Live data from Hacker News

Security Researcher Assaulted Following Vulnerability Disclosure

secjuice.com

111–118 of 118 posts

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#111

While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…

I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…

hello! thanks for this comment would you be able to contact me on twitter @me9187 (this account is mentioned in the secjuice article for verification) and tell us a little bit more about your experiences?

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#112
post #105
post #87

Earlier quoted context omitted.

No, thats not what he said.

> No, thats not what he said. No, that's the implication of what they said. If the police don't get involved in bloodless physical assaults then who is going to intervene? Does one have to call out "no slapbacks"? Or to put it another way, I'm very dubious that one could merrily slap their way down the Thames without the police showing up.

Actually I was assaulted and the police did nothing because no blood I was quite good as when some of my coworkers suggested that they put some people on "that system" we developed in our office I said no.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#113

While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…

I also know jessie gill personally and he don't deserve to be COO of the copy. I don't have any clue why Atrient CEO Sam don't take of this things well. Moreover he knows what jessie behavior is but he still won't bother to take action against him. And just to add it Jessie is pervert he has sexual harassment case going in case.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#114

Earlier quoted context omitted.

I agree completely, but the issue is that the vulnerability value is asymmetric. It's about $1m to get an iPhone no-click RCE. Up to about $4m for one with a seemingly long shelf life. Apple is not going to pay $Xm for their bug bounty. That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain…

Yeah, I'd rather not make security research any more taboo and frowned upon than it already is. Regulation should be put towards forcing companies to put bug bounty programs into place and forcing companies to put the necessary money into it, not disincentivizing the absolutely crucial and important work that researchers do. Apple can easily afford it.

I agree that regulation should be put into place, I've blogged about it in the past and I've argued that it should scale with number of affected users, but that doesn't mean we shouldn't make certain acts illegal. Selling a iOS 0day to the Saudis should be illegal.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#115

Earlier quoted context omitted.

In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.

> a great way to land yourself in federal prison. For what? Checking shodan and seeing that people don't know how to write secure code.

Checking for vulnerabilities IMO shouldn't be considered a crime - it's not a clear malicious intent. Sure if somebody is trying to open car doors in the parking lot that may warrant investigation - but for all we know they were just trying to warn drivers they left it unlocked, no actual crime has yet been committed.

But after you have this data, I jokingly suggested "welp may as well capitalize on it". But missing with somebody elses money, especially a large fin-tech company will get a lot of people upset, people with money to sue, not to mention it's the FBI's job to go after you, especially at this scale.

You could certainly try just be aware the reaction will not be favorable for you at all.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#116
post #88

Earlier quoted context omitted.

I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.

> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx

Exactly, and then the stored MAC is exposed in its un/or-poorly-authenticated API

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#117
post #111

Earlier quoted context omitted.

I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…

hello! thanks for this comment would you be able to contact me on twitter @me9187 (this account is mentioned in the secjuice article for verification) and tell us a little bit more about your experiences?

Unfortunately I can't risk being caught in Jessie's sights right now. He has a way of twisting things into his favor and always seems to get himself out of trouble by turning it on someone else. I have been following this story though and I may contact you in the future. Thanks, and sorry.

Re: Security Researcher Assaulted Following Vulnerability Disclosure

#118
post #111

Earlier quoted context omitted.

I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…

hello! thanks for this comment would you be able to contact me on twitter @me9187 (this account is mentioned in the secjuice article for verification) and tell us a little bit more about your experiences?

Seems like this guy has serious issues after reading this: https://www.leagle.com/decision/infdco20180828d81
Post reply on HN