Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So, to summarize, you go to bank and you say "your back door is vulnerable can you check", instead of checking and giving you some kind of praise, they call police to beat the hell out of you...

This is exactly sort of thing that will make community of white hackers stop caring, and leave open door to foreign agency malicious hackers to do as they please.

I would like to know what was really going inside of their heads, was someone internally trying to steal the thunder, was it vanity/pride, was it lack of funds?!, was it fear?



I think the issue was he went into the back door, and then found a key, and then started unlocking more doors. In other words, he used the initial bug to escalate access into their systems. Which is pretty obvious a no-no.


Why? He jimmied a lock. A bank should not use a padlock. He found a key and found a dead end... oh no, in the dusty closet there was another lost key. That one shouldn't be there... wait the old key opens everything? Oh no.

Privilege escalation is explicitly allowed by facebook. He escalated.


By the way while reading this, I was expecting happy ending, something nice to start the day, but, alas, this is almost like a heavy Russian drama, starts with light tone and ends so depressive I would rather go back to bed crawling under the blanker and into fetal position.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: