Who would even have time for ceremony in a situation like that?
Who would even have time for ceremony in a situation like that?
No, I do not. I am sure they are as smart as you say they are.
More importantly, I think the people who make the call to pay/not pay the bounty are not the same appsec people.
They are the ones who I'd agree are the green-shaded pocket-beprotectored bureaucrats (and pencil pushers).
In this conversation, you appear to be defending the FB appsec team for the work they do other than _this particular incident_ and I have no contention with that.
When it comes to _this particular incident_, a lot of things went awry. (a) FB did not appear to have a process in place for handling bug reports from non-native english speakers (or non-speakers for that matter). (b) A bug did eventually get resolved, which otherwise may not have happened. The fact that the bug-reporter had to resort to extreme tactics was due to the breakdown of communication and not any malicious intent on part of the bug reporter (c) The infinitesimally small bug-bounty payout was denied on a technicality, that also appears to people other than me to be no more than a bureaucratic bitch-slap out of spite for the bug reporter resorting to extreme tactics (see (b)).
In summary, FB messed up by not providing the needed (language) resources to handle such an issue in the first place and is making a lousy situation worse by not paying the (token) bug-bounty that would have just put a kibosh on the whole situation exploding all over the internet, from the get go. All of this leaves FB (the company, not the smart appsec people) looking like the bad guys.
What you call a "technicality" I continue to call probably the most important term in the whole bug bounty.
Moreover, you ignored half my comment. The point isn't that they had the ability not to pay; it's that they probably have a legal requirement not to pay.
Meanwhile: could you please acknowledge that when I pointed out that the Facebook security team does good work, your immediate response was to snark that they were pencil pushers? Your followup pretends you never said that, but you obviously did.
Perhaps we see things differently here, so lets just agree to disagree.
Meanwhile: could you please acknowledge that when I pointed out that the Facebook security team does good work, your immediate response was to snark that they were pencil pushers? Your followup pretends you never said that, but you obviously did.
I certainly conflated the FB appsec team with FB-as-company and whoever made the decision to not pay the bounty. Hence, I further qualified the target of my criticism in the subsequent replies.
But, boy-oh-boy, I must say, you seem to have taken my criticism of FB quite personally.
If so, I apologize for the misdirected barbs. They are not meant for you or the FB appsec team, but for whoever made the call to not pay the bounty. Like I said earlier, I look forward to learning more about the legal requirement not to pay. Hope you guys can muster that blog post.
Could you not make an argument that the bug finder didn't understand this the proper guidelines as Facebook.com/whitehat is only available in English?