HN user

MrHoltz

2 karma
Posts0
Comments3
View on HN
No posts found.

Granted it looks like they had a policy but it's possible that not many people were aware of it. I don't know anyone that reads the lengthy ToS or policy documents of companies they deal with and they didn't seem to give it much promotion until after this incident. He does specifically say bug bounty programme and not the policy so I'm willing to give him that. If a company has a stance they do need to promote it and perhaps have stronger wording than we might not hang you out to dry.

http://news.ycombinator.com/item?id=3605343

I manage Facebook's Whitehat program (https://www.facebook.com/whitehat). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this research is documented quite succinctly:

"If you give us a reasonable time to respond to your report before making any information public and make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research, we will not bring any lawsuit against you or ask law enforcement to investigate you."

His attempt to access data was outside our whitehat guidelines, had clear malicious intent, and included extensive and destructive efforts to remain undiscovered and anonymous. In addition, he made no effort to contact Facebook with his discoveries, and even denied involvement when initially questioned. His attempt to claim he intended responsible disclosure only after faced with criminal action is false and insulting to the community of responsible security researchers.

http://gmangham.blogspot.co.uk/

[5] I think the white hat bug bounty programme is a very good idea and that schemes like it are a very useful way for companies, especially the big ones to manage their large attack surfaces. I suspect some people are wondering why I didn’t use it to submit my findings, well the answer to that is that the bug bounty programme DID NOT EXIST when I was working on my audit, therefore it was not an option that I could take. I am willing to bet that it became a higher priority afterwards though.

It's pretty obvious that somebody here is lying, when did the bug bounty programme start?