Facebook and security researcher clash over disclosure best practices and compensation over Instagram bug and researcher's further systems probing
Very disturbing story of Facebook bug bounty failure Pete Cheslock / @petecheslock : Forgetting about the drama. This is a great write up showing how lateral movement works to get data extracted. http://exfiltrated.com/... Marc Smeets / @mramsmeets : Well, if you leave room for ambiguity in your bug bounty rules, this is what happens. http://www.facebook.com/... http://exfiltrated.com/...
Context & Ripple Effects
The day before this piece, Facebook and researcher Pete Cheslock had already gone public over an Instagram vulnerability in the related coverage of their sparring over disclosure and payment. What escalates here is scope: Cheslock went beyond reporting the bug, probing deeper into Facebook systems and publishing a write-up showing how lateral movement could be used for data extraction.
The dispute lands on a program Facebook had been scaling aggressively — it had just reported paying 321 researchers $1.3M across 2014 and adding Oculus and Moves to bounty scope. As commentator Marc Smeets notes, ambiguous bug-bounty rules are what leave room for exactly this kind of fight.
First-order effects
- Facebook must decide whether to pay for work outside the letter of its bounty rules, while Cheslock's published exfiltration walkthrough hands other researchers a template for testing how far past a single bug they can go before losing eligibility.
Second-order effects
- Other vendors running bounty programs face pressure to write explicit scope boundaries — the ambiguity Facebook left open becomes the case study competitors cite when tightening their own terms.
- Researchers recalibrate risk: if deep probing can void compensation even after a valid find, some will cap reports at the minimum scoping or demand terms up front, shrinking the depth of coverage programs get.
Third-order effects
- If disputes like this keep surfacing, bounty programs drift from informal goodwill arrangements toward formalized contracts — a direction consistent with Facebook's later move to expand scope formally to third-party apps in the access-token expansion and its Hacker Plus loyalty scheme, though critics argue formalization can shade into buying silence, as raised around NDAs and researcher-silence concerns.
The trend: Bug bounty programs are evolving from ad-hoc goodwill payouts into explicitly contracted relationships whose rules, scope boundaries, and incentives are contested in public.