27 ms·
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct
by mkjones 13y ago
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure policy), saying that "the bug allow facebook users to share links to other facebook users". Had he included the video initially, we would have caught this much more quickly.
For background, as a few other commenters have pointed out, we get hundreds of reports every day. Many of our best reports come from people whose English isn't great - though this can be challenging, it's something we work with just fine and we have paid out over $1 million to hundreds of reporters. However, many of the reports we get are nonsense or misguided, and even those (if you enter a password then view-source, you can access the password! When you submit a password, it's sent in the clear over HTTPS!) provide some modicum of reproduction instructions. We should have pushed back asking for more details here.
However, the more important issue here is with how the bug was demonstrated using the accounts of real people without their permission. Exploiting bugs to impact real users is not acceptable behavior for a white hat. We allow researchers to create test accounts here: https://www.facebook.com/whitehat/accounts/ https://www.facebook.com/whitehat/accounts/ to help facilitate responsible research and testing. In this case, the researcher used the bug he discovered to post on the timelines of multiple users without their consent.
As you can see at https://www.facebook.com/whitehat https://www.facebook.com/whitehat, in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs. When you are unable to reproduce a bug with a test account, it is acceptable to use a real account, except for automated testing. Do not interact with other accounts without the consent of their owners." Unfortunately, the OP did neither of those things. We welcome and will pay out for future reports from him (and anyone else!) if they're found and demonstrated within these guidelines.
- ibrahimmomani 13y agodude you are talking like a robot , how do you expect a hacker to behave upon your rules and follow your silly (tos) ... really unbelievable.
- dylz 13y agoYour response is incredibly dumb.
- ibrahimmomani 13y agohahahah anther one
- icambron 13y agoDoes it concern you that ultimately the way the OP got your attention is by posting to MZ's account? Are you sure you'd have ever "discovered" it if he hadn't? I agree that the OP didn't do a great job, but if he's submitting a vulnerability that you really want to hear about and you're ignoring him because of some miscommunication and you ding him for doing the one thing that gets your attention, you're creating an environment where you're less likely to find out about these things.
- mkjones 13y agoI think there's a spectrum between letting whitehats do anything (including violating privacy, hurting real user accounts, etc) vs. suing everyone who changes a GET param somewhere. Having a whitehat program with (IMO reasonable) guidelines around not impacting unsuspecting real users seems to me like a good balance and is fairly close to the first part of the spectrum. Obviously I don't love the end outcome, and this would have gone better for all parties if he had used a test account and included some kind of repro instructions (like that video) in the initial report.
- icambron 13y ago>this would have gone better for all parties if he had used a test account and included some kind of repro instructions Clearly, but that's not really something you can control. From your perspective, the other side of the tradeoff with "hurting real user accounts" is "leaving open a huge security hole", not "being mean to whitehats when they screw up". I don't disagree that the guidelines seem quite reasonable prima facie and perfectly fair to to the whitehat in some moral sense, but it's unclear if they're actually working. It boils down to, if you had to choose between finding out about this security hole the way you did or not find out about it at all, which would you choose? How many not-quite-so-aggressive versions of this guy are out there, and how many holes are you leaving on the table? Edited to add: If an important way of finding vulnerabilities is people breaking the rules, then the rules suck, regardless of their intrinsic fairness. It could well be that keeping not-great-communicator/guideline-follower whitehats from reporting some number of bugs through questionable means is actually worth those flaws sticking around. Of course I don't see the daily flow of vulnerability reports to FB (or all the ones that don't ever get reported), so I don't know. But it sounds like a harder question than you make it out to be.
- nwh 13y ago> many of the reports we get are nonsense or misguided Alright, here's a preemptive question for you then. Should a logged in user be able to retrieve the email addresses of an arbitrary friend, regardless of their contact privacy setting being set to "only me"?
- mkjones 13y agoHmm, wanna report at facebook.com/whitehat with more details? Please include repro instructions :).
- nwh 13y agoWill do.
- aestra 13y agoSince when did repo stand for "reproduction" in sofware engineering term? Never heard it around here. East coast.
- arthulia 13y agoThe abbreviation he used was actually "repro", which seems like something that would likely be shortened in an environment where you say it a lot.
- icambron 13y agoRepro, with an r. I've heard it more the last, say, five years than previously. Also East Coast.
- aestra 13y agoThanks also that was a typo. First time I have ever heard it was in these comments. We don't ever use it where I work and I deal with customer reported bugs every day.
- 13y ago
- ryanyeah 13y agoYou're setting a great precedent for people to not use your program and instead, leak out bugs for malicious purposes rather than conform to your dodgy call of ToS. Saying "this is not a bug" doesn't even ask for more information, it cuts off his entire report as FALSE even though you have now admitted the bug was indeed not the intended way for Facebook to operate (people should not be able to post on other people's walls). You seriously need to pay this guy like you promised, especially since he went to all the trouble to report it to you. This is a real low move for a company against this guy who obviously isn't a first-language English speaker. Even if he violated a very minor and insignificant point in your terms, he only did it after you flat-out rejected his report. If you want to encourage reports, you need to be reasonable. If I was this guy, I would be absolutely furious after putting so much work in, doing it the pussy-way and reporting it to the company rather than leaking/selling it for spammers to use, only to get blindsided and literally make it all for nothing.
- prawn 13y agoPay the man. He stumbled around a bit trying to work out how to help, but he brought a flaw to your attention in what he thought was a polite way. If unleashed, this bug could've been used to wreak havoc on Facebook and damage the company's reputation. $500 is the very least FB should be paying.
- nly 13y agoExactly, no harm was intended or done. Somebody posting on your wall doesn't even really impinge on your privacy (Hell, for all intents and purposes Facebook do it for profit). Whatever reward, perhaps reasonably reduced, they pay this guy will be cheaper than any bitterness earned from sitting behind a wall of pedantry with big fat righteous grins on their faces. If they bothered to look at his profile (it's public), they'd see he looks to be a great fan and tinkerer on the Facebook platform.
- tptacek 13y agoIs it even lawful for them to pay people that knowingly invade other people's accounts?
- moocowduckquack 13y ago"As you can see at https://www.facebook.com/whitehat https://www.facebook.com/whitehat, in order to qualify for a payout you must "make a good faith effort to avoid privacy violations" and "use a test account instead of a real account when investigating bugs." I just looked at it, then switched Facebook to Arabic and the TOS is magically still in English (edit - and right aligned really badly as the page evidently expects arabic). If you demand that the TOS is followed by people who do not have English as a first language, try offering a translation. This guy has done you all a service. The chances are that he may not have been able to clearly read the TOS that you wish him to abide by. He should get paid. edit - hmm, was about to check the situation with other languages, however now all the buttons are in arabic so I stopped bothering after the fourth random page.
- tptacek 13y agoThey can't pay people to violate their terms of use or to try to violate the privacy of their users. Even if they wanted to, they're probably not allowed to do that.
- spyder 13y agoSo if a security bug was discovered using methods that are against the TOS then the information about the bug is worthless for them and it's better to sold it elsewhere.
- javisst 13y agoIs your whitehat page translated to other languges? If I select a different language, only the login and footers are translated. I don't think you can reasonably assume that non-English speakers can understand the entirely English whitehat page. Additionally, if you're not logged-in, then the test accounts page doesn't work. It redirects to the same page as facebook.com/whitehat, with no notification that the test accounts page even exists. You should really pay him.
- vehementi 13y agoYou seem to be making an awful lot of excuses to not just pay someone who brought to light a critical exploit. Do you work on the security team or are you a lawyer (maybe with a panicking accountant looking over your shoulder) trying to find fine print reasons say, "Aha! We can save money to our bottom line in this instance!" ? Do you know how silly it looks for you to make these excuses?
- tptacek 13y agoThis is pretty silly. Facebook obviously doesn't care about the dollars here; if anything, I'd imagine they want to be paying more bounties.
- vehementi 13y agoOh man! If only they could fix the situation!
- tptacek 13y agoYou're willfully ignoring what the situation actually is.
- vehementi 13y agoThe situation is the guy in good faith tried to give them repro steps and report a critical bug. Technically he fucked up and didn't do it on a white hat account. No harm was intended or done. They are denying him his reward based on a technicality. If that FB employee is not some lawyer trying to cover their asses, then he should want to pay this person and make it happen via some exception. If they truly didn't care about the money and wanted to pay more bounties they would do this. There is no danger of ruining the integrity of the ToS as another replier suggested. In future incidents they are free to not make an exception. In this case, it was all in good faith and the guy didn't know the proper procedure.
- 13y ago
- tszming 13y agoI agree with you that facebook should not pay for the bug since he violated the policy, instead, facebook can consider offering him an interview opportunity and sponsor him a trip to facebook.
- loceng 13y agoHow didn't he make a good faith effort? It seems that a language barrier may be part of the issue, no?
- loceng 13y agoSo the security person who said "This is not a bug," - what's happening there? If they had guided the guy reporting the bug, asked for more information or directed him to the expected methods for reporting, then this would have likely gone completely differently, right?
- boomlinde 13y agoBy the time he'd reported it, he had already used the exploit to post on a live, non-friend, account. As far as I understand , that's already a violation of the TOS.
- loceng 13y agoIt's fairly obvious he didn't understand the whole whitehat accounts he should have been using. English isn't his first language, so should we fault the guy for that - or Facebook who's an international company - with 1+ billion users? Or should Facebook own up to that they should probably update their documents - or give the guy a fucking break because they haven't done that? This is where you need REASON to react REASONABLY, and not just use a blanket statement to "make their life easy" in decisions like this. That's lazy and inhumane.
- boomlinde 13y agoThey're not faulting the guy for not having english as a first language. They're not rewarding him because he broke the TOS.
- 4rt 13y agojust pay the guy, it's $4k. the language barriers are enough to justify any mistakes made in conforming precisely with the t&cs. he didn't abuse the hack. he reported it to you. pay him tbh.
- rogerbinns 13y agoYou apologise and pay the guy. Then you write it up as a public case study in very simple English. At each step point out what he should have done. That means the next people know what to do, and everything comes out positively from this. At the moment the loud and clear message is that there are far more welcome places than Facebook to report found issues.
- ipogios 13y agoWhat a cunt reply. The slave masters have trained you well.
- boomlinde 13y agoIf the content of the reply is so easily objectionable, you should probably be arguing on the basis of what it says.
- deleted 13y ago[deleted]
- leoh 13y agoYou know, I agree with everything you have said. But couldn't your team be a bit grateful? Though he did post to Zuck's account, he didn't sell the vulnerability as a zero day on the black market, no? A cheap insurance policy, making the payout, cultivating trust with white hats who are nonetheless decidedly a bit bone headed (if not well meaning).
- Itscurt 13y agoSo can I report the same bug under the guidelines and get paid for it, or did you rob him and patch it already? Just pay the man, as a programmer a simple bug like this is a huge no no in the engineers part, and not rewarding the user for his conduct is plain selfish of the company.
- mohamedmansour 13y agoWhy didn't your coworkers reply back asking for more info? This is like the first thing security engineers should do. Look how serious Security Engineers at Microsoft reply back, http://blogs.msdn.com/b/oldnewthing/archive/2011/12/15/10247870.aspx http://blogs.msdn.com/b/oldnewthing/archive/2011/12/15/10247... The right thing to do is add Khalil to the white hat list, and pay him what he deserves. He doesn't speak or read English as you have noticed. Your TOS for white hat page is NOT even translatable. He used real accounts because your team did not care what he had to say. What do you think he should have done? Sell it to the black market?
- Flow 13y agoHow come you didn't have unit tests that tested this scenario on the server-side services?
- e_proxus 13y agoYou could have just replied with the name of a test account and told him to post to that one to verify the exploit. In that way you would avoid any permission problems with real accounts.
- walid 13y agoClever solution. You should go work at faacebook.
- phpluver 13y agof u
- EugeneOZ 13y ago"and we have paid out over $1 million to hundreds of reporters" So each reporter received approx. $1000? That's all?... Heh, Facebook is very greedy company.
- zapadinsky 13y agoMatt you are a lazy spoiled jerk. No doubt.
