Jump to content

Facebook pays $15,000 to researcher for finding a bug

This story is originally from Verge.com:

http://www.theverge.com/2016/3/8/11179926/facebook-account-security-flaw-bug-bounty-payout

 

This could have been a big security risk.

 

Quote

Prakash noticed those protections were missing on beta.facebook.com, where developers often deploy new features that aren't ready for facebook.com. But since every Facebook account is also available on beta.facebook.com, the resulting bug let him flood the page with PIN guesses, effectively letting him break into any account he wanted.

It boggles the mind why Facebook would mirror live accounts on their beta page. It should have been only for those who opt-in for the beta. But in anycase, it was good this was reported before some nafarius people could use the technique.

 

Kudos to Facebook for taking bug bounty very seriously. Apparenly they've awarded over $4m already. Damn...

Link to comment
Share on other sites

Link to post
Share on other sites

Many thanks to the guy who found the bug, however Facebook's concern for privacy and security is laughable.

Link to comment
Share on other sites

Link to post
Share on other sites

Wow they actually paid out??? Didn't they refuse to pay the last guy who found a bug? Well in that case I think he actually demonstrated before revealing lol

 

$15K sounds low for something potentially lawsuit worthy, but good on that guy. 

"Solus" (2015) - CPU: i7-4790k | GPU: MSI GTX 970 | Mobo: Asus Z97-A | Ram: 16GB (2x8) G.Skill Ripjaws X Series | PSU: EVGA G2 750W 80+ Gold | CaseFractal Design Define R4

Next Build: "Tyrion" (TBA)

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×