TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer

189 pointsby chrisdinnalmost 12 years ago

17 comments

chrisackyalmost 12 years ago
Although this is blogspam, it&#x27;s a blogspam that I can actually support...<p>This is being covered a lot more widely because FB didn&#x27;t just pay the guy. I know it wasn&#x27;t about money for FB, but this is easily done a lot more damage then they would have expected and because of their inadequate handling of a single bug report, I can only feel satisfied as I think this will go down as a good case study of how not to be so dismissive with critical bugs.<p>(I still think they should pay the guy, and it should be double the $5k he would have expected to receive).
评论 #6239274 未加载
评论 #6242061 未加载
评论 #6239321 未加载
评论 #6242258 未加载
评论 #6243131 未加载
tptacekalmost 12 years ago
Once again, with feeling:<p>Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can&#x27;t. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook&#x27;s is clear: if you use a real account, <i>you must have the consent of the accountholder</i>. That term isn&#x27;t just there to make the Facebook security team&#x27;s job easier; they also can&#x27;t officially condone people compromising random user accounts.<p>Facebook also operates in a web of contractual and regulatory concerns, including California&#x27;s breach notification laws. Exploitation of security vulnerabilities on Facebook&#x27;s public properties outside of the terms of their bug bounty might be legally more akin to attacks than to pro-bono testing. Further, Facebook obviously needs the ability to reliably enforce their terms, lest they provide attackers with ammunition in a court case if they, for instance, Pastebin large amounts of Facebook user data. &quot;Oh, I was just participating in the bug bounty program; I certainly wasn&#x27;t setting out to sell $CELEBRITY&#x27;s data to a tabloid.&quot;<p>Jim Denaro is an attorney specializing in stuff on this. We talked to him on Twitter this weekend when the story broke, and he said he would have advised against paying the bounty here too. Maybe we can get him to write a blog post.<p>I don&#x27;t know how much &quot;outrage&quot; this has actually generated in the security community (maybe you can find links). The security people I&#x27;ve talked to think what happened makes perfect sense. Facebook didn&#x27;t freak out, the acknowledged the bug report (once they understood it) and fixed the bug. They&#x27;re just not paying a reward, because the bugfinder violated what is perhaps <i>the most important term in the bug bounty</i>.<p>One more thing: people on HN have a lot of strong opinions about Facebook, and while I don&#x27;t share many of them, I understand and respect them. Understand though that the people working on Facebook&#x27;s security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook&#x27;s operating capital.
评论 #6240117 未加载
评论 #6240030 未加载
评论 #6240037 未加载
arnarbialmost 12 years ago
&gt; Shreateh reports he will not, however, receive a bounty for his work — per an e-mail from Facebook, he violated the terms of the program when he hacked Zuckerberg’s account.<p>I think this is wrong. He posted on Sarah Godin&#x27;s wall first before making any report, very clearly breaking the rules FB sets up for its whitehat program. They offer a way to create test accounts for exactly this. Posting on Mark Zuckerberg&#x27;s wall has nothing to do with it.<p>As far as I&#x27;m concerned. FB&#x27;s only mistake here was to brush him off instead of asking for further information from the initial report. Hardly newsworthy.
评论 #6239515 未加载
jzelinskiealmost 12 years ago
Why don&#x27;t people just send things in their native language? If the platform for communication is serious (like a place to report security vulnerabilities), I would imagine they would spend the time&#x2F;money to get a real translation if one was needed. Even Google Translate probably could&#x27;ve done a better job than this guy&#x27;s original report.
评论 #6239313 未加载
评论 #6239943 未加载
评论 #6239371 未加载
jack-r-abbitalmost 12 years ago
I don&#x27;t really understand what significance there is in stating that he is &quot;unemployed.&quot; Does that somehow make his actions better&#x2F;worse or the &quot;hack&quot; more&#x2F;less tolerable?
评论 #6239382 未加载
评论 #6240162 未加载
diminotenalmost 12 years ago
The Facebook team should have taken better care of this, but the guy should have used one of the test accounts, or created a test account to demonstrate this, rather than fuck with someone else&#x27;s private Facebook account.<p>Very bad form.
评论 #6239488 未加载
guard-of-terraalmost 12 years ago
I think we should crowd-source $5k to that guy and make Zuck sure we don&#x27;t really need him for anything.<p>I&#x27;m ready to toss $10.
评论 #6239871 未加载
nthitzalmost 12 years ago
Plenty more discussion here: <a href="https://news.ycombinator.com/item?id=6229858" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=6229858</a>
joshaidanalmost 12 years ago
I find it interesting the amount of attention Hacker News is getting from this in mainstream media.<p>It makes me wonder, when people unfamiliar to Hacker News read about it in stories like this, do they get the wrong impression and think Hacker News is about the criminal kind of &quot;hacking&quot;?
评论 #6239570 未加载
babyalmost 12 years ago
hasn&#x27;t this story been posted multiple times already?<p>Also it was made clear that he clearly violated the TOS and that his messages were unintelligible.
评论 #6241623 未加载
bloafalmost 12 years ago
Its simple, Facebook can&#x27;t set the precedent that people who exploit bugs in this way get paid. If they did, every Joe who felt that their particular bug wasn&#x27;t being addressed quite right would think that public exploitation is the faster route to their reward.
评论 #6239956 未加载
callesggalmost 12 years ago
What is wrong with journalists now days. Reading on hacker news and copy pasting stuff in to articles is not what i would call good journalism.<p>It would be nice if people could stop reposting shit from &quot;average joe&quot; news papers.
lcusackalmost 12 years ago
It would be a class act if Mark Z personally paid him the bounty or maybe if FB employees crowdfunded it.<p>Then they don&#x27;t have to admit they were wrong and don&#x27;t look like jerks. Best of both worlds.
adsralmost 12 years ago
This seems like a lack of communication skills on both parts imho, why would you respond: &quot;this is not a bug&quot; to a bug report you did not understand.
codex_irlalmost 12 years ago
poor show FB - thumbs down!
enterxalmost 12 years ago
lol, you ad serving pricks! XD<p>Will someone send this Khalil Shreateh a brand new quad-core? TIA<p>Khalil Shreateh - respect. Let your name be indexed once more.
shortcjalmost 12 years ago
Facebook is a top tier company; they don&#x27;t pay people attention, much less real money, without a track record of like Harvard or Stanford already.
评论 #6239351 未加载