Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

61–70 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#61
post #26
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Grabbing someone by the clothes like that? That's assault. Plain and simple. I'm sorry that the assault wasn't more violent?

Not in the UK the police only really get involved if blood is drawn aka GBH.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#62

> Because there is no SSL protection and because the API is wide open and vulnerable to abuse, it is possible to identify kiosks by their Mac address Eh?

It should have said "MAC address" [0]. Nothing to do with Apple Macintoshes. [0] https://en.wikipedia.org/wiki/MAC_address

That still doesn't make any sense to me in the context of the rest of the sentence.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#63
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Edit: the vulnerability still exists on many online exam styled pages.

Of course it does, half the fucking garbage software you use in a browser is using shitty client side validation.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#65
post #7

So is this still a vulnerability? Time to do some more digging boys!

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

> a great way to land yourself in federal prison.

For what? Checking shodan and seeing that people don't know how to write secure code.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#66
post #21

Earlier quoted context omitted.

Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.

I'm bothered by people being assaulted just as much as most of the commentators here. Just because I'm not parroting the same "wow Atrient is bad, security researchers good" message doesn't mean my comment is not valid. Obviously a security researcher that has reported an issue wants to have a healthy dialogue with the company and see that the flaw is patched in a reasonable time frame. But lets not pretend that we h…

> nobody actively exploiting this issue

No segmentation and plaintext communication literally means this would highly difficult to prove.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#67
post #21

Earlier quoted context omitted.

Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.

I'm bothered by people being assaulted just as much as most of the commentators here. Just because I'm not parroting the same "wow Atrient is bad, security researchers good" message doesn't mean my comment is not valid. Obviously a security researcher that has reported an issue wants to have a healthy dialogue with the company and see that the flaw is patched in a reasonable time frame. But lets not pretend that we h…

> ...doesn't Atrient have the right to patch this vulnerability on their own timeline rather than the researchers?

Sure, but you can't expect a third party to just stay quiet on the subject for as long as you drag your heels.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#69

Earlier quoted context omitted.

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

> a great way to land yourself in federal prison. For what? Checking shodan and seeing that people don't know how to write secure code.

For actively exploiting a bug in a piece of software for personal gain, which is much less defensible than simply finding vulnerabilities.
Post reply on HN