-UK-student-in-prison-3339427.php http://www.seattlepi.com/news/article/Facebook-hack-lands-UK.... From the sounds of it, he broke into an employees account (likely their work computer, possibly further access). I'm speculating, but that makes it sound like he stole some portion of the Facebook source code, coupling that with the "intellectual property" claims. I'm curious about this line, towards the bottom: his intention throughout was to contact Facebook in due course when he had rectified their problems
- ErrantX 15y agoSounds like the classic "but what I would have done..." defence (unless they have backed it up with clear evidence, of course, I didn't check).
- nbpoole 15y agoThe title of this submission is completely inaccurate: the person in question is in no way a "white hat": http://www.guardian.co.uk/technology/2011/aug/17/facebook-hacking-case http://www.guardian.co.uk/technology/2011/aug/17/facebook-ha... > Between 17 April and 9 May he is accused of downloading a computer program "to secure unauthorised access" to Facebook; of attempting to hack into Facebook's "Mailman" server; of using PHP script to secure access to another Facebook server, dubbed "Phabricator"; of sharing a PHP script intended to hack into that Facebook server; and of securing "repeated" access to another Facebook server.
- 15y ago
- machrider 15y agoIs it possible to be a "white hat" hacker if you weren't actually contracted by the target for penetration testing?
- Karunamon 15y agoIndeed. It's all about what you do as a result of your shenanigans. If you, say, leave a discrete note behind that you have a gaping security hole the size of a hallway on your systems, that would be considered white hat, as opposed to say, stealing a bunch of internal emails, code, etc and selling it or putting it out on torrent sites.
- mjdwitt 15y agoFacebook, Mozilla, Google, and lots of other companies encourage this with exploit bounty programs.
- artursapek 15y agoYes. White hat hackers often approach these large companies' white hat programs themselves.
- michaelbuckbee 15y agoThere is obviously a spectrum to this sort of thing, but I know of many people that will just habitually enter javascript alerts into a web services's forms to see what happens. Mostly this is just to evaluate the product and to see if it is trustworthy, but they'll often send along a polite FYI to the site owners letting them know if they have security issues that need addressing. Actions like that: finding vulnerabilities, privately disclosing them, not disrupting the service, are all fairly innocuous things that most reasonable technically savvy people would consider 'white hat'.
- tptacek 15y agoPeople can and will go nuts if you, for instance, accidentally mess up the DOM for their customers by getting an XSS payload cached and redisplayed in e.g. "saved search" results. It sucks, but if your goal is to avoid legal drama, don't test without permission.
- Zarathust 15y agoUsually "white hat" have some kind of responsible disclosure. It seems that this "white hat" did not disclose anything to facebook, then got caught and only then, pretended to be acting for everyone's good. Admitting everything in police custody is NOT responsible disclosure
- Locke1689 15y agoMoreover, he actually accessed files. White hat hacking includes finding vulnerabilities, not using them to actually steal data. This sounds like someone who was accessing Facebook for profit and made up an excuse when he got caught.
- chc 15y agoSounds to me like someone who accessed Facebook for kicks and made up an excuse when he got caught. There's no more evidence that he profited than there is that he was being helpful. I knew a kid back in the '90s who got hauled off a couple of times by the FBI for hacking. He wasn't looking for profit — he just thought it was fun to break into systems.
- ericboggs 15y agoSurprised that Facebook didn't hire this guy on the spot.
- JonnieCache 15y ago"You accessed the very heart of the system of an international business of massive size, so this was not just fiddling about in the business records of some tiny business of no great importance," he said. This is the kind of thing that makes my blood boil.
- smsm42 15y agoWhile it is indeed despicable to imagine that there's a different law for big and small companies, it is long known that the size of actual and potential harm is considered when crime and punishment is being discussed. One would probably get different punishment for stealing $10 and stealing $100K (though if you manage to steal $100M you may actually get away with it, but that's another story). If his lawyer would argue (and a good lawyer probably should) that "he did no harm to anyone, of course it's illegal but he didn't mean to hurt anything and he did not, so let's not throw the book at him" - it could influence the outcome. In this case, the judge didn't buy it.
- JonnieCache 15y agoYou can't compare this to $10 vs. $100000K because the actual damage done here versus him doing the same thing to the servers of a small company is not x10000 the size, if that makes sense. The harm caused in both cases is negligible. I suppose you could count the large amount of time facebook probably had to spend going through their systems to make sure they were clean. Surely the money for their security team was already spent though? Also, isn't messing around with the records of a small business somewhere that probably doesn't even have proper backups actually more potentially damaging than poking at part of a globally distributed, multiply redundant decentralised system like facebook? It was really the way the judge chose to phrase that whole bit that annoyed me to be honest.
- icebraining 15y agoSurely the money for their security team was already spent though? I doubt Facebook's security team is just sitting idly waiting for an attacker to give them something to do. Each hour devoted to this is an hour they can't use for other tasks, besides the possibility of having to pay overtime.
- paulhauggis 15y agoI think this guy is grey hat at best.
- gvsyn 15y agoThis. As soon as data is fetched from the system (that is beyond what's required for the hack), you're headed square into darker territory. To be white hat, you find the vuln, alert the company to it, and that's that. There is no "no, really, here's a load of data I grabbed using it!". White hat is generally hired gun to hack for the good of the site/company, grey not hired, but hacks; black is for the lulz/profit.
- joshmattvander 15y agoSeems ridiculous for a company who has the word "HACK" all over the inside and outside of their office, to put energy into this. Hire the kid and move on.
- freehunter 15y agoIt really depends on the intent and extent of the intrusion, which I don't know. If there was no malicious intent and nothing was irreparably damaged, I'd say yeah, hire him. Even Microsoft, when WP7 was jailbroken, hired the hackers and put them on their openness team. The end result so far is that Microsoft allows "developer unlocks" for non-developers, so sideloading is possible. You'd think tech companies would have learned something from all the retribution the cracker community has laid down in the past few years. If you have security holes, own up to them and fix them. Hire real security teams and have external pen-testing on outward-facing products. And if, after all that, you get breeched still... at least learn something from the attack, and possibly from the attacker.
- daeken 15y agoAs far as I know, once you turn something like this over to the FBI or other authorities, it's out of your control. You've already lit the fuse -- where the rocket goes from there isn't your choice.
- nitrogen 15y agoHypothetically, could Facebook later say, "Oh, actually, we're retroactively granting him access to our systems, so he didn't actually access beyond his authorization"? Or would that get someone at Facebook charged with making a false report to the authorities?
- ferrofluid 15y ago"You accessed the very heart of the system of an international business of massive size, so this was not just fiddling about in the business records of some tiny business of no great importance," he said. How small does a company have to be, where it's ok for someone to "fiddle about" in their business records?
- abraxasz 15y ago"The creation of that risk, the extent of that risk and the cost of putting it right mean at the end of it all I'm afraid a prison sentence is inevitable." I'm not sure what the "creation of that risk" part is supposed to mean. If it refers to the security weakness the hacker uncovered, well as I said the hacker did not "create" it, he merely "found" it. If the risk is the potential disclosure, then what is "the cost of putting it right"? Fixing the security weakness? Well since it was not "created" by the hacker, they are just fixing something that they should have, or would have fixed anyway.. Now I'm not saying that the poor hacker should not go to jail. The article doesn't give much details so I'm not sure he should be called a "white hat". However, I'm not convinced by the argument given by the judge..
- JS_startup 15y ago8 months for this? I thought that was the average length of a sentence given to murderers in the UK.
- bryanh 15y ago> "He added that when Mangham was arrested he made "copious" admissions to police about what he had done." Given the chance, I always bang the "don't talk to authorities" drum. So now you have to wonder, how did his "copious admissions" help him? Seriously, if you are suspected of anything, no matter how innocuous or momentous: Shut. The. Hell. Up. Get a damned attorney. Of course the classic video needs to be linked: http://www.youtube.com/watch?v=6wXkI4t7nuc http://www.youtube.com/watch?v=6wXkI4t7nuc
- wyclif 15y agoUpvoted. Never, ever, talk to the cops.
- DougBTX 15y agoWorth noting that this is in the UK, where there isn't an absolute right to remain silent. http://en.wikipedia.org/wiki/Right_to_silence_in_England_and_Wales#Adverse_inferences_from_silence http://en.wikipedia.org/wiki/Right_to_silence_in_England_and...
- mmaunder 15y agoUpvoted too because I preach this to friends/family regularly for serious issues/offenses. However I've talked my way out of around 9 out of 12 speeding fines in various states by being nice and kissing a bit of ass during the last decade. Cops are people too and when they walk up to your window after pulling you over, they may actually be scared. And you know fear leads to anger, anger leads to hate, hate leads to your suffering in traffic court. So the next cop who pulls you over, wind down your window before he gets there, get your drivers license out so you don't have to fish your pockets, put your hands on the wheel so he can see you're not going to blow his brains out and if it's not more than 20 miles over the limit, try admitting guilt and being nice. You might be surprised.
- ErrantX 15y agoThis is excellent advice. The cop that arrests you and pulls you in for questioning is confident and in a position of control. The cop that stops you on the street or in your car is dealing with an unknown potentially dangerous situation. Both are cops. But they are entirely different people.
- wyclif 15y agoSo, what did he break?
- dreamdu5t 15y agoWhat was the exploit?
- noduerme 15y agoWhat it sounds like from the article isn't that he destroyed $200,000 worth of property; it's that $200k is what it cost Facebook to fix a security hole he discovered. Meaning it was money they needed to spend on security before someone with truly malicious intentions found it. Does Facebook seriously think that sending kids to jail is a viable substitute for building good security into their product, or that it will deter future attempts and mean they won't have to spend another $200k next time? More likely, next time they won't know about it, or it will come from a country where they have no power to find the responsible party. They should be on their knees thanking this kid; just another reason to loathe FB, I guess.
- nbm 15y agoIn general, the time to fix an identified security hole is dwarfed by the time to investigate a breech. You have to identify the actions taken by the attacker and correlate events between systems to understand the extent of stolen, destroyed, or modified information, and to ensure that no additional backdoors are left behind. If there is an indication of malicious intent, you also have to interact with law enforcement, discover the identity of the attacker, provide enough information to get a warrant, and so forth. In the whitehat report case, it is as simple as fixing the security hole (and identifying how it got there and how to prevent similar cases) and thanking and rewarding the reporter. However, that wasn't the case here - there was no disclosure, no reason to believe that the attacker was benign, and so an investigation needed to be done. (I work at Facebook, but not in one of the teams involved in this investigation.)
- DenisM 15y agoUsually when news like this comes up there are many comments along the lines of "it's okay, if you behave/do not touch data files/disclose/etc". Bad news folks - this might be ok by you, it's not ok by the law. Unauthorized computer access is jail-time illegal. Do not access any computer or computer network without owner's permission. Seek legal counsel if you're not 100% clear about this, and do it before you get your ass in trouble.
- noduerme 15y agoIt's still fair to say that prosecuting after the fact, if you can find the person responsible, is a pretty shoddy way to run your security. And if you acknowledge that, then it isn't difficult to see the value - both to product and to PR - of choosing to be magnanimous with the benign ones. It's still fair to criticize Facebook for an overreaction which appears to be a way to cover its own ass and deflect attention from the larger issue, namely, that it should have spent to prevent this in the first place, and that nobody knows who else is accessing user information.
- amalag 15y agoIf facebook was involved in helping prosecute this guy, sounds like they were, makes me want to boycott facebook. I only get online once every 2-3 days, but this is too much.
- elemeno 15y agoWhy so? If someone breaks into a company's system, surely the company has a very real obligation to help prosecute the law-breaker? While I can see where there's an argument to made in favour of not prosecuting someone who really is a white-hat hacker (although I'm personally loathe to apply that label to anyone who doesn't have a track record of responsible security research and pen testing as opposed to J. Random Hacker who happens to tell the company after the fact), this guy pretty clearly doesn't fall into that category. While the article was light on the details (being as it was that it was about the sentencing rather than the crime), it does seem as though he both copied some of Facebook's source code or other internal data (as it mentions it being copied to an external hard drive), and it does not seem as though he reported the hole to Facebook along with any details of how he penetrated their system. Given that, why should Facebook not help to prosecute him?
- ck2 15y agoI'm not saying he deserved this sentence but if you have that much talent and energy BUILD SOMETHING OF YOUR OWN. We all understand the tinkering nature of taking something apart to see how it works. But if you are that clever and deep into hacking apart facebook, stop and make your own project with that kind of energy.
- loup-vaillant 15y agoFrom this article, I take that judge McCreath acknowledged that Mangham did not intended to use the data he downloaded. Yet, he talks of "stealing" and "creating a risk" (a huge one, given Facebook's size). But really, how risky is it to keep data in an external hard drive at home? There is a risk, but I'd say not much. Also, there were no theft, since Facebook did not lose any data. And since this "intellectual property" has not been used, Facebook didn't lose a penny over this unwanted duplication. From there, I see only 3 possibilities: (i) judge McCreath did not actually trust Mangham's alleged intentions (I'm not sure I do either), or (ii) he doesn't know enough about computer security, or (iii) other actual damages warrants the sentence (like wasted effort at Facebook's and by the law enforcement). I bet judge McCreath wanted to punish Mangham over (i) and (iii), but it was easier to use (ii) to do so. Or, he doesn't really understand computer security, though that's less likely by the year.
- arice 15y agoI manage Facebook's Whitehat program (https://www.facebook.com/whitehat https://www.facebook.com/whitehat). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly: "If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you." His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.
- bobz 15y ago...insulting to the community of responsible security researchers Bravo.
- palish 15y agoHis attempt to access data... How much data did he access?
- nbm 15y agoI don't know the specific amount of data (as a percentage or bytes) accessed, but I think there are two main reasons you might want to know: If you're wondering whether it affected the privacy of data created by people who use Facebook, the referenced article has a statement that it was not, but it appears this was added after the article was published, so you may have missed it. If you're wondering whether it might be a small amount that a security researcher might collect to verify their report, from what I understand it was more than that.
- lawnchair_larry 15y ago"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you." You think you can sue someone for sharing vulnerability information?
- CHsurfer 15y agoIt seems that the government(s) make a lot of noise about how valiantly they pursue these 'dangerous' hackers, but they won't go near the state sponsored industrial espionage that appears to be coming out of China. Why are we so proud of persecuting our own citizens while we ignore much more damaging actions carried out by another government?
- Volpe 15y agoProbably because it's not a one sided affair and both sides in a (China/US) confrontation have a lot of leverage over each other so a conflict is not in the interest of either party...
- guard-of-terra 15y ago"Sentencing Mangham, Judge Alistair McCreath said his actions could have been "utterly disastrous" for Facebook." So what?? Facebook isn't a British business; why should british judical system should care that much? Even if he was that guilty. Countries should totally quit being unpaid prostitutes to foreign companies.
- TeeWEE 15y agoFacebook you suck. This hacker should be awarded for finding flaws in facebook that could be misused by people who really wanted to do harm. If this hacker didnt find these flaws facebook would haver never known that they have a security flaw. Even better: Facebook should hire this guy! He managed to break into a system that is developer by the "top notch" facebook engineers. Get him out of prison!
- rbanffy 15y agoThere seems to be no evidence to support his allegations he was going to properly disclose his exploits to Facebook. OTOH, there is evidence he misappropriated data and deleted information that could be used to track him. His hat is not impeccable white.
- mickey7 15y agohe is not an ethical hacker. he did not offer his services to facebook to agree on a price. hacked it of his own initiative then disclosed the vulnerabilities with his real identity which means he assumed-expected to somehow benefit, probably not financial - just craved recognition / 'pat on the back' / coolness / job offer acted like a muppet