That is why he isn't getting paid (yet?)
Are you refering to those unwritten rule that are written here: https://www.facebook.com/whitehat
From what he managed to write in the blog post, he CAN write English which is not THAT bad.
But this dude doesn't really bother. Hey Facebook, there's a bug. Wanna know it? How about you... beg me to tell you?
I am quoting him: whatever , i dont care for miss spelling , just the idea , i never correct an underline red word ;)
Did FB treat it properly? No. Did he act properly? Not either. But since it's FB... THEY ARE EVIL!!!!111!
-----Original Message to Facebook-----
From: kha****@hotmail.com
To:
Subject: post to facebook users wall .
Name: Ḱhalil
E-Mail: khal****@hotmail.com
Type: privacy
Scope: www
Description: dear facebook team .
my name is khalil shreateh.
i finished school with B.A degree in Infromation Systems .
i would like to report a bug in your main site
(www.facebook.com) which i discovered it .
repro:
the bug allow facebook users to share links to other
facebook users , i tested it on sarah.goodin wall and i
got success post
link - > https://www.facebook.com/10151857333098885
-----End Original Message to Facebook-----
From that, you surmised that he exploited the "make a new wall post" form by replacing the user ID with another of his choosing?In this case Khalil probably held the incorrect assumption that an actual demonstration of the bug would be how Facebook would want this to be reported, hence the lack of details.
It's not unreasonable for him to think Facebook would take a look at their HTTP logs to find out what happened.
His English is actually good enough. In the post he posted on Mark's wall you can see the language is good enough and I saw the video interview too where he even spoke well enough.
A technical and step-by-step report was well within his capability.
He could attach screenshots or create a video demonstration.
He used the bug on real users (2 of them!) one of them being Mark Zuckerberg which has obviously created huge negative PR for Facebook.
If someone tests a bug on your Facebook account how happy would you be?
Facebook can't reward someone who used a bug against its users.
On top of that he has damaged their reputation too. Almost all major news sites have written headlines similar to "Palestinian developer hacked Mark Zuckerberg", "Security vulnerability found in Facebook" etc etc which I'm sure they are not super thrilled about.
A community member taking the time and interest to try and go through proper channels to submit a vulnerability should, IMO, be given more respect than was shown by FB.
The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug report guidelines.
IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.
My first thought is to say to facebook "Oh, I thought you were interested in fixing bugs. I'll know better what to do next time." Are you forgetting that the purpose of the bounty program is to protect facebook users by discovering and fixing bugs before spammers get the chance to use them? And that spammers pay real money for bugs like this one?
It's an awfully high standard to hold people to, considering the fb ToS is not translated to the guy's native language.
I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).
I bet if the submitter had written the bug report in Arabic, and FB had a professional translator on their security team (with some technical background), things might have been very different and we may not even be having this discussion.
Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.
Also, relative to other places you could be spending your time, FB security issues yield relatively little in the blackhat market because of their highly responsive abuse and security teams.
Sure this bug was like that. But what if someone discovers a bug that allows you to post as the person?
What if I hacked the Twitter account of a major press organization?[2]
Eventually the SEC will require traders to seek independent verification before executing based on social data, or put stops in place similar to the flash crash protections.
1. http://www.sec.gov/news/press/2009/2009-226.htm 2. http://www.forbes.com/sites/jakezamansky/2013/05/01/the-twit...
http://www.smh.com.au/business/mining-and-resources/hoax-pre...
- he did not do all this in good faith. it seems like he genuinely did. Sure there are TOS. But given his english, do you really think he understood them? Of course not. Good faith is a higher morale value (even thus Americans are pretty much used to "if it passed as law/text, morale values are irrelevant, cuz lawyers+money is all that matters)
- $500 is less than peanuts for FB. Finding these bugs, even if they have to read into the guy's submission more than usual, is critical for FB. Refusing the bounty means that next time it'll be left unfixed and the bad guys will probably get it instead.
All in all, FB's not wrong per say, but it's still a bad move from FB, morally and PR-wise.
Hindsight may be 20/20, but I'd absolutely expect my support or security team to respond with instruction on how and what steps should be taken to diligently report issues. FB did not even try to correct the wrong and dissuade the reporter from abusing users' pages.
Clearly there was a language gap and the original bug report suffered as a result. I don't its such a big deal overall.