11 ms·
Dismissive and ignored? Did you read what he submitted to them? It made no sense. He vaguely stated that there was a bug and his education. His bug report was n
by short_circut 13y ago
Dismissive and ignored? Did you read what he submitted to them? It made no sense. He vaguely stated that there was a bug and his education. His bug report was nonsensical. I am not even slightly surprised they ignored it. And he violated the TOS before he even ever tried to post to Zuckerberg's wall.
- mcphilip 13y agoI don't think it is as cut and dry as that. The reply that 'this is not a bug' showed a lack of concern that the reporter may have been having difficulties correctly submitting information about what would be a very significant defect, if true. A community member taking the time and interest to try and go through proper channels to submit a vulnerability should, IMO, be given more respect than was shown by FB.
- Oculus 13y agoThe problem here is that if FB took every single bug report that they got 100% seriously, they'd never get to the real bug reports, but would just constantly be sifting through the spam. You have to make educated guesses on whether or not a report is just useless spam. This report, the way it read, shoots off a lot of spam flags. I understand why he got dismissed so easily and frankly it is his fault. Nobody has enough staff to hold hands with every single bug submitter regardless of what they send.
- walid 13y agoHardly anyone files a bug for fun. I can't imagine that the masses would file bugs since they don't know what they are in the first place. So when anyone files a bug and attach their name with it, they should be taken seriously. What was more important was that he made it clear that he made a post on someone else's timeline without him being friends with them. Red flag right there.
- madeofpalk 13y agoIn the original thread a Facebook security researcher mentioned that they receive a lot of reports that just aren't bugs ("I view source and my password is there in plaintext!")
- iyulaev 13y agoReplying "this is not a bug" is equivalent to saying "I have read and understood your report, and this is not a bug, it is a feature." First off, it's not a dismissal, it's an acknowledgement. Second, since it's not a bug but rather a feature, then how does using the feature violate the ToS? The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug report guidelines.
- yogo 13y agoExactly! In any kind of support role the number one pattern you observe is that there is always a lack of information. Maybe they are flooded to the point where they really cannot respond to these reports, but from what I've seen over 2/3 of support requests and bug reports require extracting more information from the submitter (even when the form specifically states to provide as much detail as possible with examples). I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).
- Oculus 13y agoI definitely agree with you on this. The response from the engineer could've been better. Some sort of canned response would have worked. IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.
- webvictim 13y agoEmbarrassment is a very relative thing - it looks to me like the majority of comments on this HN post are saying the guy was in the wrong for breaking the TOS and I have to say I agree. Facebook haven't been embarrassed, they've just upheld a policy which says that they won't pay anyone who doesn't play by the rules. Quite fair, in my opinion.
- santosha 13y agoAt USENIX this year, Chris Evans gave a talk about how Google does their VRP. Specifically, he mentioned that there weren't many false positive reports at all, way fewer than he expected there would be. In general, most bugs have something to them. Google has a long history of following up on bug reports with little or nothing to go on, because they take their jobs seriously, and aren't antagonistic to community bug hunters. FB would do well to take a leaf out of their book.
- Oculus 13y agoAs I mentioned in the reply above, the engineer's response could've been many times better, but you have to agree the bug submitter gave them practically nothing to work with.
- shiven 13y agoClearly, any website the size of FB and its huge resources, needs to have an option for bug submitters to submit bugs in their NATIVE language. I bet if the submitter had written the bug report in Arabic, and FB had a professional translator on their security team (with some technical background), things might have been very different and we may not even be having this discussion.
- santosha 13y agoSure, the guy's bug report was terrible. However, the blame is squarely on FB. It's the security team's job to follow up, and to ask for more information if they don't have all the details. Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.
- donohoe 13y agoIt was tough enough to read his post to MZ wall. Clearly there was a language gap and the original bug report suffered as a result. I don't its such a big deal overall.
- ethanbond 13y agoNot figuring out a way to communicate with someone clearly having difficulty communicating is dismissive.
- zobzu 13y agoThe fact that hes not english native and that communication seems hard for him does not mean that: - he did not do all this in good faith. it seems like he genuinely did. Sure there are TOS. But given his english, do you really think he understood them? Of course not. Good faith is a higher morale value (even thus Americans are pretty much used to "if it passed as law/text, morale values are irrelevant, cuz lawyers+money is all that matters) - $500 is less than peanuts for FB. Finding these bugs, even if they have to read into the guy's submission more than usual, is critical for FB. Refusing the bounty means that next time it'll be left unfixed and the bad guys will probably get it instead. All in all, FB's not wrong per say, but it's still a bad move from FB, morally and PR-wise.
- LandoCalrissian 13y agoI think the important part too, is when he technically violated the TOS it was only to get their attention because he was otherwise being ignored. I don't see any reason they should not want to pay him.
- jack-r-abbit 13y agoFWIW, his initial bug report included a link to a post he made on a non-friend's wall. So his first TOS violation was prior to his first attempt to file a bug. The second TOS violation (posting on Zuck's wall) was what got him press time.
- rmc 13y agoOf course "good faith" goes both ways. Facebook has to act in good faith. If they don't, they can't demand others do to them.
- efuquen 13y agoHaving dealt with fellow developers that don't have perfect english or thick accents I think it's quite unprofessional to dismiss someone's complaint without even trying to understand them. It's great for us native English speakers that it's such a dominant language but I think we should all give a little more respect for others where it's clearly not their first language and they're the ones having to go out of their way to communicate with us. I for one am glad I don't have to deal with the bilingualism, with a bit more empathy and less dismissiveness the whole thing could have been avoided.
- lttlrck 13y agoI agree with that completely, however, common-sense should have told him that demonstrating an exploit on third-party was a really dumb idea. It has nothing to do with TOS or language barriers. That is why he isn't getting paid (yet?)
- AsymetricCom 13y agoI think it's more telling that the lack of professionalism displayed by an unemployed developer is the focus, and not the fact that an unemployed developer with a lack or professionalism discovered this hack. This could have been exploited so much worse than it was. Just because he didn't follow unwritten rules of disclosure, doesn't mean that Facebook didn't majorly mess up here. The details of the dev and his behavior are quite trivial, in this case.
- jack-r-abbit 13y ago> Just because he didn't follow unwritten rules of disclosure Are you refering to those unwritten rule that are written here: https://www.facebook.com/whitehat https://www.facebook.com/whitehat
- lewispollard 13y agoSomeone in another thread pointed out that that page doesn't get translated when you set the language to Arabic, seems likely that the guy just couldn't understand the whitehat TOS for that reason.
- thezilch 13y agoI read it, but I don't assume to know the reporter knows how we do things, especially in light of security. The FB responses were absolutely dismissive, and I hope they have learned to, at least, setup some boilerplate responses. Perhaps they already have those, and the responder was simply doing a bad job. I suppose you've never received a bug report (much less a security report) from a client that hasn't the foggiest on even the difference between that blue "e" symbol that has the internets and that "orange swirly thing." Hindsight may be 20/20, but I'd absolutely expect my support or security team to respond with instruction on how and what steps should be taken to diligently report issues. FB did not even try to correct the wrong and dissuade the reporter from abusing users' pages.
- wereHamster 13y agoTo all hackers: If you speak perfect english, please proceed to submit exploits to the FB security team and collect $5k on your way out. If not, post to blackhat forums and receive $10k. Or use the exploit to manipulate FB stock price (I'm sure posting as Mark would move the stock price significantly, if only for a few minutes. But that's enough to earn a lot more than $5k).
- dsl 13y agoHe posted on Mark's wall, not as him. Also, relative to other places you could be spending your time, FB security issues yield relatively little in the blackhat market because of their highly responsive abuse and security teams.
- rmc 13y agoHe posted on Mark's wall, not as him. Sure this bug was like that. But what if someone discovers a bug that allows you to post as the person?
- dsl 13y agoWhat if I was able to send a fake press release on behalf of a company?[1] What if I hacked the Twitter account of a major press organization?[2] Eventually the SEC will require traders to seek independent verification before executing based on social data, or put stops in place similar to the flash crash protections. 1. http://www.sec.gov/news/press/2009/2009-226.htm http://www.sec.gov/news/press/2009/2009-226.htm 2. http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twitter-crash-is-flash-crash-redux/ http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twit...
- whatusername 13y agoHell -- you don't even have to "hack" in to anything to do damage with a Press Release. Just Publish it anyway - most of the press is too lazy to double-check http://www.smh.com.au/business/mining-and-resources/hoax-press-release-sparks-whitehaven-plunge-20130107-2cc47.html http://www.smh.com.au/business/mining-and-resources/hoax-pre...
- rohunati 13y agohis first language is Arabic.
- skeletonjelly 13y agoCan we not get into this again? There are plenty of threads on the validity of this as a bug report.