5 ms·
Facebook bug hunter paid $10K by community, not company
- yogo 13y agoNot a bad pay day for a critical bug. Forget the black market, hypothetically speaking I wonder how much an ad agency would have paid for something like this if they can use/abuse it for a week before fb catching on (assuming the agency is unscrupulous).
- Raphmedia 13y agoImagine... being able to post ads on anyone's timeline! Now THAT is something you could make profit with!
- aroch 13y agoI'm happy for the guy and all, but Facebook is doing the right thing by not paying the bounty. They specifically bar messing with real user data, while they could have handled the original report better that's still not justification. If you bend the rule once, everyone will want you to bend the rule "just one more time" for them.
- fixxer 13y agoI haven't been paying close attention to this, so forgive the ignorance if I'm wrong: didn't he try to use the correct channels, but was turned away?
- yebyen 13y agoThe big idea as I understand it is: He proved the bug on a live account instead of one of the prescribed test accounts He reported it as "this is a bug" not as "this is the procedure to use in order to reproduce the bug" He demonstrated critical inability to report the steps required to reproduce the bug. It must get to the point where this money faucet receives hundreds of people submitting "bugs" where their friend has really left their account logged in and it's been exploited via social engineering, or some other "not a bug", so bugs are closed when they're submitted with not enough information. I understand and subscribe to this strategy myself.
- thezilch 13y agoYou missed the part where FB -- admit to and are fixing -- lack any process to deal with those that are either not aware or don't understand the process. At no point do they instruct the reporter that it'd be helpful to provide more steps and that he should not be using live accounts to demonstrate the PoC. Nay, they merely shrugged him off and stated his actions were "not a bug."
- yebyen 13y agoYou know, I went looking for help on something this morning (why does ntop crash so much?) and at first all I could find was a post asking a similar question, and a reply about how to ask the question better. The GP replied (paraphrased) "there are a lot of posts on this board asking for help and 95% of the replies are about how to ask the question better. You would do well to try and read between the lines a little bit, just try interpreting and answering some questions instead of just posting all about how poorly the questions are asked." The point is, that guy wasn't offering money. He was supporting free software. I agree it's easy to make a blanket response for posts not providing enough information, but if they can't fill out the form correctly enough for the reviewer to duplicate the result, why should they get the money? Just to close the loop, I did find another post eventually where the author explains he "is aware" that ntop crashes frequently when it's configured to monitor multiple interfaces, and you should use the SVN builds since they are more robust. The bug still exists in FreeBSD and I update my ports tree every day. Searching for "ntop quits" again to put some dates on these posts, I see the complaint was in 2003 and the post addressing my issue was in 2011. I guess it still hasn't been fixed, but the software is still well-known. Anecdotes are like...
- fixxer 13y agoFrom that description, he sounds smart, but not well versed in proper protocols. Seems like there should be a way to filter such bug reports (a web form?).
- aioprisan 13y agoThat's completely inaccurate. He responsibly disclosed the bug but Facebook security didn't have the right privacy settings turned on and was completely unresponsive to a huge security hole. So he did something non-malicious to get their attention and it was fixed in 5 minutes. See how that works?
- deleted 13y ago[deleted]
- andrewvc 13y agoThe whole point was that the legitimate channels all ignored him, so he had to take it one level further.
- aroch 13y agoNo, please go read what happened. He messed with real user data prior to to his attempted reporting of the bug. In fact the only thing he sent to the FB team was a link to a real user who he had messed with
- jack-r-abbit 13y agoThis. It is really starting to piss me off that nearly every article so far fails to mention that he messed with a real user account BEFORE he even tried to report the bug. This matters because this (messing with real users) is why FB isn't paying him. Sure FB handled the poorly written "bug report"... poorly. But he was already not going to get paid before he even sent the bug report.
- philliphaydon 13y agoFrom my understanding he messed with real accounts when Facebook didn't take the issue seriously, shrugging him off rather than discussing with him. Facebook should have rewarded him. Instead turning him away only makes a white hat hacker turn black hat and sell the exploit to the back market for far more than he would have initially got from Facebook.
- aroch 13y agoNo, he messed with real user data and then attempted to report it. Even if the FB employee had followed up correctly with him, he's still have broken the rule.
- thezilch 13y agoYes, he messed with real data, but he appears to have no idea that is a problem, given the blog post that spawned these numerous threads about the events that transpired. FB did not follow up with him; did not explain the rules; he had no idea he had wronged anyone and thus expected a bounty (Re: his blog post to the public). FB could have avoided all of this and probably without the bounty; they could have explained the rules better and made sure he understood why no bounty was plausible.
- aroch 13y agoFrom his blog post: i report that exploit through whitehat --> www.facebook.com/whitehat So he clearly found the whitehat page. While English may not be his first language he clearly has some higher level understanding. The phrasing of "don't mess with data" is pretty clear: make a good faith effort to avoid privacy violations And if you look at testing accounts, it's also quite clear (emphasis mine): Please use a test account instead of a real account when investigating bugs. When you are unable to reproduce a bug with a test account, it is acceptable to use a real account, except for automated testing. Do not interact with other accounts without the consent of their owners.
- thezilch 13y ago
- jwcrux 13y agoI completely agree. It's not like Facebook didn't pay just because they didn't feel like it. They couldn't pay without rewarding a blatant violation of their ToS. If they paid once, then they would have to start paying any researcher who abused the vulnerability before reporting it.
- diminoten 13y agoDid anyone here donate to this guy? If so, can you explain why you did it?
- dspillett 13y agoI didn't, but I suppose many have facebook accounts and would prefer people like him keep giving information about exploits to facebook instead of selling the information to the highest bidder as a "zero day" or just leaving it unfixed so someone less scrupulous can find it and use/sell it for nefarious means. It could also be people who like to see facebook and/or its figure head with egg on face, who want to encourage this fellow (and others) to mess with Zuckerberg's profile again for that entertainment value.
- alttag 13y agoI also didn't, but some of the articles on the subject paint "the guy" as a down-on-his-luck hacker in developing country and ancient computer hardware trying to do the right thing. It's presented as almost a charity donation or a scholarship to someone in less than affluent circumstances.