Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
collingreene
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
collingreene
5y ago
Pysa - https://engineering.fb.com/2020/08/07/security/pysa/
2.
▲
by
collingreene
7y ago
Here is our experience building and using program analysis as part of our product security efforts at facebook: https://engineering.fb.com/security/zoncolan/ . Its run in both self-service (output to developers), g
3.
▲
by
collingreene
7y ago
https://www.facebook.com/data-abuse - as mentioned in the article this scenario (non-fb companies mishandling fb user data) is exactly the reason Facebooks data abuse bounty program exists. Hopefully the finders of this sub
4.
▲
by
collingreene
8y ago
This exists, https://internetbugbounty.org/ Facebook, microsoft, github, etc all pay $$ and our time into a pool that is used to incentivize the finding, vetting and fixing of security flaws in major software running the in
5.
▲
by
collingreene
8y ago
I work at Facebook and have personally seen no evidence of this. The article cites one designer who left (out of ~25,000+ total Facebook employees).
6.
▲
by
collingreene
8y ago
The two people interviewed were fired for cause from this same program, of course they will have a negative opinion. One even fired for the same thing this safety driver failed to do. >Both Kelley and the former driver in Tempe were dism
7.
▲
by
collingreene
8y ago
> Why do you think the LIDAR did not work? The LIDAR might have worked just fine but what the system taking the output of the sensor did with the data is the question. Very true. I don't know either way.
8.
▲
by
collingreene
8y ago
I remain interested in why the lidar didn't work in this case and I hope more details emerge so we can learn what happened. But it seems logical that Uber would disable the onboard built-in volvo crash detection feature, it would be ad
9.
▲
by
collingreene
8y ago
Internal abuse is a big area of effort for Facebook and google but things still go wrong. Here was googles moment for that back in 2010: https://www.wired.com/2010/09/google-spy/
10.
▲
by
collingreene
8y ago
>I don’t understand ... why aren’t the default settings of an account more secure and private? They are (for the most relevant definition of your question). Specifically a Facebook app you choose to install can no longer see any of your
11.
▲
by
collingreene
9y ago
This exists and companies purchase it, ex: https://www.thehartford.com/data-breach-insurance Risks (all kinds, not just technical) can be accepted, ignored, transferred and mitigated so it is important to have this option.
12.
▲
by
collingreene
9y ago
I don't think anyone in security would disagree with you. The problem is measuring something that is sort of definitionally unknowable (how many vulns are in this code, where, how likely is it someone outside the company will find it,
13.
▲
by
collingreene
9y ago
If you like that book he wrote one about applying those ideas to this exact problem! https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri... I've never managed to make the effort to apply his ideas with much ri
14.
▲
by
collingreene
10y ago
+1 to starting a private program first which is recommended by all bounty programs. If helpful I wrote down my notes about starting a bounty program although my experiences were formed by larger companies https://medium.com/
15.
▲
by
collingreene
11y ago
Nice, these look superior to the intel books (which intel graciously printed then mailed to me for free like 10 years ago, go intel!). Ill check them out.
16.
▲
by
collingreene
11y ago
Assembly Language step by step by Jeff Duntemann remains one of my favorite books overall (not just programming, not just computers). It was updated in the last few years and the 3rd edition remains quite good.
17.
▲
by
collingreene
12y ago
Your acute mistaken conclusion> Simply throwing money at FOSS will not fix any security bugs. I can't think of anything closer to "throwing money at FOSS" than something like the internet bug bounty. Google/Facebook&#
18.
▲
by
collingreene
12y ago
Maybe you just enjoy hyperbole but while part of what you say is correct (finding security vulns in software is unavoidably a bit of a crapshoot) your conclusions are wrong. Finding deep, serious vulns like this in software can currently on
19.
▲
by
collingreene
12y ago
Cool article! A friend and I once did this but then recorded the commands attackers ran and replayed them on a big tv in our office. We called it hacker fishtank.
20.
▲
by
collingreene
12y ago
To echo this sentiment: In 2013 facebook received 14,763 submissions which lead to 687 paid issues, 1 : 21 signal to noise. Facebook errs on the side of paying out as often as possible even for lame bugs (apache shows its version number in
21.
▲
by
collingreene
13y ago
We first learned of this claim a few hours ago. We've been in touch with MyPermissions directly and are waiting to receive more information from them. At this point, we haven't been able to reproduce the reported issue or validate
22.
▲
by
collingreene
13y ago
This is really great. I have found myself saying some of these same things when explaining things. Going to keep this in my pocket to use in the future. Thanks!
23.
▲
by
collingreene
13y ago
Replying as discussion originally seemed to be about first/last/profile picture privacy. The scenario is: you are not able to get into your rightful facebook account but you know some information (phone, email) that is associated
24.
▲
by
collingreene
13y ago
I work at facebook on the security team. This is an account recovery endpoint used if your account was hacked for example. Your name, profile picture and a few other things are considered public information so there is no security issue dis
25.
▲
by
collingreene
13y ago
Google is on board. """ is sponsored by Microsoft and Facebook. It will be jointly controlled by researchers from those companies along with their counterparts at Google, """
26.
▲
by
collingreene
13y ago
Cool, found it. Will respond in the email thread.
27.
▲
by
collingreene
13y ago
I need more information if you want me to look into this issue. We have paid out on such issues before but there is no hard rule. In general we err on paying out if there is any question. We have paid out before when a submission wasn'
28.
▲
by
collingreene
13y ago
I work at facebook on the bug bounty program, if you have an email, name or ticket id I can look into it for you. There could be a few things going on here, maybe your bug was classified as low pri, maybe we misdiagnosed the bug. Speculatio
29.
▲
by
collingreene
14y ago
Because of the volume of reports we have settled on a scan every new item quickly, categorize it into severity and then respond. As you say it is a minor privacy issue so it looks like it went into a lower-pri area. I will make sure you hea
30.
▲
by
collingreene
14y ago
I work at facebook on our whitehat program. To clear this up we have not, and would never come after someone properly submitting bugs to us. Quite the opposite we are very appreciative when someone takes the time to find something and send
More ›