Skip to main content

Facebook pays $33k to security researcher for finding, reporting huge bug in social network

facebook pays 33500 to hacker for finding security bug sign login
Image used with permission by copyright holder

Facebook just made the company’s largest payout ever to a security researcher who discovered a bug so large he could’ve hijacked an entire network server. 

According to ZDNet, Facebook paid Brazilian computer engineer Reginaldo Silva $33,500 for reporting a major bug to Facebook. Silva has been testing the type of bug he eventually found on Facebook since 2012, earning a much-smaller $500 bounty from Google after he found a related security issue by running a code on one of their servers. Silva detailed how he discovered the Google bug and moved on to discover the much-larger Facebook bug in a blog post. Although he’d been testing this particular type of bug for years, he’d only discovered how it applied to Facebook and worked on the problem for two days before he hacked the system and reported the problem. 

Facebook addressed the bug and the bounty they paid Silva yesterday with a post by the Facebook Bug Bounty team, which awards money to white-hat hackers who tell the social network about vulnerabilities they’ve discovered. 

Many Facebook users commented on the post, expressing disappointment at Facebook’s payment rate, which they felt to be too low. But hopefully the publicity will help Silva get hired at another large tech company (or Facebook itself). 

And Silva isn’t giving up his quest to rid Facebook of bugs. “This is not my first security bug submitted to them, and it certainly won’t be the last. My goal is to keep finding high-impact security flaws,” he told Digital Trends via email.

Topics
Kate Knibbs
Former Digital Trends Contributor
Kate Knibbs is a writer from Chicago. She is very happy that her borderline-unhealthy Internet habits are rewarded with a…
Bluesky barrels toward 1 million new sign-ups in a day
Bluesky social media app logo.

Social media app Bluesky has picked nearly a million new users just a day after exiting its invitation-only beta and opening to everyone.

In a post on its main rival -- X (formerly Twitter) -- Bluesky shared a chart showing a sudden boost in usage on the app, which can now be downloaded for free for iPhone and Android devices.

Read more
How to make a GIF from a YouTube video
woman sitting and using laptop

Sometimes, whether you're chatting with friends or posting on social media, words just aren't enough -- you need a GIF to fully convey your feelings. If there's a moment from a YouTube video that you want to snip into a GIF, the good news is that you don't need complex software to so it. There are now a bunch of ways to make a GIF from a YouTube video right in your browser.

If you want to use desktop software like Photoshop to make a GIF, then you'll need to download the YouTube video first before you can start making a GIF. However, if you don't want to go through that bother then there are several ways you can make a GIF right in your browser, without the need to download anything. That's ideal if you're working with a low-specced laptop or on a phone, as all the processing to make the GIF is done in the cloud rather than on your machine. With these options you can make quick and fun GIFs from YouTube videos in just a few minutes.
Use GIFs.com for great customization
Step 1: Find the YouTube video that you want to turn into a GIF (perhaps a NASA archive?) and copy its URL.

Read more
I paid Meta to ‘verify’ me — here’s what actually happened
An Instagram profile on an iPhone.

In the fall of 2023 I decided to do a little experiment in the height of the “blue check” hysteria. Twitter had shifted from verifying accounts based (more or less) on merit or importance and instead would let users pay for a blue checkmark. That obviously went (and still goes) badly. Meanwhile, Meta opened its own verification service earlier in the year, called Meta Verified.

Mostly aimed at “creators,” Meta Verified costs $15 a month and helps you “establish your account authenticity and help[s] your community know it’s the real us with a verified badge." It also gives you “proactive account protection” to help fight impersonation by (in part) requiring you to use two-factor authentication. You’ll also get direct account support “from a real person,” and exclusive features like stickers and stars.

Read more