5 ms·
Nothing seemed missing to me. I think he thought that Zuckerberg/Facebook would emphasize with what it's like to be a white hat hacker, be very curious, challe
by jasonjackson 14y ago
Nothing seemed missing to me.
I think he thought that Zuckerberg/Facebook would emphasize with what it's like to be a white hat hacker, be very curious, challenge yourself and then let him off the hook. Other companies have been known to hire hackers after getting caught.
One thing that didn't really add up is he never turned himself in after committing the crime. He waited 3 weeks? That places doubt on his intentions. Maybe he just freaked out.
- Strallus 14y agoDo white-hat hackers normally turn themselves in? (also, I think you meant empathize)
- nbpoole 14y ago(Note: this post represents my own opinions, not anyone else's) No, but they normally report the vulnerabilities they find. I participate in a lot of responsible disclosure programs (Google, Facebook, Mozilla, Dropbox, Twitter, Etsy, etc). All of those programs dictate that you report the security vulnerabilities you find, and that you not abuse them. What was described in the blog post sounds a lot like real security audits that I've seen done. However, the difference is that those audits are done by professional security researchers who have been hired by the company for that purpose. If you're an outside security researcher you have to abide by a very different set of standards. Common sense would argue those standards include abiding by the company's responsible disclosure policy.