Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

101–110 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#101

This is not the first time Atrient has been sloppy with the details of their NDAs, nor the first time Jessie Gill has gotten in trouble for being a touch too eager to get physical. https://www.leagle.com/decision/infdco20180828d81

Geez, what a creep and psychopath. This is what happens when someone thinks that they are too rich to follow the rules of society.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#104
post #98

Earlier quoted context omitted.

If only he were brutally beaten to provide you a more stimulating story.

If only they hadn't put it on so thick, we wouldn't have had our time wasted with something that it turns out, after reading nearly to the end, we didn't want to read.

>... we...

Seems like a lot of other people in this thread found it interesting and enjoyed the read. Who's the "we" that you're speaking for here?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#105
post #87
post #73

Earlier quoted context omitted.

So you're saying that in the UK I can legally walk around shoving and slapping people at random?

No, thats not what he said.

> No, thats not what he said.

No, that's the implication of what they said. If the police don't get involved in bloodless physical assaults then who is going to intervene? Does one have to call out "no slapbacks"?

Or to put it another way, I'm very dubious that one could merrily slap their way down the Thames without the police showing up.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#106

While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…

I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that that video could tie to later. Anyway, I wasn't there so I can't be 100% sure of anything, but I have known Jessie for years, hell I've been to his house several times, and the behavior is spot on.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#107

People are complaining a lot about GDPR here but such a case would definitely lead to a fine of 4% or 8% of atrients revenue.

I think I'll submit a Subject Access Request, as I am sure I'm a member of the Caesars loyalty programme.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#108

Earlier quoted context omitted.

I agree with you, but it isn't a clear cut issue. Attacking a server right now comes with some legal risk, which is a deterrent to some. It's impossible to tell white hats from black. If it were paired with a law that made it a felony to resell vulns to third parties then it would be much more robust.

The only way you're going to reduce the amount of vulnerabilities being sold on black markets is to provide sufficient financial and social incentive. There are enough people with dubious morals who don't care how illegal it is to find and exploit them, who will eagerly take the biggest payday. Combine no guarantee you'll get paid, poor treatment by authorities and employers and the (albeit low) risk of getting your…

I agree completely, but the issue is that the vulnerability value is asymmetric. It's about $1m to get an iPhone no-click RCE. Up to about $4m for one with a seemingly long shelf life. Apple is not going to pay $Xm for their bug bounty.

That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain classes of vulnerability sale as an act of terrorism or treason or arms export violation.

I know it is hard, but we have to try to solve this.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#109

Earlier quoted context omitted.

The only way you're going to reduce the amount of vulnerabilities being sold on black markets is to provide sufficient financial and social incentive. There are enough people with dubious morals who don't care how illegal it is to find and exploit them, who will eagerly take the biggest payday. Combine no guarantee you'll get paid, poor treatment by authorities and employers and the (albeit low) risk of getting your…

I agree completely, but the issue is that the vulnerability value is asymmetric. It's about $1m to get an iPhone no-click RCE. Up to about $4m for one with a seemingly long shelf life. Apple is not going to pay $Xm for their bug bounty. That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain…

Yeah, I'd rather not make security research any more taboo and frowned upon than it already is. Regulation should be put towards forcing companies to put bug bounty programs into place and forcing companies to put the necessary money into it, not disincentivizing the absolutely crucial and important work that researchers do. Apple can easily afford it.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#110
post #77

Earlier quoted context omitted.

Weird, I've gotten "wasted" at tradeshows but never assaulted anyone :)

Angry drunk vs. happy drunk is a good zeroth-order personality test.

> Angry drunk vs. happy drunk is a good zeroth-order personality test.

And to be fair even "happy drunk" can be unprofessional in the wrong context.

But I think anyone who judges someone for how they act in a bar, after dark, and the concern is they were too jovial (absent some kind of sexual harassment or belting out racist jokes) is not someone I'd want to work with anyways.

Post reply on HN