Mark Zuckerberg’s Facebook page was hacked by an unemployed web developer
washingtonpost.com
washingtonpost.com
This is being covered a lot more widely because FB didn't just pay the guy. I know it wasn't about money for FB, but this is easily done a lot more damage then they would have expected and because of their inadequate handling of a single bug report, I can only feel satisfied as I think this will go down as a good case study of how not to be so dismissive with critical bugs.
(I still think they should pay the guy, and it should be double the $5k he would have expected to receive).
A community member taking the time and interest to try and go through proper channels to submit a vulnerability should, IMO, be given more respect than was shown by FB.
The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug report guidelines.
IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.
My first thought is to say to facebook "Oh, I thought you were interested in fixing bugs. I'll know better what to do next time." Are you forgetting that the purpose of the bounty program is to protect facebook users by discovering and fixing bugs before spammers get the chance to use them? And that spammers pay real money for bugs like this one?
It's an awfully high standard to hold people to, considering the fb ToS is not translated to the guy's native language.
I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).
I bet if the submitter had written the bug report in Arabic, and FB had a professional translator on their security team (with some technical background), things might have been very different and we may not even be having this discussion.
Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.
Clearly there was a language gap and the original bug report suffered as a result. I don't its such a big deal overall.
- he did not do all this in good faith. it seems like he genuinely did. Sure there are TOS. But given his english, do you really think he understood them? Of course not. Good faith is a higher morale value (even thus Americans are pretty much used to "if it passed as law/text, morale values are irrelevant, cuz lawyers+money is all that matters)
- $500 is less than peanuts for FB. Finding these bugs, even if they have to read into the guy's submission more than usual, is critical for FB. Refusing the bounty means that next time it'll be left unfixed and the bad guys will probably get it instead.
All in all, FB's not wrong per say, but it's still a bad move from FB, morally and PR-wise.
That is why he isn't getting paid (yet?)
Are you refering to those unwritten rule that are written here: https://www.facebook.com/whitehat
From what he managed to write in the blog post, he CAN write English which is not THAT bad.
But this dude doesn't really bother. Hey Facebook, there's a bug. Wanna know it? How about you... beg me to tell you?
I am quoting him: whatever , i dont care for miss spelling , just the idea , i never correct an underline red word ;)
Did FB treat it properly? No. Did he act properly? Not either. But since it's FB... THEY ARE EVIL!!!!111!
-----Original Message to Facebook-----
From: kha****@hotmail.com
To:
Subject: post to facebook users wall .
Name: Ḱhalil
E-Mail: khal****@hotmail.com
Type: privacy
Scope: www
Description: dear facebook team .
my name is khalil shreateh.
i finished school with B.A degree in Infromation Systems .
i would like to report a bug in your main site
(www.facebook.com) which i discovered it .
repro:
the bug allow facebook users to share links to other
facebook users , i tested it on sarah.goodin wall and i
got success post
link - > https://www.facebook.com/10151857333098885
-----End Original Message to Facebook-----
From that, you surmised that he exploited the "make a new wall post" form by replacing the user ID with another of his choosing?In this case Khalil probably held the incorrect assumption that an actual demonstration of the bug would be how Facebook would want this to be reported, hence the lack of details.
It's not unreasonable for him to think Facebook would take a look at their HTTP logs to find out what happened.
His English is actually good enough. In the post he posted on Mark's wall you can see the language is good enough and I saw the video interview too where he even spoke well enough.
A technical and step-by-step report was well within his capability.
He could attach screenshots or create a video demonstration.
He used the bug on real users (2 of them!) one of them being Mark Zuckerberg which has obviously created huge negative PR for Facebook.
If someone tests a bug on your Facebook account how happy would you be?
Facebook can't reward someone who used a bug against its users.
On top of that he has damaged their reputation too. Almost all major news sites have written headlines similar to "Palestinian developer hacked Mark Zuckerberg", "Security vulnerability found in Facebook" etc etc which I'm sure they are not super thrilled about.
Hindsight may be 20/20, but I'd absolutely expect my support or security team to respond with instruction on how and what steps should be taken to diligently report issues. FB did not even try to correct the wrong and dissuade the reporter from abusing users' pages.
Also, relative to other places you could be spending your time, FB security issues yield relatively little in the blackhat market because of their highly responsive abuse and security teams.
Sure this bug was like that. But what if someone discovers a bug that allows you to post as the person?
What if I hacked the Twitter account of a major press organization?[2]
Eventually the SEC will require traders to seek independent verification before executing based on social data, or put stops in place similar to the flash crash protections.
1. http://www.sec.gov/news/press/2009/2009-226.htm 2. http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twit...
http://www.smh.com.au/business/mining-and-resources/hoax-pre...
I think they should be a little lenient in this case since it seems like he messed with only Zuckerberg's account, and because of the PR around it.
No, he posted to another persons account first (that was his initial bug report). Then he posted again to Zuckerberg's account when they ignored him.
Also, it's too late to prevent the bad PR.. paying him now will only tell every other hacker that they can do whatever they want to facebook accounts/users, as long as they embarrass facebook with it afterward.
http://www.cnn.com/2013/08/19/tech/social-media/zuckerberg-f...
He is rather poor and had a tiny broken laptop that is missing five keys.
He could have used that money and really tried to get them to see the problem.
They should pay him just out of realizing what idiots they were.
Someone should at least send him a better laptop.
Even if Facebook wanted to ignore the terms of their bug bounty to pay this person, they probably can't. Bug bounties are legally fraught as it stands. Like every bug bounty, Facebook's is clear: if you use a real account, you must have the consent of the accountholder. That term isn't just there to make the Facebook security team's job easier; they also can't officially condone people compromising random user accounts.
Facebook also operates in a web of contractual and regulatory concerns, including California's breach notification laws. Exploitation of security vulnerabilities on Facebook's public properties outside of the terms of their bug bounty might be legally more akin to attacks than to pro-bono testing. Further, Facebook obviously needs the ability to reliably enforce their terms, lest they provide attackers with ammunition in a court case if they, for instance, Pastebin large amounts of Facebook user data. "Oh, I was just participating in the bug bounty program; I certainly wasn't setting out to sell $CELEBRITY's data to a tabloid."
Jim Denaro is an attorney specializing in stuff on this. We talked to him on Twitter this weekend when the story broke, and he said he would have advised against paying the bounty here too. Maybe we can get him to write a blog post.
I don't know how much "outrage" this has actually generated in the security community (maybe you can find links). The security people I've talked to think what happened makes perfect sense. Facebook didn't freak out, the acknowledged the bug report (once they understood it) and fixed the bug. They're just not paying a reward, because the bugfinder violated what is perhaps the most important term in the bug bounty.
One more thing: people on HN have a lot of strong opinions about Facebook, and while I don't share many of them, I understand and respect them. Understand though that the people working on Facebook's security are real and very smart and by and large not the least bit interested in screwing other bugfinders out of 0.00000000001% of Facebook's operating capital.
But they certainly are happy to act as total pencil pushers when it comes to parting with that 0.00000000001% of Facebook's operating capital.
I look forward to Jim Denaro's blog post. Perhaps my viewpoint on this completely wrong and could be corrected, but for now this stinks of a cop-out behind red tape.
Edit: Further clarification below ... https://news.ycombinator.com/item?id=6240105.
Who would even have time for ceremony in a situation like that?
No, I do not. I am sure they are as smart as you say they are.
More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people.
They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).
In this conversation, you appear to be defending the FB appsec team for the work they do other than _this particular incident_ and I have no contention with that.
When it comes to _this particular incident_, a lot of things went awry. (a) FB did not appear to have a process in place for handling bug reports from non-native english speakers (or non-speakers for that matter). (b) A bug did eventually get resolved, which otherwise may not have happened. The fact that the bug-reporter had to resort to extreme tactics was due to the breakdown of communication and not any malicious intent on part of the bug reporter (c) The infinitesimally small bug-bounty payout was denied on a technicality, that also appears to people other than me to be no more than a bureaucratic bitch-slap out of spite for the bug reporter resorting to extreme tactics (see (b)).
In summary, FB messed up by not providing the needed (language) resources to handle such an issue in the first place and is making a lousy situation worse by not paying the (token) bug-bounty that would have just put a kibosh on the whole situation exploding all over the internet, from the get go. All of this leaves FB (the company, not the smart appsec people) looking like the bad guys.
What you call a "technicality" I continue to call probably the most important term in the whole bug bounty.
Moreover, you ignored half my comment. The point isn't that they had the ability not to pay; it's that they probably have a legal requirement not to pay.
Meanwhile: could you please acknowledge that when I pointed out that the Facebook security team does good work, your immediate response was to snark that they were pencil pushers? Your followup pretends you never said that, but you obviously did.
Perhaps we see things differently here, so lets just agree to disagree.
Meanwhile: could you please acknowledge that when I pointed out that the Facebook security team does good work, your immediate response was to snark that they were pencil pushers? Your followup pretends you never said that, but you obviously did.
I certainly conflated the FB appsec team with FB-as-company and whoever made the decision to not pay the bounty. Hence, I further qualified the target of my criticism in the subsequent replies.
But, boy-oh-boy, I must say, you seem to have taken my criticism of FB quite personally.
If so, I apologize for the misdirected barbs. They are not meant for you or the FB appsec team, but for whoever made the call to not pay the bounty. Like I said earlier, I look forward to learning more about the legal requirement not to pay. Hope you guys can muster that blog post.
Could you not make an argument that the bug finder didn't understand this the proper guidelines as Facebook.com/whitehat is only available in English?
This is all you have to say?
They, rightfully or not, see an independent who was ignored and then persecuted for trying to responsibly report a bug. It's given Facebook a black eye to more than just the HN crowd, and people will probably be thinking twice about disclosing security bugs, particularly if they get "working as intended" as their initial response.
Also, consider the guidelines that go into developing a UI. The more roadblocks you put in someone's way to register for your site, the fewer people will register. Apply that to this, and the more roadblocks you put into reporting a bug correctly (requesting special accounts, fighting to convince staff that your bug is an actual issue), the fewer bug reports you're going to get. That's not a good thing for Facebook in the long run.
I think this is wrong. He posted on Sarah Godin's wall first before making any report, very clearly breaking the rules FB sets up for its whitehat program. They offer a way to create test accounts for exactly this. Posting on Mark Zuckerberg's wall has nothing to do with it.
As far as I'm concerned. FB's only mistake here was to brush him off instead of asking for further information from the initial report. Hardly newsworthy.
The Facebook employee who replied to the email handled it very poorly, but the guy who found this bug also handled it very poorly by not actually sending any details about what he did.
But yeah, I guess ignoring the lingua franca of the world and furthering the status quo is the easiest path.
Secondly, at a no point I said anything against this guy, he at least put in the effort and is commendable. My whole point was that thinking about resorting to translators instead of thinking about how to improve the number of English speakers is being narrow-minded. It's like saying: building a dam is hard, let's just keep the floods coming.
I already said it: yes, English it's not the most spoken language, but it's the dominant in that it transcends cultures and countries. Saying that Chinese is the dominant language because is the most spoken is like saying that ants are the most influential beings because they're the species most prevalent on earth.
English is a clear 2nd. (And on at least one estimate it is first)
Otherwise: Con esa forma tan cerrada de pensar, por favor absténgase de opinar.
Also, the only narrow minded here is the one who advocates for a fragmented world and the resulting slow flowing of information.
http://en.wikipedia.org/wiki/Postcolonialism
Postcolonialism, and especially postmodernism, are very complex concepts that require a great deal of study to grasp, but it may be worth your while if you want a serious challenge to your argument.
P.S. While I do think some of the statements made by cliveowen were insensitive, I also think that teaching people English (or another world language) in addition to their native tounges would help break down barriers between people, and lead to a better world overall.
The main counter argument is that you simply have no right dictate how others communicate, despite your declarations of improved efficiency and increased idea proliferation. I think people who spend tons of money on clothes and other trappings are wasting resources and contributing to unhealthy societal development, yet I do not go around demonizing these people. I kindly share my view to receptive listeners, while also attempting to recognize my own biases and inability to perfectly understand this massively complex world. Do you also go around proselytizing SUV owners for their massive waste of gasoline? Why not?
Lastly, it would be impossible to quantify this, but I wonder how much cultural richness, diversity of thinking, etc we would be losing if all of the sudden everyone was forced to only use English? My bet is that it would not be a trivial loss.
Anyways, I wouldn't be surprised if translation technologies make this discussion completely moot in the next couple decades.
-translations cost a huge amount of money
-a fragmented world slows down the spreading of information
-the most influential pieces of writing are written in English
In addition, if you say "let's get some translators instead of learning English because learning is hard" that's laziness. There's no way around, it's not like I think you're just being lazy, it's just that you are being lazy.
Lazy:
adjective
-unwilling to work or use energy
-characterized by lack of effort or activity
All I got so far are a bunch of downvotes, what I didn't get is an opinionated, fact-based counterargument.
And I'm sad to say it, but I'm frankly disappointed that a community of engineers (for the most part) exhibits this kind of hidebound mindset.
It's kind of like if I called you lazy for not going to the store and buying me a case of beer every week. EDIT: OK not exactly, but you get the point... demanding large life changes from others because you claim there is a benefit. This is the epitome of egotistical exuberance.
I would try to explain my reasoning but judging by your other replies, it would be a fruitless endeavor.
I would even argue that you are much much worse since not only are not learning other languages you are sitting on a forum complaining that other people can't speak your own and they must work just so you have less to do.
Not everybody has access to good material and resources. Yes, the internet made this much easier. But it may be still difficult to "bootstrap" it
English may be more difficult depending on your mother tongue
It is frustrating when you want to say something in another language and even if you use Google Translate you're still not 100% sure.
So I think he should have tried harder, but at the same time, it may be difficult for some people.
I concur with the second point.
How many do you know?
Edit: Oh, and how about a bit of Latin and Greek, maybe?
There's no advantage whatsoever in having a fragmented world, and if the mess in my head is any indication the alleged advantages of bilingualism are just BS.
After all, knowing more than one language does give you some different insights, not just into the culture of the other language but also into your own culture. Furthermore, there is a whole canon of classical works in basically every language which would likely lose some of its value if it were only accessible in the translated form.
We can add to the last point by taking note that English is a particularly bad example of a ‘world-wide native language’. While its simplicity – both with regards to its vocabulary and its grammar – certainly helps when it is the second language of someone, such concerns are of smaller importance when you want it to be everyone’s first language: Such a language can come with a much stronger set of grammatical rules and nicer ways to build composite words and still be (roughly) equally accessible to its native speakers.
Because there are dozens to hundreds of languages that could be! How are they supposed to be good at them!
Even Google Translate probably could've done a better job than this guy's original report.
Erk no. Google translation is decent for many languages, but sort shite for lots, and non-existant for others.
Especailly big reports with lots of fine details of "this is supposed to do this" type language can be harder.
Journalism is always fair and balanced. They would never, ever use potentially biasing words to suggest that you favor the big corporation over the individual.
I think. It's gotten nearly impossible to tell w/ modern journalism.
The word "unemployed" has such negative connotations here that trying to use it in an underdog narrative is dooming your story to failure.
Very bad form.
I'm ready to toss $10.
Really? Just because FB's security team was dismissive of a real bug report due to a language barrier they could have overcome with the tiniest bit of due diligence?
Hence I don’t see how you come to your conclusion…
It makes me wonder, when people unfamiliar to Hacker News read about it in stories like this, do they get the wrong impression and think Hacker News is about the criminal kind of "hacking"?
Facts is facts, man. Sorry if you don't like the snark, but I'm not sorry for telling the truth.
That's not touching on the rest of your posts. They've all been hyperbolic bullshit, and I hate seeing it bleed over from the political discussions.
Source: Wikipedia, "hacker".
Also it was made clear that he clearly violated the TOS and that his messages were unintelligible.
Previous discussion
https://news.ycombinator.com/item?id=6229858 +383
and about 10 other single digit posts of various blogspam sites
https://www.hnsearch.com/search#request/submissions&q=facebo...
and reddit
http://www.reddit.com/r/sysadmin/comments/1kkvfr/user_report... +329
http://www.reddit.com/r/netsec/comments/1kkvei/user_reports_... +532
http://www.reddit.com/r/technology/comments/1ko71v/researche... +831
http://www.reddit.com/r/technology/comments/1kkoux/hacker_po... +3005
Can we wrap this one up perhaps?
The bad precendent is that if you're not a great english speaker, you might as well sell your bug on the black market. This is not good for facebook.
It would be nice if people could stop reposting shit from "average joe" news papers.
Then they don't have to admit they were wrong and don't look like jerks. Best of both worlds.
Will someone send this Khalil Shreateh a brand new quad-core? TIA
Khalil Shreateh - respect. Let your name be indexed once more.