Hacker News new | ask | show | jobs
by collingreene 4840 days ago
I work at facebook on our whitehat program. To clear this up we have not, and would never come after someone properly submitting bugs to us. Quite the opposite we are very appreciative when someone takes the time to find something and send it our way. Everything is aligned around rewarding responsible disclosure instead of punishing its inverse.

Nir in particular is one of our best supporters (rough rankings https://www.facebook.com/whitehat/thanks/) we certainly have no intention to sue him or anyone submitting bugs to us. He even stopped by our office last week to talk about bugs.

Some external opinions of our program - https://www.eff.org/deeplinks/2010/12/knowledge-power-facebo...

1 comments

I reported a fairly minor privacy related leak and was curious how long you guys typically take to respond?
Because of the volume of reports we have settled on a scan every new item quickly, categorize it into severity and then respond. As you say it is a minor privacy issue so it looks like it went into a lower-pri area. I will make sure you hear back soon.
Thanks! I got a reply.