Facebook has recognised that it has to encourage more researchers to look into security vulnerabilities, after the social networking giant updated its bug disclosure policy.

Facebook has long encouraged researchers to let the company know about security issues they uncover and give the social networking giant time to address them before going public. However, due to its wording, there was concern the previous policy could give the impression bug submitters could be victims of retaliatory action.

“This was a change to clarify the language in an existing policy so that security researchers feel more comfortable working with us when they find a vulnerability,” explained Ryan McGeehan, manager of security incident response for Facebook. “This was a change to clarify the language in an existing policy so that security researchers feel more comfortable working with us when they find a vulnerability.”

Change Needed

“The previous version could have been read to mean that we might take enforcement action against someone for researching and discovering a bug,” he added. “This wasn’t our intention, and so we’ve changed it to read less strictly. We made the change about a week and a half ago.”

The new policy states that: “If you share details of a security issue with us and give us a reasonable period of time to respond to it before making it public, and in the course of that research made a good faith effort to avoid privacy violations, destruction of data, or interruption or degradation of our service, we will not bring any lawsuit against you or ask law enforcement to investigate you for that research.”

The issue of responsibility disclosure has continued to be a point of contention in the security community. Some vendors, such as Google and Mozilla, have taken to offering monetary rewards as incentives for researchers to share bugs in their products directly with them.

Legal Fears

“Well-meaning Internet users are often afraid to tell companies about security flaws they’ve found – they don’t know whether they’ll get hearty thanks or slapped with a lawsuit or even criminal prosecution,” blogged Marcia Hofmann, senior staff attorney with the Electronic Frontier Foundation (EFF). “This tension is unfortunate, because when companies learn what needs to be fixed, their services will be better and their users safer.”

Facebook worked with the EFF to draft the new policy, McGeehan said.

“Security is a top priority for us, and we invest lots of resources in protecting our site and the people who use it from attacks,” he said. “Like any web service as complex as Facebook, however, we occasionally have a vulnerability in our code. We hire the most qualified and highly-skilled engineers and security professionals we can find, but we also know that there’s an entire community of very smart and talented security researchers outside Facebook who want to do the right thing. This policy allows that community to work with us more easily so we can fix vulnerabilities quickly and before they’re exploited.”

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

View Comments

Share
Published by
Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago