Skip to main content

Facebook admits mistake and still won't pay the researcher who hacked on Zuckerberg's page

The frustrated researcher, who failed to get an adequate response from Facebook’s security team and so hacked Mark Zuckerberg’s page to get their attention, is not going to receive a bug bounty for his discovery the social network has confirmed.
In a posting made on the social network’s security page, Facebook chief security officer Joe Sullivan admitted that his team made mistakes in its interactions with Palestinian researcher Khalil Shreateh and failed in its communication with him.
As a result, the site is going to make some changes in how it responds to potential vulnerability reports.
Facebook responds
“We should have explained to this researcher that his initial messages to us did not give us enough detail to allow us to replicate the problem. The breakdown here was not about a language barrier or a lack of interest — it was purely because the absence of detail made it look like yet another misrouted user report.”
“We will make two changes as a result of this case: (1) We will improve our email messaging to make sure we clearly articulate what we need to validate a bug, and (2) we will update our whitehat page with more information on the best ways to submit a bug report.”
From the looks of things, it’s true that Facebook didn’t really try very hard to explain the level of detail it required from Shreateh to confirm that a flaw existed on its social network.
He made two attempts to tell Facebook about the flaw, pointing them to a URL where he had managed to post a message containing a link to an Enrique Iglesias video on the wall of Sarah Goodin, a woman who had gone to college with Zuckerberg.
Facebook bug report
Facebook’s security team clearly failed to understand the scope of what Shreateh was attempting to report, but that should have been the cue for them to point him towards detailed directions of the type of information they required to properly investigate a report of a bug or vulnerability.
Instead, Facebook’s curt unhelpful response to Shreateh left him vaguely threatening to post on Mark Zuckerberg’s wall.
(Something he said he would not do because he “respected people’s privacy”, but did actually do in the end.
Khalil Shreateh says he can post to Mark Zuckerberg's wall
Joe Sullivan says, however, that Facebook will not change its policy of refusing to pay rewards to security researchers who test vulnerabilities against real Facebook users:
“It is never acceptable to compromise the security or privacy of other people. In this case, the researcher could have sent a more detailed report (like the video he later published), and he could have used one of our test accounts to confirm the bug.”
And you know what? I agree with Facebook. Shreateh shouldn’t have messed with anyone’s Facebook page without their permission. Yes, we should be grateful that he didn’t abuse the flaw in a malicious way, or sell details of the bug to online criminals who could certainly have used it to their advantage.
But it would have been better if he had only used test accounts to show how the flaw worked, and if he was frustrated by Facebook’s less-than-great way of dealing with him sought the assistance of the media or other researchers to underline the importance of what he was trying to report.
Does that mean Shreateh shouldn’t receive a reward? Well, although many will feel he does deserve to receive a bounty for finding a bug – it doesn’t look like Facebook is prepared to make an exception and shift on this one.
Let’s hope that this unfortunate interaction doesn’t prevent Shreateh from responsibly reporting flaws to Facebook in future, and – if he does – let’s hope that he receives the bug bounty reward that he will deserve.

Comments

Popular posts from this blog

Hass avocado farming in Kenya

Hass avocado farming in Kenya has become the new craze due to its extensive European market. Farmers today have lots of concern on where to source for quality certified hass avocado seedlings in Kenya , Nurseries such as the ones owned by Farmers Trend have been a good source for the seedlings and better information. To get quality hass avocado seedlings, contact https://farmerstrend.co.ke/ on 0790509684 Buy hass avocado seedlings at an affordable from a reputable certified seedbed in Kenya. Contact John Kiruthi on 0790-509684 Prices range from 150/= to 400/= per pc This post is a result of many queries that we get on this platform on where one can source hass avocado seedlings in Kenya. The Hass avocado season runs from June to mid – September with other varieties like Fuerte avocado starting a little earlier in March/April. The nursery imports its Hass shoots from South Africa and grafts them with locally available indigenous avocado seedlings for root stock. T...

Hack an Ethernet Router(ADSL)

Hack an Ethernet Router(ADSL) ADSL(Asymmetric Digital Subscriber Line) ethernet routers are used by many people across the world because it is efficient in many ways,But it is also the more vulnerable to the network,The most serious vulnerability which can easily be exploited by an hacker(a beginner also ) is…….. In first every ADSL Ethernet router comes with a USERNAME and PASSWORD using which it is possible to gain access to the router settings and configure the device. The vulnerability actually lies in the Default username and password that comes with the factory settings. Usually the routers come preconfigured from the Internet Service provider and hence the users do not bother to change the password later. This makes it possible for the attackers to gain unauthorized access and modify the router settings using a common set of default usernames and passwords. Here is how you can do it. U need some tools like PORT SCANNE R which you can download here 1.You need some ip addr...

Easy tools to Improve SEO Ranking For Your Website In Kenya by 2023

SEO tools save you from tedious keyword research and data analysis. With these tools, you’re able to see what’s working and which parts of your strategy could benefit from some tweaking. The best SEO tools also provide reports about how you measure up to competitors and where the greatest opportunities lie. What’s more, they allow you to measure search performance countries, regions, or languages. It gets better. If you’re managing more than one website, SEO tools can help you assess each site’s performance on the fly. Many entrepreneurs with multiple websites end up putting a lot of data in spreadsheets and analyzing it manually. But that soon becomes overwhelming and raises the risk of the reports being inaccurate. Fortunately, you can use SEO software to save hours of effort and generate accurate reports at a click. Best Search Engine Optimization (SEO) Tools 1. Ahrefs: SEO Keyword Tool Ahrefs is o...