Skip to main content
  1. Home
  2. Social Media
  3. Legacy Archives

Facebook pays $33k to security researcher for finding, reporting huge bug in social network

Add as a preferred source on Google

Facebook just made the company’s largest payout ever to a security researcher who discovered a bug so large he could’ve hijacked an entire network server. 

According to ZDNet, Facebook paid Brazilian computer engineer Reginaldo Silva $33,500 for reporting a major bug to Facebook. Silva has been testing the type of bug he eventually found on Facebook since 2012, earning a much-smaller $500 bounty from Google after he found a related security issue by running a code on one of their servers. Silva detailed how he discovered the Google bug and moved on to discover the much-larger Facebook bug in a blog post. Although he’d been testing this particular type of bug for years, he’d only discovered how it applied to Facebook and worked on the problem for two days before he hacked the system and reported the problem. 

Recommended Videos

Facebook addressed the bug and the bounty they paid Silva yesterday with a post by the Facebook Bug Bounty team, which awards money to white-hat hackers who tell the social network about vulnerabilities they’ve discovered. 

Many Facebook users commented on the post, expressing disappointment at Facebook’s payment rate, which they felt to be too low. But hopefully the publicity will help Silva get hired at another large tech company (or Facebook itself). 

And Silva isn’t giving up his quest to rid Facebook of bugs. “This is not my first security bug submitted to them, and it certainly won’t be the last. My goal is to keep finding high-impact security flaws,” he told Digital Trends via email.

Kate Knibbs
Former Contributor
Kate Knibbs is a writer from Chicago. She is very happy that her borderline-unhealthy Internet habits are rewarded with a…
Topics
Instagram is finally giving your old posts a soundtrack do-over
Instagram lets creators refresh old posts without nuking their engagement
Opening settings in Instagram

Instagram is rolling out a Replace Audio feature that lets users change the in-app music attached to feed posts and carousels after they have already been published. The original post stays live throughout the process, preserving its likes, comments, and shares.

Your post keeps all its engagement

Read more
X finally rebuilt its neglected Android app, and it only took a year
X’s Android app was so rough, the company rebuilt the whole thing
X Android app gets a complete overhaul

Android users have spent years receiving the rougher version of X. Now, the company has finally decided that patching the old app was no longer enough. X has released a completely rebuilt Android app following nearly a year of development. Existing users can access it by installing the latest update through the Google Play Store, so there is no separate replacement app to download.

X tore the old foundation out

Read more
New X phishing scam uses fake login alerts to steal your account
Scammers have copied X's own security emails almost pixel for pixel, and people are falling for it.
X app store listing on iPhone

You open your inbox and see an alert claiming someone just logged into your X account from an unfamiliar device. Your first instinct is to click through and lock things down immediately. That instinct is exactly what a new phishing scam is counting on.

As reported by The Guardian, a wave of fake X security emails is currently doing the rounds. They claim a new device has logged into your account and urge you to click a link to reset your password or review app access. 

Read more