Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

51–60 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#52

While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…

Does it matter what happened before?

Is there _any_ circumstance under which that's appropriate or even justifiable behaviour for a CxO, no matter what had happened in the preceding few moments? If your CxO isn't capable of maintaining professional behaviour in front of arrogant researchers or blackhats boasting in public, I'd suggest it's well past time to be polishing up your resume and moving on...

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#53

> Because there is no SSL protection and because the API is wide open and vulnerable to abuse, it is possible to identify kiosks by their Mac address Eh?

It should have said "MAC address" [0]. Nothing to do with Apple Macintoshes.

[0] https://en.wikipedia.org/wiki/MAC_address

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#54
post #39

Now that this is out in the open, I wonder how much longer Atrient will stay in business. These people sell these systems to casinos. Their customers are not going to like this at all. Atrient mostly handles affinity cards and such. So they have lots of info about customers, including drivers license scans[1], but not much of a connection into the casino's main systems. A basic break-in might get you a suite upgrade…

Regarding a "casino's main systems"..

Going back a few years I was involved with a gaming organisation. We were advised that certain activities legally had to be air gapped (we are not in the US), and I raised an issue of how it is that servers could be accessed by VNC (single dictionary word password) over the Internet if that were the case.

I was advised that the server was installed in a rack with 1RU of space between it and the router connecting it to the internet, and that lawyers had reviewed it and considered that to meet the legal definition.

I strongly suspect you'll find core activities just as vulnerable.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#56
post #7

So is this still a vulnerability? Time to do some more digging boys!

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

As if blackhats in Vladivostok are particularly afraid of the FBI. Once the vulnerability is public, if that stuff is still connected to the public Internet, game over.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#57
post #21

So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?

Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.

I'm bothered by people being assaulted just as much as most of the commentators here. Just because I'm not parroting the same "wow Atrient is bad, security researchers good" message doesn't mean my comment is not valid.

Obviously a security researcher that has reported an issue wants to have a healthy dialogue with the company and see that the flaw is patched in a reasonable time frame. But lets not pretend that we have all the facts here. Were they in the middle of an internal investigation? If that investigation showed that there was nobody actively exploiting this issue, doesn't Atrient have the right to patch this vulnerability on their own timeline rather than the researchers?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#59
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

> Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it. That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... : " Assault is sometimes d…

According to the article, this incident took place in London, not the US. The law is similar but slightly different. It would fall under "Common Assault":

https://www.sentencingcouncil.org.uk/blog/post/assault-offen...

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#60

Earlier quoted context omitted.

Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.

If only he were brutally beaten to provide you a more stimulating story.

[deleted]
Post reply on HN