A security researcher discovered that a photo deleted from Instagram nearly two years prior was still present in the personal data backup download, appearing in three different folders. This violated Facebook's stated policy of removing deleted content within 90 days. After reporting the issue to Facebook's security team and a six-month resolution process, the researcher received a $550 bug bounty ($500 + $50 delay bonus) and was listed in the Hall of Fame 2021.

2m read timeFrom infosecwriteups.com
Post cover image

Sort: