Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity

    Facebook vs. Hackers: Win One, Lose One

    Written by

    Sean Michael Kerner
    Published August 20, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Facebook is one of the world’s most popular social networking destinations and a favorite target for hackers and security researchers alike. Two incidents this past week demonstrate the breadth and the limitations of Facebook’s current security model.

      In the first incident, a security researcher exposed a vulnerability in Facebook by publicly exploiting the account of founder Mark Zuckerberg. In the same time period, Facebook’s automated-scanning tool got tripped up by a false positive that led to an app outage.
      In the Mark Zuckerberg Facebook Wall attack, security researcher Khalil Shreateh reported that he found a flaw and alerted Facebook. Shreateh alleges that Facebook ignored his report, so he was left with no other recourse than to demonstrate his flaw by publicly attacking Zuckerberg’s Facebook wall.

      Facebook disagrees that Shreateh properly disclosed the flaw. A Facebook spokesperson told eWEEK that his company’s official response to the issue was made in a comment on the popular Hacker News discussion forum. In that response, Facebook engineer Matt Jones, noted that the researcher did not provide complete information and violated Facebook’s terms of service by testing the flaw on a real account, for which he had not obtained user consent.

      Facebook has a bug-bounty program that rewards researchers for properly disclosing flaws. Earlier this month, Facebook reported that it has paid out more than $1 million in bug bounties to researchers over the last two years.

      The Zuckerberg wall hacking incident and Facebook’s security programs overall are seen in both a positive and negative light by different security researchers.

      “The fact that Facebook has open channels of communication, and a bug-bounty program, are clearly things they are doing right,” WhiteHat Security CTO Jeremiah Grossman told eWEEK. “Unfortunately, in this case, a language barrier got in the way of a vulnerability report, but Facebook was able to respond very quickly and fix the issue before more people, other than their CEO, were impacted.”

      Chester Wisniewski, senior security advisor at Sophos, has a different viewpoint. Wisniewski noted that Facebook has long been understaffed for fielding security issues. “They liken their 1 billion users to that of a nation, yet are sorely under-invested in their national security,” Wisniewski said. “Having sufficient resources to address security concerns would likely have resulted in a more positive outcome.”

      The issue, said Ken Westin, a security researcher at Tripwire, is the communication channels available to researchers to communicate security issues to Facebook. “Initially, Facebook’s bug-bounty team ignored the vulnerability that Khalil Shreateh submitted, twice telling him it was not a bug,” Westin told eWEEK. “It was only after he exploited the hole that Facebook’s security team requested more information; unfortunately, this is all too common.”

      Facebook vs. Hackers: Win One, Lose One

      As it turns out, there is some angst in the security research community about the speed with which Facebook actually deals with security researchers overall.

      Matt Bergin, senior security consultant and project manager, CORE Security, told eWEEK that Facebook is notoriously slow when processing the payments for their bug-bounty program. Though he added that, in the Shreateh case, Facebook did act in accordance with its own stated policies for disclosure.

      “Many companies that offer bug-bounty programs incentivize researchers monetarily, but proper procedures must be executed by both the researcher and the vulnerable company involved,” Bergin said. “Researchers who participate in these programs have the obligation to follow these guidelines if they expect to be paid for their efforts.”

      Automated Scanning

      In addition to bug reports that researchers like Shreateh make to Facebook, the social networking giant also has a number of automated-scanning technologies in place. Last week, one of those automated-scanning technologies detected a malicious pattern in some Facebook Apps, which results in thousand of apps being shut down.

      While automated scanning can be a good thing, in this case there were a lot of false positives.

      “We started with a broad pattern that correctly matched many thousands of malicious apps but, unfortunately, also matched many of your high-quality apps,” Facebook engineer Eugene Zarakhovsky wrote . “When we detected this error, we immediately stopped the process and began work to restore access.”

      As is the case with the bug-reporting system, security researchers have different viewpoints on the effectiveness of Facebook’s automated-scanning technologies. WhiteHat’s Grossman said the technologies are, “necessary but not sufficient.”

      Tim Erlin, director of security and IT risk strategy at Tripwire told eWEEK that, in this case, it sounds like Facebook took the right actions to address the problem as soon as the company found it. “Their automated-scanning efforts are a requirement to run the application business they have,” Erlin said. “In cases where an error occurs, transparency is the right policy.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.