Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

31–40 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#31
post #15
post #8

Wouldn't the Nevada Gambling Commission be interested in this?

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it?

1. Yes. 2. Also yes.

The Nevada Gaming Commission, all of the big casino companies in its state, and the companies that make the gambling machines, are quite remarkable, technologically speaking.

Sometimes I think the terrible web sites they have for hotel reservations are just a smokescreen.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#32
Disclosing security vulnerabilities that aren't part of a bug bounty program takes a large amount of either courage or ignorance. Until there are protections in place for a given jurisdiction, far safer to leak it anonymously or just stay quiet. I was surprised that GDPR didn't contain any sort of protections for security researchers. The fines collected are hefty enough they could easily run a very successful bug bounty program.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#33
post #15

Earlier quoted context omitted.

I mean, maybe, but do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? My guess is they're still operating like it's the 1980s. Hopefully I'm wrong! Curious that the FBI now does vulnerability coordination. Haven't ever heard that before.

do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? 1. Yes. 2. Also yes. The Nevada Gaming Commission, all of the big casino companies in its state, and the companies that make the gambling machines, are quite remarkable, technologically speaking. Sometimes I think the terrible web sites they have for hotel reservations are just a smokes…

> Sometimes I think the terrible web sites they have for hotel reservations are just a smokescreen.

Captain Obvious says he'd imagine that the amount of money brought in from room reservations is a drop in the bucket to what is made on the casino floor, hence the comping of rooms for players. The money spent on reservations vs protecting the gaming would be in proportion to that.

Maybe Captain Obvious is being a bit simple minded, but makes sense. Everything about the hotel is geared to get you to lose your money in the casino.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#34
While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions with security researchers who are extremely arrogant and on a vendetta to show how smart they are, and drift from white hat to grey or in some cases black hat territory.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#37
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

I had to do "online traffic school" and noticed there were 2 javascript variables that were on a timer. If you set the variables correctly in the right order, the timer expired and it would let you go to the next page.

I spent the time figuring this out because I read exceptionally fast. When I've read a page in a few minutes and the timer forces me to sit there for an additional 13 minutes, I'm going to figure those things out. It was silly.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#39
Now that this is out in the open, I wonder how much longer Atrient will stay in business. These people sell these systems to casinos. Their customers are not going to like this at all.

Atrient mostly handles affinity cards and such. So they have lots of info about customers, including drivers license scans[1], but not much of a connection into the casino's main systems. A basic break-in might get you a suite upgrade or free booze. A more ambitious attacker would obtain the casino's customer list, with enough info to identify big losers and big winners.

[1] http://www.atrient.com/products/card-printing-enrollment/

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#40
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.

If only he were brutally beaten to provide you a more stimulating story.
Post reply on HN