2 ms·
I think what ComputerGuru is saying is that facebook should be liable for security vulnerabilities like the one discovered, not the hacker who discovered. (this
by quackerhacker 13y ago
I think what ComputerGuru is saying is that facebook should be liable for security vulnerabilities like the one discovered, not the hacker who discovered. (this is what I gathered from your comment)
I actually agree to an extent with ComputerGuru. The company deploying the code (facebook) is responsible for any exploits. We don't know if Facebook does consult a security team (given the bounty amounts, I'm sure they have one internally).
The real problem with code though is that bugs will ALWAYS exists. They can get even worse as more people have a hand in the package. I've encountered this alot on projects, where code snippets will either be redundant, over complicated, or (in this case is my guess) will conflict with other pattern checks.
To be honest, I'm actually surprise that we heard about this exploit. I'd almost imagine that most companies would be tempted to have the hacker sign an NDA in order to collect the bounty.
- runn1ng 13y agoYes, I meant it like that. Bugs will always exist and it's stupid to think that Facebook should be liable for bugs that caused nobody any harm whatsoever just because the bug existed.