- dgally 13y agoFrom a PR perspective, here are the rules: 1. Apologize 2. Pay the guy 3. Spell out in clear,vanilla English the steps to take to report bugs. Don't be a fucking macho/idiot. No need to dig in your heels when u already shot yourself in the foot by saying right out of the gate that it was not a bug.
- 2343467457 13y agoWELL SAID!!!! FULLY AGREE
- deconite 13y agoAgreed: Shreateh could have used/sold the bug to anyone, however he chose to bring it to the attention of FB. Knowing they didn't have enough information [to claim it as a bug or NOT as a bug] from him they could have requested it instead of ignoring it. Despite the fact he used it to post on Z'bergs wall, in his mind he that wa sthe most articulate way for him to show them what it does. Clearly he had no intentions of hacking his account further else he wouldn't have declared who he was. To be outraged by the fact he was desperately bringing this bug to FB's attention is ridiculous and you should be thankful. Instead showing reasons to not pay him are ungrateful and seem deliberate. Dude brought to you a decent hack, sort him out.
- pm24601 13y agoBug profit flowchart: You discover a bug on FB just by being a normal user not a "whitehat" security user: * You discovered it by doing "something" to someone else account --> FB will not pay : SELL on black market. * You think the bug isn't really a bug but then it happens again --> FB will not pay : SELL on black market. * You have a life that you don't want to waste with reading through legalese and filling out forms. FB says it is not a bug. Maybe they are right? You don't want to spend the time arguing about it over email --> SELL on black market * You are not a lawyer, or do not do security testing full-time on FB. Or you are a normal user who has not kept on the FB ToS now that we are on the 100 billionth version --> You probably did something wrong. --> FB will not pay : SELL on black market. * You are a US citizen and do not want to be charged with CFAA violations as a hacker --> SELL on black market. Otherwise, FB might give you some money.
- what_what 13y agoFirst, who starts a sentence with the word "ok"? Second, "we have paid out over $1 million..." to "hundreds of reporters..." true that would be 1000000/500 = 200. How hard can it be to have an algorithmic approach to report submission? That is, please make sure your report is reproducible and/or give a link to video or other media for demonstrating the bug. Also, given the resources of FB, can't they receive bug info in the natural language of the submitter? Why force everyone to use English? Its not like the FB company suffers for a lack of resources. And yeesh, not paying out $500? Wow that is cheap.
- rffinnegan 13y agorffinnegan: am simply thrilled to find someone who works for facebook in a dialogue. I am certainly glad that his issue was resolved, but I have been trying for months to find a route of communication other than your many multiple forms to communicate what has happened to my wife's account that was apparently hacked- who or how can I communicate about this?
- rffinnegan 13y agoI realize this is about a post on Mr. Zukerberg's page, but I am simply thrilled to find someone from faebook in a dialogue. I have been struggling for months to find a way to communicate about my wife's difficulties after her account was hacked. Who- not what form- do I communicate with about that, PLEASE?!
- jhonovich 13y agoThe attention this guy is getting is worth dramatically more than the $500, whether he intended this impact or not.
- kehlar 13y agoThis is just bad PR for FB all around. You guys handled this poorly. It's obvious the OP held no ill intentions when he posted on MZ's wall - if anything he seemed to have been driven to it in order to get your attention to a serious bug which your team specifically claimed not to be a bug. Your ungrateful response is typical of a large corporation only out to save face.
- uberknock 13y agoFB should pay him double - or more - no telling how much he's saved the company by revealing the incompetence within the sec team. Too bad FB doesn't have the graciousness to be thankful that the researcher didn't exploit what its security team deemed as dismissive.
- taxwork 13y agoPay the man. He did you a you favor. Stop with all this jibber jabber regarding TOS. He could have used this security flaw to do damage. Instead he posted his name etc. "Rules are Rules" are for people too dumb to think. Pay up. Man you guys and gals who don't want to pay sound like a bunch of parrots. All you know is how to repeat words. THINK
- PoxonFB 13y agoWhat is needed is an onion site that offers the same amount of money that facebook does for real facebook exploits. So if Facebook ever does this again, just give them the one shot at it, then go post it to the onion site and get paid.
- MiloWithNoMIlk 13y agoClear message here- Whitehats don't bother to submit your finds to FB bc they'll find anyway to try to get out of paying!:)
- ravnos 13y agoA very smooth way how copyright thieves do their tricks of the trade. 1st they deny you that your work isn't good or just like here, you say "IT'S NOT A BUG". Then they they get your work, re-edit it and claim that it's their own. On this matter, the whitehat proved that there was a bug, then I'm pretty sure you tried to look further into his report and then figured out to identify the issue. Stole the idea from the whitehat and had it fixed.
- mempko 13y agoRules are meant to be broken. Pay the man, he saved the company money.
- dandyhighwayman 13y agoThis is crap and you're embarrassing yourself and Facebook. You all are lucky that people are sharing this stuff with you guys for $500 instead of on the black market for much more. You're also lucky that people are doing the job that highly-paid Facebook engineers should have done. And if I read between the lines of your post, you and your team think that you're pretty clever. The right thing to do is to cut this guy a check for $500 and keep your mouth shut, before people stop reporting security bugs to you. I know I'm already discouraged--if I find anything, the last thing I want to deal with is a mediocre engineer telling me I didn't fill out the TPS form the right way.
- chana5 13y agoI completely agree!
- aakarpost 13y agoWhatever! Facebook should pay him for figuring out the BUG in the system.
- wilerch 13y agoshame on both sides. especially on you mkjones! you failed your responsibility and still blabla!
- imtheone 13y agoPay the guy! He could have sold it and made lots of money. He was trying to do the right thing. Too bad he had to go to such extremes to get someone's attention.
- Cayfill 13y agoIn all fairness, he was also braking the rules of eligibility regarding his country. It states one must love in a country not currently under any US sanctions. I'm pretty sure there is no such country as Palestine in Zuckerbergs map, let alone in the official US world atlas.
- 2343467457 13y agoyou are mistaken as to what is the more important issue here. a friendly demonstration for your consideration because you ignored the lack before or the potential invasion of privacy for the millions of users of facebook? stop being so full of yourselves.
- semihmasat 13y agoJust empty talk.
- coolbreeze762 13y agoWhat you've just done is create a disincentive for "researchers" to report vulnerabilities to you. The next time Kahlil or someone else finds a vulnerability (and there will be a next time), he/she/they will simply use it and/or sell it. Kahlil did the right thing, at the end of the day, and only broke Facebook protocol in order to get your attention because you ignored his first (legal) notification of said bug. If you don't pay him, you'll have a hard time with credibility in future cases. In addition to all of that, it's the right thing to do. You stay classy Facebook.
- simples 13y agothe real reason why he wont be rewarded, is because the guy who found the bug, is an arab from palestine, who was being ignored on purpose. facebook is jewish. simple.
- andy721 13y agoyour milking this aren't you. I know the truth.
- Howesr1 13y agoWOW. Facebook is proving their scuminess once more. It's $500. Pay the guy you cheap asshat b-tards.
- andrew23950 13y agoFacebook is wrong on this issue. OP made a good faith effort to report the problem. When this failed, he demonstrated the bug in a non-destructive way. He did not post maliciously, nor did he use the bug to obtain confidential information. When the channel set up by Facebook failed, he took the problem to the CEO. I will post this issue to various social media outlets until the OP is fairly compensated. Facebook's actions here are deplorable and discourage users' efforts to report bugs.
- 138zilla 13y agoAnd the lesson we learned here kiddos is? :Facebook can change, juggle, and ignore your privacy whenever they want to do whatever it is they want to do, but you can't even if it is to help them. So when he found a bug that would be a spammers dream then sell it to the spammers cause they would pay millions where Facebook will dick you out of 500$:
- User1101 13y agoHighly unfair that you aren't paying him, TOS or not. Additionally, one could argue that your TOS is bad to begin with. It could be re-written to properly account for this situation. This guy did not have malicious intent - that is the bottom line and all that matters here.
- chana5 13y agoYou're a fucking idiot. He found a serious error in your system and made a good faith effort to inform you of it despite his language barrier. Instead of showing any sort of gratitude for his discovery and integrity, you chose to dig in your heels and discourage the man and others like him from bringing this to your attention. As a result, you've brought even more damage to the reputation and integrity of Facebook. Way to be an asshole.
- lenajd 13y agoIf you admit that "you should have pushed back asking for more details" than you should also admit that because of that, you are partly liable for the fact that he did go beyond the explicit rules. Now, are those rules also in Arabic? Also, how are you to encourage users to work with you in a quick, efficient manner, if these kinds of things are bogged down with red tape? It's only $500. Perhaps, you should change your rules to make the system for bug reporting easier, efficient, and a bit more egalitarian. Best, LJ
- object704 13y agoJust give the guy a job. He did you a service and if he didn't do it, and others found this hack, they'd hack millions of accounts with personal information and YOU would be held responsible and taken to court! Either pay the man, or give him a job on your security team since he seems to do a better job than half of the team already there.
- realistic2013 13y agoThis is just GARBAGE!!! He tried to bring this issue to facebook's attention and you guys turned a blind eye to him. He had no choice but to prove to you guys that it was real. So he did what he did. Yes you guys have a test account and ask people to use it, well atleast pay this guy a portion of what you would have paid him if he would have proved the bug using a test account. What is going to happen next? The next time a person finds a bug he is going to sale it to the highest bigger and some fool will end up posting on my facebook page embarressing me and my family. Ever tried contacting Facebook Representatives over the phone and asking them for help with security issues?? I have... It is impossible.... After I would send you guys a ton of emails, no response. What will likely happen is that Facebook will be taken to court because of the embarressments caused by some hackers and facebook taking too long to correct the issue. What is just so F'd up is that Facebook could protect their users accounts by paying people a few hundred bucks. This is just one of my main reasons i am barely on FB anymore. All you guys care about is just the money you all get on advertisments.
- ozzy2013 13y agoThat's ridiculous, he didn't use the accounts of real people. Real people wouldn't have elicited the FB security team response within minutes. Real people don't have a "follow" button on their wall. He used the one account that got your attention and was not malicious and he deserves to be paid. You know damn well your terms are meant against maliciousness and spammers. Your stance is petty.
- deconite 13y agoSomeone may have commented on this: Shreateh could have used/sold the bug to anyone, however he chose to bring it to the attention of FB. Knowing they didn't have enough information [to claim it as a bug or NOT as a bug] from him they could have requested it instead of ignoring it. Despite the fact he used it to post on Z'bergs wall, in his mind he that wa sthe most articulate way for him to show them what it does. Clearly he had no intentions of hacking his account further else he wouldn't have declared who he was. To be outraged by the fact he was desperately bringing this bug to FB's attention is ridiculous and you should be thankful. Instead showing reasons to not pay him are ungrateful and seem deliberate. Dude brought to you a decent hack, sort him out.
- wyefei 13y agoI worked in FB before so I understand that it's kind impossible to track all the bugs/reports received without clear information provided. However, you can easily tell this guy is humble and not really trying to show off, it's the one who simple wrote "this is not a bug", instead of asking for more information, putting him to actually hack Mark's page. For a better PR, pay him and use this case as an example to teach the future whitehats. FB has low esteem for a reason.
- terra3110 13y agoWith all respect, obviously you was able to reproduce the bug and fix it. Maybe you forget, that language barrier to Palestine can be an issue too, so because you make not clear what you asking for, when he send you back a link. Obviously it is more work to post on Mark Zuckerbergs Page than respond in the way you want. Plus i am very sure, the mistake was on Facebook ends in the first place. I experienced it myself: Since 6 month now i try that Facebook take action, because the break of privacy issues and violation of Facebook terms by a Facebook user - i even not give an response on any channel in tried. If you really do not give him his reward for the Report and keep you informed, than this is extremely unfair from facebook end. IN this case i strongly recommend WhiteHat Hackers in future cases: Do not count on Facebook Team, publish bugs and security issues on Blogs. Obviously the Facebook team give priority not based if a problem is urgent, only how "public" it is. Frank
- walid 13y agoFrank, this is a wonderful rendition of horrible grammar.
- goldfly22 13y agoAlthough, Mr. Shreateh did not follow the Facebook TOC to the letter, as written by Facebook's legal team, he did operate in good faith, according to the Yahoo article, quoted below. Whether or not Facebook legally owes Mr. Shreateh $500 + change or not, the potential PR costs and being "cheap" image is one I would hope does not attach itself to Facebook - leave that to Walmart. "So when a security researcher named Khalil Shreateh from Palestine found a bug that let him post stuff to other people's Walls, he reported it to Facebook. That bug is a spammer's dream. To prove his bug was real, Shreateh posted something to Sarah Goodin's wall, a friend of Facebook CEO Mark Zuckerberg. He then contacted Facebook's security team with the proof that his bug was real, he explained in a lengthy blog post. Facebook has a bounty program where it pays people to report bugs instead of using them or selling them on the black market. In this case, instead of fixing the bug and paying the researcher the $500+ fee, Facebook told him "this was not a bug," according to an email that Shreateh shared. Shreateh says he tried a second time to warn Facebook and when that didn't work, he used the bug to post a message to Mark Zuckerberg's Wall."
- tejli 13y agoLol. Khalil next time post a bug of facebook in the black market and then they will pay better.
- Maxfm 13y agoFacebook - value themselves at $100bn, value their customers and developers as dirt. Very unclassy.
- ramon 13y agoYou guys should hire the guy since he showed the world what a big flaw that was, instead of selling it he kept on trying to tell to the company. He should be seen as a hero by Facebook! Shows how many issues there should be that are not taken into account. BTW: English not being the primary language for these folks has not to do with anything, shows how much stereotype there's in being American or not. It's a global world, wake up! BR,
- xd 13y agoExploiting bugs to impact real users is not acceptable behavior for a white hat It's pretty arrogant of Facebook to redefine the meaning of white hat don't you think? Posting to the Facebook founders page to let them know of a security vulnerability is not malicious, plain and simply, not. Trying to steer the embarrassment of your failings because this guy didn't read your TOS is incredibly hypocritical.
- webvictim 13y agoUsing a bug to post to said founder's page against his will is definitely not white hat behaviour. Period.
- xd 13y agoAnd you base that on what? Sending someone a message to give them a heads up on their security, no matter the medium used, is not malicious behavior, if you feel it is .. well, the world must be a very scary place for you.
- frodopwns 13y agoI think we all know the signal-to-noise-ratio on the internet is a bit whack. So it seems entirely plausible that this was all due to an improperly formed submission. That being said I think Facebook could have given the reward and a slap on the wrist at the same time considering the language barrier.
- walid 13y agoConsidering the language barrier, a slap on the wrist is less appropriate. Facebook could have used this opportunity to publicize explaining to Khalil that his bug finding techniques are not in accordance with the guidelines and garner good will by paying him the $500 as an exception to the rule. The media would be frantically covering how facebook in spite of its guidlines decided to thank the person who reported the bug and overlook an apparently innocent mistake. A missed opportunity on facebook's end.
- andygambles 13y agoWhy doesn't Facebook just create a live account that is set-up to see if it can be hacked? Or does that exist and I completely missed the point?
- Adam89 13y agoIn all honesty I think you guys are being extremely harsh with a man that has pointed a huge problem on your website. He has done Facebook a huge favour and instead of paying him, you have the nerve to refer to a TOS not written in his first language as an excuse. This will lead to bad publicity for a multi million dollar company like yourselves. The man looks really poor and if he wanted to he could have made a lot of money selling that exploit to spammers. However he decided to do the ethically right thing, only to be stabbed in the back by Facebook. I cannot believe that a company of your size and magnitude would stoop so low, its pathetic!!!! Just on that basis I will boycott Facebook as your organisation seems to have lost all of its good morals!!!!!
- cybernoodles 13y agoBy him demonstrating something which Facebook clearly stated "...is not a bug" at the time, Facebook can't claim he violated the ToS. If it was not a bug, he was taking advantage of a feature which Facebook gave him the liberation to by stating so. The moment Facebook claims it is a bug, that contradicts what Facebook told him in the email, and thus it is Facebook's fault, not his. Facebook REALLY should not have said "this is not a bug." Facebook then had few options: to leave this as a feature (which is ludicrous), or treat it as a bug and redact what was stated in the email, which means Facebook should pay the damn man. You can't lie in an email and then pull a 180 when it's convenient for you.