Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think we post any details about the exploit, just the fact that someone reported it (see https://www.facebook.com/whitehat). Of course, once we've fixed the bug, the reporter is free to write about the exploit, how long it was live, etc.


I did not mean details about the exploit but details about what the exploit enabled an attacker to do/see.


Yeah, after it's been fixed the person who discovered it is welcome to post details about what it would allow an attacker to do / see / etc.


I think what the OP is trying to say, is that Fackbook (as the custodian of our private data) should make available a list of resolved exploits such that we may be aware of potential data leaks.

Eg - up until today, and for who knows how long, photos you thought were private may have been accessed by undesireables.


Yes. In my opinion a website that is open and honest about its caring about privacy would do that.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: