Mark Zuckberg's Facebook page hacked to highlight flaw

Programmer tried to alert Facebook to the bug but was ignored and so took more direct action

James Vincent
Monday 19 August 2013 14:07 BST
Comments
Facebook CEO Mark Zuckerberg prepares to speak at a news conference at Facebook headquarters July 6, 2011 in Palo Alto, California.
Facebook CEO Mark Zuckerberg prepares to speak at a news conference at Facebook headquarters July 6, 2011 in Palo Alto, California. (Justin Sullivan/Getty)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Mark Zuckerberg’s Facebook page was hacked by a Palestinian programmer keen to highlight to the company the flaw he had found in their code.

The exploit allowed Khalil Shreateh to post on Zuckerberg’s wall (see below) even though he was not authorised to do so. Shreateh posted his message after he tried to alert Facebook about the flaw but was told that it was “not a bug”.

“Dear Mark Zuckerberg,” read Shreateh's message. “First sorry for breaking your privacy and post [sic] to your wall, I has no other choice to make after all the reports I sent to Facebook team.”

The reports sent by Shreateh were to Facebook’s a Whitehat program; a bounty scheme that offers rewards to programmers that flag up potential security bugs.

The minimum reward for a successful report is $500 and Facebook states that “there is no maximum reward: each bug is awarded a bounty based on its severity and creativity”. The company claims to have paid out more than $1 million so far.

Minutes after posting on Zuckerberg’s page Shreateh was contacted by Facebook’s security engineers and his account temporarily suspended. Facebook refused to pay Shreateh for flagging up the flaw as by posting on Zuckerberg’s page he had violated the company’s Terms of Service.

Facebook engineer Matt Jones made a public statement, noting that his team “fixed this bug on Thursday.” Jones noted that the Facebook team receives hundreds of reports each day, many of which are “nonsense or misguided”. He did admit however that they “should have pushed back asking for more details here”.

The post by Khalil Shreateh on Mark Zuckberg's Facebook wall. Credit: Khalil Shreateh/Facebook
The post by Khalil Shreateh on Mark Zuckberg's Facebook wall. Credit: Khalil Shreateh/Facebook (Khalil Shreateh/Facebook)

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in