So is this still a vulnerability? Time to do some more digging boys!
Security Researcher Assaulted Following Vulnerability Disclosure
51–60 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#52While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…
Is there _any_ circumstance under which that's appropriate or even justifiable behaviour for a CxO, no matter what had happened in the preceding few moments? If your CxO isn't capable of maintaining professional behaviour in front of arrogant researchers or blackhats boasting in public, I'd suggest it's well past time to be polishing up your resume and moving on...
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#53> Because there is no SSL protection and because the API is wide open and vulnerable to abuse, it is possible to identify kiosks by their Mac address Eh?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#54Now that this is out in the open, I wonder how much longer Atrient will stay in business. These people sell these systems to casinos. Their customers are not going to like this at all. Atrient mostly handles affinity cards and such. So they have lots of info about customers, including drivers license scans[1], but not much of a connection into the casino's main systems. A basic break-in might get you a suite upgrade…
Going back a few years I was involved with a gaming organisation. We were advised that certain activities legally had to be air gapped (we are not in the US), and I raised an issue of how it is that servers could be accessed by VNC (single dictionary word password) over the Internet if that were the case.
I was advised that the server was installed in a rack with 1RU of space between it and the router connecting it to the internet, and that lawyers had reviewed it and considered that to meet the legal definition.
I strongly suspect you'll find core activities just as vulnerable.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#55Re: Security Researcher Assaulted Following Vulnerability Disclosure
#56So is this still a vulnerability? Time to do some more digging boys!
In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#57So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?
Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.
Obviously a security researcher that has reported an issue wants to have a healthy dialogue with the company and see that the flaw is patched in a reasonable time frame. But lets not pretend that we have all the facts here. Were they in the middle of an internal investigation? If that investigation showed that there was nobody actively exploiting this issue, doesn't Atrient have the right to patch this vulnerability on their own timeline rather than the researchers?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#58People are complaining a lot about GDPR here but such a case would definitely lead to a fine of 4% or 8% of atrients revenue.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#59... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
> Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it. That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... : " Assault is sometimes d…
https://www.sentencingcouncil.org.uk/blog/post/assault-offen...
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#60Earlier quoted context omitted.
Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.
If only he were brutally beaten to provide you a more stimulating story.