Hacker News new | ask | show | jobs
by jaxb 4690 days ago
facebook's communication skills were not stellar either ('this is not a bug').

If you are taking reports from users about security problems, treat every one as real until proven otherwise.

1 comments

If you get over 90% fail rate?

If you say you will pay 500Bucks per Bug reported, you will have a huge Fail rate, even if the Facebook Support is well Motivated after 3hours working, answering to 100Tickets you might not be able to understand something written in that way:

"Rhe vulnerability allow’s facebook users to share posts to non friends facebook users , i made a post to sarah.goodin timeline and i got success post … of course you may cant see the link because sarah’s timeline friends posts shares only with her friends , you need to be a friend of her to see that post or you can use your own authority ."

Yes.

a) it's called triage and b) you won't want to miss that one report that blows your security wide open.

The point is moot now, facebook says they took note and will ask for more details from now on.