Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

21–30 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#21

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#22
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

In that case you fail the test for showing a lack of ethics ;)

I would say the state failed the ethics test for firing him.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#23
... so more than two thousand words into the article, having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault:

> When one of the security researchers [approached Jessie at a conference] and introduced himself as the researcher who Jessie had been dealing with, Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it.

It was in front of other people, at a conference, and all that the article admits to happening is "grabbing by clothes", "taking his badge", and angry words.

That was not worth my time.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#24
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#25
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Physically threatening a security researcher for finding vulnerabilities in a product you sell is a big no-no, regardless of whether you find it to be "assault" or not. Personally, I found the background into the vulnerabilities the researcher found to be interesting.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#26
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Grabbing someone by the clothes like that? That's assault. Plain and simple. I'm sorry that the assault wasn't more violent?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#27

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

It takes days to turn around an NDA. If months have passed, the vendor is obviously stalling.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#28
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

In that case you fail the test for showing a lack of ethics ;)

We don't have the full details but presumably this was on a single test at the beginning of the class.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#29
post #15
post #8

Wouldn't the Nevada Gambling Commission be interested in this?

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

I've not dealt with the NGC directly -- only other gaming commissions and some NGC partners -- but everyone I've dealt with in gambling has cared deeply about security. They often get it wrong, but they take this stuff very seriously.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#30
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

> Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it.

That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... :

"Assault is sometimes defined as any intentional act that causes another person to fear that she is about to suffer physical harm. This definition recognizes that placing another person in fear of imminent bodily harm is itself an act deserving of punishment, even if the victim of the assault is not physically harmed."

"Historically, battery and assault were considered separate crimes, with battery requiring that the aggressor physically strike or offensively touch the victim. In that way, a battery was a “completed” assault. Many modern statutes don't bother to distinguish between the two crimes, as evidenced by the fact that the phrase "assault and battery" has become as common as "salt and pepper." These days, statutes often refer to crimes of actual physical violence as assaults."

Post reply on HN