TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Facebook rewarded a 10-year-old for finding Instagram security flaw

233 pointsby vvvvabout 9 years ago

13 comments

Zeimythabout 9 years ago
It makes me happy to see people who find and report bugs rather than hiding and exploiting them. I'm sure the monetary incentive doesn't hurt, either.
评论 #11625203 未加载
评论 #11624350 未加载
评论 #11625996 未加载
评论 #11625956 未加载
danjocabout 9 years ago
$10,000? Not to diminish what this child did in any way, but that is 4x what the person received who obtained access to<p>Static site content<p>Source code<p>SSL key pairs<p>iOS and Android app signing keys<p>iOS push notification keys<p>Email server credentials<p>Twitter, Facebook, Tumblr, Foursquare, and Flickr API keys<p><a href="http:&#x2F;&#x2F;exfiltrated.com&#x2F;research-Instagram-RCE.php" rel="nofollow">http:&#x2F;&#x2F;exfiltrated.com&#x2F;research-Instagram-RCE.php</a>
评论 #11625588 未加载
pbhjpbhjabout 9 years ago
Do Facebook face some sort of liability under COPPA for allowing [condoning?] this under 13 yo - I&#x27;m presuming without verifiable parental consent prior to use - to use their services?<p>Perhaps the time for Facebook to fight COPPA (for better or worse) is coming soon?
评论 #11624767 未加载
评论 #11624871 未加载
ck2about 9 years ago
Trying to remember that other incident, not with facebook, maybe microsoft, where it was a teenager and they wouldn&#x27;t pay them because they weren&#x27;t 18+<p>So good on Facebook (this once).<p>ETA: it was paypal <a href="http:&#x2F;&#x2F;seclists.org&#x2F;fulldisclosure&#x2F;2013&#x2F;May&#x2F;163" rel="nofollow">http:&#x2F;&#x2F;seclists.org&#x2F;fulldisclosure&#x2F;2013&#x2F;May&#x2F;163</a>
Asparagirlabout 9 years ago
Meanwhile, Apple remains one of the only big tech companies to <i>not</i> have a bug bounty program.
评论 #11625584 未加载
评论 #11625008 未加载
blazespinabout 9 years ago
lol: &quot;In 2015 alone, 210 researchers received $936,000 with an average payout of $1,780.&quot;
评论 #11624493 未加载
satyajeet23about 9 years ago
Damn, facebook paid for a warm fuzzy PR moment.<p>The bug is worth $100.
topbruabout 9 years ago
Any details on how it worked?
评论 #11624510 未加载
tpallarinoabout 9 years ago
That&#x27;s awesome. Good for this kid.
ldom22about 9 years ago
jesus when I was 10 years old I was barely programming on actionscript, which is now dead. Now at 28 I can&#x27;t even make that kind of money in an entire year
altozabout 9 years ago
Anyone else see this headline and thought, &quot;Some government gave them a 10-year-old?&quot;
评论 #11624798 未加载
评论 #11624897 未加载
评论 #11624831 未加载
评论 #11624795 未加载
azinman2about 9 years ago
Payed out to over 800 researchers? Wow that&#x27;s a lot of security bugs. I wouldn&#x27;t have guessed so many were possible. Imagine if they didn&#x27;t have such a program!
porterabout 9 years ago
Awesome kid, but how was this risk only worth $10k to facebook? Needs a few more zeros behind it.
评论 #11624596 未加载