TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Recent reports on our whitehat program

36 点作者 Lightning超过 11 年前

11 条评论

ck2超过 11 年前
Facebook, at least send the guy a new laptop.<p>You don&#x27;t even have to tell anyone you did it if you are worried about &quot;rewarding non-preferred behavior&quot;.<p>Mute the commercial and watch this video to meet this guy and realize he was trying to help and you were being idiots:<p><a href="http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-facebook-hack/" rel="nofollow">http:&#x2F;&#x2F;www.cnn.com&#x2F;2013&#x2F;08&#x2F;19&#x2F;tech&#x2F;social-media&#x2F;zuckerberg-f...</a><p>He hasn&#x27;t worked in two years and his laptop is missing 5 keys.
评论 #6242560 未加载
mafro超过 11 年前
I am the only person out there that agrees he shouldn&#x27;t receive a bounty?!<p>Facebook&#x27;s stance is akin to &quot;we don&#x27;t negotiate with terrorists&quot;. Although obviously this wasn&#x27;t malicious (or &quot;terrorism&quot;); just a case of a foolish newbie who failed to follow the rules.
评论 #6242314 未加载
评论 #6242347 未加载
评论 #6242464 未加载
评论 #6242434 未加载
评论 #6243243 未加载
jwr超过 11 年前
This is wrong. The reporting guy clearly had white-hat intent and made an effort to alert Facebook to a real security problem. Because of miscommunication and some poor decisions, a message was posted to another user&#x27;s wall. There was no malicious intent, this was done as a (admiteddly desperate) part of a conversation.<p>Now is the time for both sides to make their apologies and for Facebook to reward the hacker.
tptacek超过 11 年前
They&#x27;re not going to pay him. To do so would be legally risky, and set a precedent that could be helpful to <i>actual</i> malicious attackers in civil litigation. &quot;Don&#x27;t use accounts without accountholder consent&quot; is the single most important term in a bug bounty; if you don&#x27;t honor it, you&#x27;re not participating in the bug bounty, but rather doing something else.
评论 #6245193 未加载
new299超过 11 年前
They should pay the guy, not because it&#x27;s the &quot;right&quot; thing to do, but because it maximises future bug reporting.<p>If people see that facebook back out of paying for legitimate, reported bugs, they&#x27;ll seek other options to monetize them.
Radle超过 11 年前
After reading the messages between the white hat and Facebook, I do believe it is the right decision do not pay him.<p>In his report he lacked the communication skills necessarily to make a useful bug report, which after my opinion caused the problem.
评论 #6242579 未加载
评论 #6243053 未加载
评论 #6242818 未加载
评论 #6242366 未加载
评论 #6242484 未加载
thezilch超过 11 年前
This is absolutely the right response; I think it&#x27;s not a stretch that a security report might be provided by a &quot;newcomer&quot; or potentially even a complete layman.
jcutrell超过 11 年前
It makes way more sense to offer some sort of sandbox to prove bugs to filter this kind of thing (instead of having less-than-stellar bug responders like the &quot;this is not a bug&quot; guy).<p>If you could create your own &quot;non-friend&quot; user mock object and demonstrate the bug, no one has to parse your bad language. He proved the bug through a live test - doesn&#x27;t it make sense to provide this kind of testing ground to whitehats?<p>I&#x27;m not a hacker, just a plain old developer. But in my world, when I want to explain something, I do it with test-case code and live examples, not through long-winded emails or bug reports.
评论 #6244536 未加载
Sami_Lehtinen超过 11 年前
I guess he would have made more money by selling the exploit to someone with tons of fake accounts and botnet. Then they would have used it to flood walls with malware and advertising links and generic spam.
zwdr超过 11 年前
Facebook can&#x27;t possibly pay him. Exploiting a bug on the live site is not something they can reward, even if they want to. It would set the wrong kind of precedent, signaling that it&#x27;s OK to do whatever to demo an exploit on Facebook.<p>That said, facebook will surely find some deal so they end up with positive PR.
arnehormann超过 11 年前
This could be soooo easy. Just provide a way to create a temporary account for tests that is not &quot;a real user&quot; and offer it on request. Creating and deleting these should not be a problem - if a report is false, the account won&#x27;t change anyway.
评论 #6242650 未加载
评论 #6242554 未加载