Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Facebook refuses again to pay exploit bounty (ehrazahmed.blogspot.in)
5 points by tailbalance on Sept 5, 2013 | hide | past | favorite | 2 comments



I'm a software engineer at Facebook working on security and privacy. This is simply a hoax. The html source shown in the video clearly says "No test user was deleted". We've verified in our logs that the victim account was manually deactivated by visiting https://www.facebook.com/deactivate.php. Anyone can visit https://www.facebook.com/whitehat/accounts/ and verify that the query parameter used by this endpoint is selected_test_users not selected_users. We've also audited our code to verify that there's no variant of this exploit that works against that endpoint or any other that we've found. In fact, the most recent code change to this endpoint was in April and was routine maintenance that had no security implications.


Hope he doesn't try to prove his point like the other guy did with Zucker's account.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: