Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

91–100 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#92
post #9

I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week

Online cbts like that are mostly honor system and there’s a zillion ways to get around then.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#93
post #2

If you (like me) didn't know what a Shodan safari is, you're in for a fun ride: https://techcrunch.com/2019/01/21/shodan-safari/

Without Oath's abusive GDPR wall: https://outline.com/JF28AH

How can outline legally host another website's content?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#94
post #77
post #46

Earlier quoted context omitted.

One of the Glassdoor reviews mentions the COO getting wasted at tradeshows, so maybe the assault is just normal behavior for him.

Weird, I've gotten "wasted" at tradeshows but never assaulted anyone :)

Angry drunk vs. happy drunk is a good zeroth-order personality test.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#95
post #88

Earlier quoted context omitted.

I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.

> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx

I've used quite a few systems where the MAC address is used as a secondary password to verify that someone didn't just steal the hard drive out of a kiosk.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#96
post #88

Earlier quoted context omitted.

I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.

> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx

I thought of this. But the OP stated that the traffic is unprotected making this security measure moot.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#97
post #26
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

Grabbing someone by the clothes like that? That's assault. Plain and simple. I'm sorry that the assault wasn't more violent?

I'm not saying it's not assault. I'm saying that wasn't worth my time to read half a novel of backstory for.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#98

Earlier quoted context omitted.

Agreed, the "assault" was a big let down. But it did serve as a good hook to draw more attention to this company's awful security practices and apparent unwillingness to fix them.

If only he were brutally beaten to provide you a more stimulating story.

If only they hadn't put it on so thick, we wouldn't have had our time wasted with something that it turns out, after reading nearly to the end, we didn't want to read.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#99
post #23

... so more than two thousand words into the article , having built up to the title of "assaulted" in the context of casinos (which have a movie reputation of hiring big boys to beat you up for things like counting cards and, apparently, vulnerability disclosure), and being a security guy myself, this is the entirety of the assault: > When one of the security researchers [approached Jessie at a conference] and introd…

> Jessie suddenly lunged at the researcher and violently grabbed him by his clothes on his chest before then tearing his attendee badge away from him, telling the researcher that he didn't need it anymore and that he would keep hold of it. That seems to meet the legal criteria for assault and possibly even battery. Quoting from https://www.nolo.com/legal-encyclopedia/assault-battery-aggr... : " Assault is sometimes d…

I'm not saying it's not assault. I'm not arguing legal definitions either. I'm saying it didn't live up to the expectation that the title and first paragraph created, and that it was long winded, causing me to say it was not worth my time.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#100

This is not the first time Atrient has been sloppy with the details of their NDAs, nor the first time Jessie Gill has gotten in trouble for being a touch too eager to get physical. https://www.leagle.com/decision/infdco20180828d81

Hahahaha, how terrible is Atrient's lawyer, Mark E. Ferrario, for filing a complaint that didn't even allege a cause of action?!

He just asked the court to do some random stuff without arguing a case. The whole opinion is just, "Plaintiff didn't allege anything, so dismissed".

Post reply on HN