That is very slow for a server-side vulnerability. Was the fix that complicated that it could not be safely deployed within minutes or hours? Or did the FB management not take the issue seriously?
That is very slow for a server-side vulnerability. Was the fix that complicated that it could not be safely deployed within minutes or hours? Or did the FB management not take the issue seriously?
As soon as we found the vulnerability, our first priority was to determine how we could protect people most effectively. If we had closed the vulnerability immediately, the attackers could have escalated their attack to modify information or post as someone else by using the access tokens they had already acquired before we reset them. Instead, we determined all the potentially affected accounts and reset their access tokens in a coordinated way to prevent further misuse of the vulnerability.
We haven't reset 90M accounts all at once before. Identifying the attackers, defining our remediation, validating that it would work, and closing the vulnerability while simultaneously ensuring all accounts were secure is complex to do at scale.
You could have taken the site down until it was fixed.
So protecting people was your second priority.
Everything should be in lock down mode while accessing vulnerability and working on a fix.
It would be fine if your point was reasonable. But it's not. It's little more than an excuse to hate on Facebook.
https://www.amazon.com/Art-War-Sun-Tzu/dp/1599869772 (the parts on the type of ground are very good and should be instructive to y'all)
https://www.artofmanliness.com/articles/ooda-loop/ (It seems you guys have been 'looped' pretty badly, this will start the process of fixing that)
https://www.amazon.com/War-Carl-von-Clausewitz/dp/1469947021 (the sections on 'fog of war' should help you all out, the text in general is informative)
"Within two days, we closed the vulnerability, stopped the attack, and secured people’s accounts by resetting the access tokens for people who were potentially exposed. As a precaution, we also turned off “View As.”
The last sentence could mean they disabled the feature and then spent two days fixing the vulnerability before re-enabling it. It's not clear though, maybe this is just wishful thinking on my part.
Edit: This hasn't been the case for years.
Lots of reasons to delay.