This is not the first time Atrient has been sloppy with the details of their NDAs, nor the first time Jessie Gill has gotten in trouble for being a touch too eager to get physical. https://www.leagle.com/decision/infdco20180828d81
Security Researcher Assaulted Following Vulnerability Disclosure
101–110 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#102Re: Security Researcher Assaulted Following Vulnerability Disclosure
#103If you (like me) didn't know what a Shodan safari is, you're in for a fun ride: https://techcrunch.com/2019/01/21/shodan-safari/
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#104Earlier quoted context omitted.
If only he were brutally beaten to provide you a more stimulating story.
If only they hadn't put it on so thick, we wouldn't have had our time wasted with something that it turns out, after reading nearly to the end, we didn't want to read.
Seems like a lot of other people in this thread found it interesting and enjoyed the read. Who's the "we" that you're speaking for here?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#105Earlier quoted context omitted.
So you're saying that in the UK I can legally walk around shoving and slapping people at random?
No, thats not what he said.
No, that's the implication of what they said. If the police don't get involved in bloodless physical assaults then who is going to intervene? Does one have to call out "no slapbacks"?
Or to put it another way, I'm very dubious that one could merrily slap their way down the Thames without the police showing up.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#106While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#107People are complaining a lot about GDPR here but such a case would definitely lead to a fine of 4% or 8% of atrients revenue.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#108Earlier quoted context omitted.
I agree with you, but it isn't a clear cut issue. Attacking a server right now comes with some legal risk, which is a deterrent to some. It's impossible to tell white hats from black. If it were paired with a law that made it a felony to resell vulns to third parties then it would be much more robust.
The only way you're going to reduce the amount of vulnerabilities being sold on black markets is to provide sufficient financial and social incentive. There are enough people with dubious morals who don't care how illegal it is to find and exploit them, who will eagerly take the biggest payday. Combine no guarantee you'll get paid, poor treatment by authorities and employers and the (albeit low) risk of getting your…
That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain classes of vulnerability sale as an act of terrorism or treason or arms export violation.
I know it is hard, but we have to try to solve this.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#109Earlier quoted context omitted.
The only way you're going to reduce the amount of vulnerabilities being sold on black markets is to provide sufficient financial and social incentive. There are enough people with dubious morals who don't care how illegal it is to find and exploit them, who will eagerly take the biggest payday. Combine no guarantee you'll get paid, poor treatment by authorities and employers and the (albeit low) risk of getting your…
I agree completely, but the issue is that the vulnerability value is asymmetric. It's about $1m to get an iPhone no-click RCE. Up to about $4m for one with a seemingly long shelf life. Apple is not going to pay $Xm for their bug bounty. That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#110Earlier quoted context omitted.
Weird, I've gotten "wasted" at tradeshows but never assaulted anyone :)
Angry drunk vs. happy drunk is a good zeroth-order personality test.
And to be fair even "happy drunk" can be unprofessional in the wrong context.
But I think anyone who judges someone for how they act in a bar, after dark, and the concern is they were too jovial (absent some kind of sexual harassment or belting out racist jokes) is not someone I'd want to work with anyways.