Skip to main content

Facebook admits mistake and still won't pay the researcher who hacked on Zuckerberg's page

The frustrated researcher, who failed to get an adequate response from Facebook’s security team and so hacked Mark Zuckerberg’s page to get their attention, is not going to receive a bug bounty for his discovery the social network has confirmed.
In a posting made on the social network’s security page, Facebook chief security officer Joe Sullivan admitted that his team made mistakes in its interactions with Palestinian researcher Khalil Shreateh and failed in its communication with him.
As a result, the site is going to make some changes in how it responds to potential vulnerability reports.
Facebook responds
“We should have explained to this researcher that his initial messages to us did not give us enough detail to allow us to replicate the problem. The breakdown here was not about a language barrier or a lack of interest — it was purely because the absence of detail made it look like yet another misrouted user report.”
“We will make two changes as a result of this case: (1) We will improve our email messaging to make sure we clearly articulate what we need to validate a bug, and (2) we will update our whitehat page with more information on the best ways to submit a bug report.”
From the looks of things, it’s true that Facebook didn’t really try very hard to explain the level of detail it required from Shreateh to confirm that a flaw existed on its social network.
He made two attempts to tell Facebook about the flaw, pointing them to a URL where he had managed to post a message containing a link to an Enrique Iglesias video on the wall of Sarah Goodin, a woman who had gone to college with Zuckerberg.
Facebook bug report
Facebook’s security team clearly failed to understand the scope of what Shreateh was attempting to report, but that should have been the cue for them to point him towards detailed directions of the type of information they required to properly investigate a report of a bug or vulnerability.
Instead, Facebook’s curt unhelpful response to Shreateh left him vaguely threatening to post on Mark Zuckerberg’s wall.
(Something he said he would not do because he “respected people’s privacy”, but did actually do in the end.
Khalil Shreateh says he can post to Mark Zuckerberg's wall
Joe Sullivan says, however, that Facebook will not change its policy of refusing to pay rewards to security researchers who test vulnerabilities against real Facebook users:
“It is never acceptable to compromise the security or privacy of other people. In this case, the researcher could have sent a more detailed report (like the video he later published), and he could have used one of our test accounts to confirm the bug.”
And you know what? I agree with Facebook. Shreateh shouldn’t have messed with anyone’s Facebook page without their permission. Yes, we should be grateful that he didn’t abuse the flaw in a malicious way, or sell details of the bug to online criminals who could certainly have used it to their advantage.
But it would have been better if he had only used test accounts to show how the flaw worked, and if he was frustrated by Facebook’s less-than-great way of dealing with him sought the assistance of the media or other researchers to underline the importance of what he was trying to report.
Does that mean Shreateh shouldn’t receive a reward? Well, although many will feel he does deserve to receive a bounty for finding a bug – it doesn’t look like Facebook is prepared to make an exception and shift on this one.
Let’s hope that this unfortunate interaction doesn’t prevent Shreateh from responsibly reporting flaws to Facebook in future, and – if he does – let’s hope that he receives the bug bounty reward that he will deserve.

Comments

Popular posts from this blog

How to hack facebook password

Are you curious to "hack facebook password" well then this post is just for you, Most people ask me to tell them the easiest way to hack facebook password, so here are some ways to that hackers take to hack facebook password: 1.Facebook phishing 2.Keylogging 3.Facebook new features 4.virus Yo will see on my articles the 4 ways on how to hack a facebook password for information on the above methods. But today we will focus on a method which has a high success rate called Phishing and keylogging, so first of all: What is phishing?   Phishing is the most commonly used method to hack Facebook. The most widely used technique in phishing is the use of Fake Login Pages, also known as spoofed pages. These fake login pages resemble the original login pages of sites like Yahoo , Gmail, MySpace etc. The victim is fooled to believe the fake facebook page to be the real one and enter his/her password. But once the user attempts to login through these pages, his/her facebook log...

How a Telegram Group (Farmers+254) Is Rapidly Transforming Itself To Becoming A Support System For Farmers In Kenya

A simple mobile phone 15 years ago was out of reach for most small holder farmers in Kenya but that has changed. Affordable smart phones are increasingly becoming accessible and there is foreseen increase in usage for the technology by small holder farmers to access information in the medium term. A mobile phone screenshot of Farmers+254 Telegram Group Today, a group of young professional youths involved in agriculture has seen an opportunity in creating an agricultural group on telegram – Farmers+254 – in Kenya,  a group where farmers are sharing information, marketing their produce, getting technical help,  market updates, trends in agribusiness, value addition support and questions getting answered in real time. Telegram has indeed become part of the holy grail together with the traditional over the internet SMS to reach more small holder farmers and value chain actors with timely information dissemination. TELEGRAM Telegram  is a cloud-based ins...
How To Spy A Mobile Phone? - CellPhone Spying Software Have you ever wanted to spy on your spouse, kids, friends or employees? Or just play ''Secret Service'' 'cause you know, restraining order can only get you so close?! You certainly are in for a treat. Now, you can play make-belief all you want with a software that works just as well. SpyBubble is a software that allows you to log in from any computer and access any smartphone that it is installed on. Through SpyBubble, you can monitor and supervise any smartphone simply by entering your login username and password. SpyBubble has the following features that can be very useful in certain situations: Call Tracking 1. Access call logs and see how many calls were received and answered on the smartphone, how many calls were made on specific numbers, at what time and the duration they lasted. SMS Tracking 2. Sent and received messages are saved into your SpyBubble account as they are generated, so yo...