Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You would prove nothing other than that crime pays.


Crime does pay, that's rather the point of crime, it doesn't really need proving.


In that case, crowdsourcing a way to pay this guy $5k for the vulnerability he found and abused would be counterintuitive.


WOW WOW you say "abused"... strong language there. He was trying to show the bug to them. This guy looks like he never read the TOS in the first place so he wasn't going after abusing. He didn't communicate properly is the way I would put it.


abused

Really? Just because FB's security team was dismissive of a real bug report due to a language barrier they could have overcome with the tiniest bit of due diligence?


I see no abuse. Secondly, the publicity of this will probably land the dude a job.


Had he sold this exploit, he could've made upwards of $20k-100k. Especially this bug. It allows marketing firms to post to peoples walls without even knowing them. That's a huge vulnerability at the moment when everybodies clamoring for 'social marketing'


I'd suggest that exploits for Facebook wouldn't actually sell that well on the black market. There's only one install of Facebook in the world and it's controlled centrally so can be patched at any time. It's not like an exploit for Windows which can go unpatched for months if people don't install an update - those are worth money because there's a real use case. With a Facebook exploit you'd get a few hours of spamming at best before it's patched and all the crap you posted is deleted - that's probably not worth the money.


I assume guard-of-terra intended to pay the guy who found the bug, not the company that criminally neglected the security of its users.

Hence I don’t see how you come to your conclusion…


No, rather it would be assisting those talented engineers those who cannot speak fluent English and are discriminated against in that sense.


Crime really pays (for such exploits) and he didn't go down that road, isn't he?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: