Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arice
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
1.
▲
by
arice
4y ago
[HackerOne CTO here] There are certainly some important lessons for us to learn here but, just for clarity, this wasn't one of them. The data access in question here was central to the individual's daily job responsibilities and d
2.
▲
by
arice
9y ago
That's helpful feedback on missing context from our post. Thanks. This series by VICE articulates the sometimes subtle distinctions between legitimate monitoring software built for enterprises and parents vs this particular software (w
3.
▲
Learning from a Year of Security Breaches
(medium.com)
327 points
by
arice
10y ago
|
49 comments
4.
▲
by
arice
11y ago
That's me, and I'm quite embarrassed as I never paused to consider how it could be interpreted. That was a real story. Shortly after we established Facebook's bug bounty program, we received several vulnerabilities from a bri
5.
▲
by
arice
11y ago
Great questions. We'll line up a more analytical post on the topic as I don't know all the answers here, and we all should. In the interim, here's a few rough from memory answers: > Thats an average of $357/vuln The 1
6.
▲
by
arice
11y ago
Great feedback, thanks. The 180 day guidance you reference falls under a "Last Resort" clause when "... the Response Team [is] unable or unwilling to provide a disclosure timeline". (which, at first glance, might not hav
7.
▲
by
arice
11y ago
I don't make a habit of storing assets in banks that fail to insure me against a total loss of those assets. That insurance just happens to require extensive third-party verification of security practices that may be publicly audited u
8.
▲
by
arice
11y ago
The stance you take is harmful when said organizations are responsible for the stewardship of the data of others, and being "less secure" places the general public at risk. The true impact of a breach is rarely limited to a single
9.
▲
by
arice
13y ago
This is great work by Egor, as usual. I work on Facebook's security and thought I'd add a bit more clarity here on the mitigation steps available to developers. Awareness here is important. The first issue manifests itself if 1) a
10.
▲
by
arice
14y ago
Hopefully not too oddly: Facebook was one of the first OAuth 2.0 implementations and the additional benefits of requiring stricter pre-registration was not initially apparent. An unfortunate oversight. For kicks: compare section 5.2.3.5 v00
11.
▲
by
arice
14y ago
I'm very sorry you had this experience. We would never intentionally ignore a legitimate bug report. If you could send me a message (link in profile) with the e-mail address you used, I'd be happy to get to the bottom of this.
12.
▲
by
arice
14y ago
FYI: Facebook has open sourced this tool, you can find it on github. Here's the commit that added Bootstrap: https://github.com/daaku/rell/commit/64bd62d40df54ddc08a9270...
13.
▲
by
arice
15y ago
Unfortunately, much of the internet industry has an established history of doing just that. This heavy-handed approach to vulnerability disclosure has led to an atmosphere of distrust and is bad for everyone. Facebook's policy is intended t
14.
▲
by
arice
15y ago
Facebook's Responsible Disclosure Policy applies to all Facebook properties. The exceptions you outlined specifically apply to our bounty program. Basically, we may not pay a cash reward for a security issue reported in Mailman (an open sou
15.
▲
by
arice
15y ago
I manage Facebook's Whitehat program ( https://www.facebook.com/whitehat ). We have taken an incredibly open stance towards security researchers and welcome the contributions they make towards securing the internet. Our policy towards this
16.
▲
by
arice
16y ago
Not every computer is guaranteed to be free of malicious software capable of acting on behalf of the individual. This necessitates that security filters operate on private communications. This is true for all messaging products. An example
17.
▲
by
arice
16y ago
Yishan Wong makes some interesting points: http://www.quora.com/Are-Foursquare-and-Gowalla-going-to-sur...
18.
▲
by
arice
16y ago
I'm a confused user: The field didn't tell me what I should put in, so I just typed Bob and it worked.
19.
▲
by
arice
16y ago
The same choice is still possible on Facebook, no? There is a default-unchecked "Keep me logged in" box and a Logout button.
20.
▲
by
arice
16y ago
FWIW, the previous default was "Friends and Networks", not "Friends and Family". That includes Networks like the United Kingdom with 20M users and no restrictions on who could join.
21.
▲
by
arice
16y ago
Haha! If that is a virus, then so is this: http://news.ycombinator.com/item?id=1354731 :-)