Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

71–80 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#71
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Yeap. Kill the Messenger is the default setting. It's a miracle Snowden is still alive.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#73
post #26

Earlier quoted context omitted.

Grabbing someone by the clothes like that? That's assault. Plain and simple. I'm sorry that the assault wasn't more violent?

Not in the UK the police only really get involved if blood is drawn aka GBH.

So you're saying that in the UK I can legally walk around shoving and slapping people at random?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#74
post #21

Earlier quoted context omitted.

Anything else bothers you about this story? Because how they chose to contact Atrient seem like the very unimportant detail in all this.

I'm bothered by people being assaulted just as much as most of the commentators here. Just because I'm not parroting the same "wow Atrient is bad, security researchers good" message doesn't mean my comment is not valid. Obviously a security researcher that has reported an issue wants to have a healthy dialogue with the company and see that the flaw is patched in a reasonable time frame. But lets not pretend that we h…

Don't these security researchers have the right to go to a conference and talk to other attendees?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#76
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Edit: the vulnerability still exists on many online exam styled pages.

Sorry you got fired from your old job. Sounds like your new job could be "pay a dollar to skip the exam."

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#77
post #46

With articles like this, I often to take out the horrible thing that the company is doing and post the quote to Hacker News, to give a sense of the scale of the issue; in this case me trying to do so would require including the majority of the article. It’s that bad. And yes, apparently the company thought it was ok for the COO to physically assault security researchers at a conference.

One of the Glassdoor reviews mentions the COO getting wasted at tradeshows, so maybe the assault is just normal behavior for him.

Weird, I've gotten "wasted" at tradeshows but never assaulted anyone :)

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#78

Earlier quoted context omitted.

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

As if blackhats in Vladivostok are particularly afraid of the FBI. Once the vulnerability is public, if that stuff is still connected to the public Internet, game over.

I'm pretty sure this article is all that was required for some enterprising people to do their own research and find some of the same vulnerabilities. I imagine we might see some interesting damages outlined in some lawsuits from casinos against Atrient.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#79

Earlier quoted context omitted.

It should have said "MAC address" [0]. Nothing to do with Apple Macintoshes. [0] https://en.wikipedia.org/wiki/MAC_address

That still doesn't make any sense to me in the context of the rest of the sentence.

Possibly, existing kiosks are registered by MAC address in the API. By querying the API for registered kiosks, you can pretend to be one by spoofing the MAC

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#80

Earlier quoted context omitted.

do you really think they have some sort of well-staffed cyber-division that would 1. understand this and 2. know what to do with it? 1. Yes. 2. Also yes. The Nevada Gaming Commission, all of the big casino companies in its state, and the companies that make the gambling machines, are quite remarkable, technologically speaking. Sometimes I think the terrible web sites they have for hotel reservations are just a smokes…

> Sometimes I think the terrible web sites they have for hotel reservations are just a smokescreen. Captain Obvious says he'd imagine that the amount of money brought in from room reservations is a drop in the bucket to what is made on the casino floor, hence the comping of rooms for players. The money spent on reservations vs protecting the gaming would be in proportion to that. Maybe Captain Obvious is being a bit…

Everything about the hotel is geared to get you to lose your money in the casino.

That's last century thinking. Gambling's influence on the bottom line domestically is waning.

These days it's all about entertainment, clubs, and restaurants. That's why every casino in Las Vegas is falling all over itself to build new sports and entertainment arenas, and paying huge bucks to put celebrity chef names on their restaurants.

Post reply on HN