Facebook has decided to help security researchers by adding a new special option to its accounts, called "Whitehat Settings".
But how can this new option be useful to researchers? By introducing a mechanism that allows bypassing Facebook's security mechanism, Certificate Pinning.
Certificate Pinning is there for security reasons. However, with the introduction of the new setting, “Whitehat Settings,” researchers are given the opportunity to gain access to an account if they need to check something. This is because with the new setting, Facebook will “break” Certificate Pinning for that specific account.
Facebook took this action because researchers were having difficulty bypassing the security mechanism.
The new “Whitehat Settings” option will be available on Facebook, Messenger, and Instagram. However, it is only supported on Facebook’s Android apps, not iOS. The new feature has its own settings (ability to disable Facebook’s TLS 1.3 support, ability to use certificates, built-in proxy).
HowFacebook decide to help security researchers?
Facebook has always been on the side of the infosec community and is one of the few companies that actively supports security research. It has its own bug bounty program and offers security tools.
Facebook has been in the spotlight lately due to leaks. After the scandals, it is doing everything it can to strengthen security on its main platform and in its mobile applications. It has expanded its bug bounty program considerably and has offered large sums of money to researchers who discover vulnerabilities in its platform and its other applications. It also offers rewards (up to $40,000) to researchers who discover significant vulnerabilities that cause users to lose control of their accounts and capture by hackers.
