Man who hacked Zuckerberg's Facebook account gets cash reward
cnbc.com
cnbc.com
I understand it's frustrating when a bug report goes ignored or dismissed (still waiting on PayPal to confirm a couple bugs I reported last June or July (admittedly I haven't tried hard)), but that's part of the process. You work with them to refine the message until they understand clearly what the problem is and get it resolved. You don't mess with anyone else's account, under any circumstances.
This is just not acceptable, and it's sad to see some of the security community supporting it.
Facebook's rules were only available in english - despite having a way to switch most of facebook to arabic, the guy is obviously not a strong english speaker.
Rules are only guidelines for people who can't (or aren't allowed to) exercise good judgment. Rules are meant to be black and white, but real life is rarely so. In this case absolutely no harm was done, or even suggested, by the guy's actions. Facebook's decision to apply judgment rather than zero-tolerance is commendable.
EDIT: Facebook is still doing the brainless zero-tolerance thing. Shame on them. I should have read the article rather than assume the best.
PS the best company I ever worked for had as the first line of their employee handbook: "Don't do anything stupid just because it is written down in this book."
Re-read the article. They didn't.
Nowhere I saw good faith, just greed for money. He was even asking for money in the initial bug "reports". http://4.bp.blogspot.com/-4LbrTjyKBXc/Ug5sokeeR0I/AAAAAAAAAJ...
You only disagree with it because it's not well-enforced. Seeing other people get away with it sets a precedent for you to feel like it shouldn't be a rule. And the same would happen to Facebook if they paid him - eventually, the whitehat program's "technicalities" would become as pointless to enforce as a police officer ticketing someone for going "1 mph" over the speed limit. "Oh but it doesn't matter! It's just 1 mph!" If a speed limit designed to make a clear cut line doesn't work for you, how do you define rules? There's no objectivity to it at that point. It becomes a slippery slope.
Many people feel that small "technicalities" don't constitute real, ethical laws. This is wrong and an error in thinking. Every rule and every law is a restriction by technicality. Technically, you can go 65 mph, but not 66 mph. That's the line that delineates legality. It doesn't matter if you agree with it, it doesn't matter if you see other people do it, that's what it is.
But it is a rule, just like Facebook's Whitehat TOS. Agree with it or disagree with it, they don't care. You either follow all the rules, or you don't participate. That's the bottomline. They don't owe anyone money, they offer a bounty if you explicitly follow the rules and have proper discretion. It's really not complicated.
I don't agree. We're not robots, we're people. There is room for flexibility. To quote Captain Picard from Startrek TNG...
"Jean-Luc Picard: I don't know how to communicate this, or even if it is possible, but the question of justice has concerned me greatly of late and I say to any creature who may be listening, there can be no justice so long as laws are absolute. Even life itself is an exercise in exceptions."
That's about 7 months of salary here in Bolivia for a software developer. I imagine it's even less where he's from.
His intentions were good and it solved a serious problem, is this really something you do not want to reward?
While it has caused some bad PR for Facebook, I still believe that mainly happened because of how they reacted and a language barrier.
If did not speak english at all but found a serious bug like this, should he just not report it or should he use google translate?
> Now, Marc Maiffret, chief technology officer of cybersecurity firm BeyondTrust, is trying to mobilize fellow hackers to raise a $10,000 reward for Shreateh after Facebook refused to compensate him.