• smeg@feddit.uk
    link
    fedilink
    English
    arrow-up
    85
    ·
    6 days ago

    There were also SSH key files.

    I’m not publishing the archive, keys, or session logs.

    I submitted the report and findings using Meta’s bug bounty program. Meta marked the report “Not Applicable.”

    Guess they don’t care if you publish the SSH keys then?

    • docktordreh@discuss.tchncs.de
      link
      fedilink
      arrow-up
      21
      ·
      6 days ago

      They’ve probably rotated the keys since they were notified of the security breach.

      But yes, companies that act this way undermine the resolve to disclose their security vulnerabilities.

    • Dr. Moose@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      6 days ago

      Ssh keys to what? If the key is used for user operations, not internal then there’s no security breach here other than deobfuscation.