Security Researcher Assaulted Following Vulnerability Disclosure
91–100 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#92I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#93Re: Security Researcher Assaulted Following Vulnerability Disclosure
#94Earlier quoted context omitted.
One of the Glassdoor reviews mentions the COO getting wasted at tradeshows, so maybe the assault is just normal behavior for him.
Weird, I've gotten "wasted" at tradeshows but never assaulted anyone :)
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#95Earlier quoted context omitted.
I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.
> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#96Earlier quoted context omitted.
I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.
> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#97... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
Grabbing someone by the clothes like that? That's assault. Plain and simple. I'm sorry that the assault wasn't more violent?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#98Earlier quoted context omitted.
Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.
If only he were brutally beaten to provide you a more stimulating story.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#99... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…
> Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it. That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... : " Assault is sometimes d…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#100This is not the first time Atrient has been sloppy with the details of their NDAs, nor the first time Jessie Gill has gotten in trouble for being a touch too eager to get physical. https://www.leagle.com/decision/infdco20180828d81
He just asked the court to do some random stuff without arguing a case. The whole opinion is just, "Plaintiff didn't allege anything, so dismissed".