Hacker Newsnew | past | comments | ask | show | jobs | submit | yesmade's commentslogin

Those were other times. What stopped this researcher to share this on his personal blog to see if other people are able to see the same thing?


$3k for the facebook review bug. that's a little bit too much

- update

thanks for the downvotes guys. keep up the good work


The bounty actually surprised me, too. I expected between $1000-$2000. That is one of reasons I like reporting bugs to Facebook - they pay really good, critical bugs are fixed really fast (<1 day).

One time they paid me $5000 for a bug I never could have found, but they did internally based on my low severity report. (http://josipfranjkovic.blogspot.com/2013/11/facebook-bug-bou...)


It’s impressive that they are able to fix them so quickly – one needs to imagine they get a non-trivial number of reports, and that some majority of them are junk. They have a good triage + repro + escalation system.


Facebook puts out stats from their bug bounty program once a year. Most of bugs are invalid reports - in 2013 they had 14,763 reports, with 687 being valid.

(https://www.fb.com/818902394790655)

They probably got a couple people working exclusively on bug bounty reports. I also have to say they did a great job changing communication channels from emails to tickets which show in /support/, it is way easier now. The downside is that you must have a Facebook account, not sure if it was needed before the change.


congratulations on both findings


This bug actually seems quite critical imo, defeats the purpose of a feature and permits abuse/cheating


Who are you to say that it's "too much," when it's their money than they can spend as they wish?


> seems > too > much

relax guy nobody here is angry at the amount he made


I don't see "seems" anywhere in there. As written, it sounds extremely judgmental.


Instead of questioning why others are getting so much, question why you're getting so little.


chill out man. you are turning this into something personal. it was only a comment at the amount he got for cheating the review system. even the OP said he wasn't expecting that much.

stop jumping into the hate wagon everybody


I wasn't judging you, haha. I'm just saying, it makes more strategic sense in general to bring yourself up to the level of others (however inflated) rather than bring others down to yours.


Perhaps Gigablah was trying to be helpful?

HN can be frustrating if you provoke it. The problem isn't so much what you said as how you put it: the combination of dismissive tone and superficial content puts readers here on edge, because too many comments are like that and we all find them annoying. As a result it's easy to have your good intentions misread. If you had explained the thought process behind your comment, I think it would have been received better.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: