Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

41–50 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#41

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

After getting ignored even when the FBI got involved? What would be the right way then?

Probably through your lawyers.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#43
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

I suspect you were fired for trying and using the vulnerability (which you no doubt did merely to confirm your suspicion of it) rather than for bringing it forward, which merely provided the evidence for the reason for firing.

Though you probably would have done better to report the problem through the state authorities overseeing the contractor (or the general government oversight agency, like th Bureau of State Audits in California) rather than the contractor, to whom your report was a threat of revealing their poor performance.

If nothing else, a report to responsible state authorities would be less likely to meet with someone with an incentive to sweep it under the rug (especially a general oversight body) and would be more likely protected by whistleblower protections, which most states have in some form.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#45

Earlier quoted context omitted.

After getting ignored even when the FBI got involved? What would be the right way then?

Probably through your lawyers.

_their_ lawyers, I guess. Which would be paid out of their own pockets?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#46

With articles like this, I often to take out the horrible thing that the company is doing and post the quote to Hacker News, to give a sense of the scale of the issue; in this case me trying to do so would require including the majority of the article. It’s that bad. And yes, apparently the company thought it was ok for the COO to physically assault security researchers at a conference.

One of the Glassdoor reviews mentions the COO getting wasted at tradeshows, so maybe the assault is just normal behavior for him.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#47
post #39

Now that this is out in the open, I wonder how much longer Atrient will stay in business. These people sell these systems to casinos. Their customers are not going to like this at all. Atrient mostly handles affinity cards and such. So they have lots of info about customers, including drivers license scans[1], but not much of a connection into the casino's main systems. A basic break-in might get you a suite upgrade…

Well there was also this:

"...and that you could enter casino cash prize draws with as many entries as you wanted in order to win them, ..."

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#48

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

After getting ignored even when the FBI got involved? What would be the right way then?

[deleted]

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#49
post #32

Disclosing security vulnerabilities that aren't part of a bug bounty program takes a large amount of either courage or ignorance. Until there are protections in place for a given jurisdiction, far safer to leak it anonymously or just stay quiet. I was surprised that GDPR didn't contain any sort of protections for security researchers. The fines collected are hefty enough they could easily run a very successful bug bo…

I agree with you, but it isn't a clear cut issue. Attacking a server right now comes with some legal risk, which is a deterrent to some. It's impossible to tell white hats from black. If it were paired with a law that made it a felony to resell vulns to third parties then it would be much more robust.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#50
post #32

Disclosing security vulnerabilities that aren't part of a bug bounty program takes a large amount of either courage or ignorance. Until there are protections in place for a given jurisdiction, far safer to leak it anonymously or just stay quiet. I was surprised that GDPR didn't contain any sort of protections for security researchers. The fines collected are hefty enough they could easily run a very successful bug bo…

I agree with you, but it isn't a clear cut issue. Attacking a server right now comes with some legal risk, which is a deterrent to some. It's impossible to tell white hats from black. If it were paired with a law that made it a felony to resell vulns to third parties then it would be much more robust.

The only way you're going to reduce the amount of vulnerabilities being sold on black markets is to provide sufficient financial and social incentive. There are enough people with dubious morals who don't care how illegal it is to find and exploit them, who will eagerly take the biggest payday. Combine no guarantee you'll get paid, poor treatment by authorities and employers and the (albeit low) risk of getting your shit kicked in, I'm not surprised people aren't lining up at the door to report vulnerabilities.
Post reply on HN