5 ms·
Reading local files from Facebook's server (fixed)
- zachberger 12y agoThe temporary fix wasn't very user friendly. It was a plain text response "Please try again later" when trying to upload a resume.
- franjkovic 12y agoYeah. In the 1 day timeframe between temp and permanent fix you could not upload resume, which is a breaking change for end users. But, I think it was pushed because it was Sunday and Careers team was not on site to properly/permanently fix the bug.
- themartorana 12y agoWell, they had to figure out what was going on with software from a 3rd party vendor. That likely adds overhead. But hey, I'd break all kinds of functionality temporarily to make sure this exploit - which as is explained, looked worse than it ended up being, wasn't actually as bad as (or worse than) it did look.
- franjkovic 12y agoI agree with this, too. Personally, I would probably do the same. A day of breaking small part of site vs killing local file read seems like a good trade.
- ceejayoz 12y agoI'm impressed with the fix turnaround.
- deleted 12y ago[deleted]
- franjkovic 12y agoHN, I am wondering about your thoughts on the $5500 bounty. This is a bug that affected third party system on Facebook's servers, and the network was locked down. I could have gained access to resume analysis software and maybe resume uploads themselves. There was a small to none chance I could get Facebook internal code or binaries. So, was the bounty enough?
- vertex-four 12y agoDid you report it to Facebook, rather than sell it on the market? Yes? Then it was enough, by definition. Honestly, resume uploads are unlikely to be worth much. The resume analysis software either. What information there is worth anything to an unreputable buyer?
- kenko 12y agoIt absolutely doesn't follow that it was enough. Someone might report it to facebook rather than sell it on the market out of principle regardless of the bounty, while still thinking that the bounty is way too low relative to the severity of the issue. (What's more, the size of the bounty might be revealed only after it's been reported.) However, I'm unsurprised to find such reasoning on HN.
- kogir 12y agoActually, if the goal of a bounty program is to get reports instead of wild exploits, the only metric of success is getting the reports. In the case that someone would have reported it for reasons other than the bounty, the bounty is not only too much, but completely wasted.
- Too 12y agoHow can you say it's completely wasted? This guy just blogged about getting $$$ from facebook, and it hit the front page of HN. It might inspire others to also report vulnerabilities. And conversely, if he was looking for bounties and didn't get any there would instead be a front page HN story about facebook not paying bounties.
- styles 12y agoDid anyone else notice a user named Gopher? Go at Facebook?
- 2ddddd22 12y agoGJ Plit