While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…
I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…
Security Researcher Assaulted Following Vulnerability Disclosure
111–118 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#112Earlier quoted context omitted.
No, thats not what he said.
> No, thats not what he said. No, that's the implication of what they said. If the police don't get involved in bloodless physical assaults then who is going to intervene? Does one have to call out "no slapbacks"? Or to put it another way, I'm very dubious that one could merrily slap their way down the Thames without the police showing up.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#113While the behavior of Atrient and specifically Jessie Gill is absurd in terms of working with the researchers to address the issues and pay the bounty, I am always skeptical of these captured videos. We don't have any context of what was said before and what the communication between the researchers and Atrient was like other than their accounts. Maybe I am just being cynical, but I've personally had interactions wit…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#114Earlier quoted context omitted.
I agree completely, but the issue is that the vulnerability value is asymmetric. It's about $1m to get an iPhone no-click RCE. Up to about $4m for one with a seemingly long shelf life. Apple is not going to pay $Xm for their bug bounty. That said, that there will be some that continue to engage in illegal activity doesn't mean we shouldn't make it illegal in the first place. I'd even be in favour of treating certain…
Yeah, I'd rather not make security research any more taboo and frowned upon than it already is. Regulation should be put towards forcing companies to put bug bounty programs into place and forcing companies to put the necessary money into it, not disincentivizing the absolutely crucial and important work that researchers do. Apple can easily afford it.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#115Earlier quoted context omitted.
In the off chance that you're serious, this sounds like a great way to land yourself in federal prison.
> a great way to land yourself in federal prison. For what? Checking shodan and seeing that people don't know how to write secure code.
But after you have this data, I jokingly suggested "welp may as well capitalize on it". But missing with somebody elses money, especially a large fin-tech company will get a lot of people upset, people with money to sue, not to mention it's the FBI's job to go after you, especially at this scale.
You could certainly try just be aware the reaction will not be favorable for you at all.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#116Earlier quoted context omitted.
I still don't understand it, TCP/IP doesn't transmit MAC addresses. Your knowledge of it ends at the next router... Therefore you definitely can't authenticate/authorize by MAC address.
> Therefore you definitely can't authenticate/authorize by MAC address. I would be entirely unsurprised to see that the device is calling out to the API with it's MAC address as some kind of authenticator. eg: http://foo.example.com/api/prizes?id=xx:xx:xx:xx:xx
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#117Earlier quoted context omitted.
I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…
hello! thanks for this comment would you be able to contact me on twitter @me9187 (this account is mentioned in the secjuice article for verification) and tell us a little bit more about your experiences?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#118Earlier quoted context omitted.
I personally (and unfortunately) know Jessie Gill of Atrient. I have to, for work purposes. The way his interactions and comments/quotes were described in that article were exactly things that he would say and do. He's a pretty violent guy actually. And the way he's acting in that video, only saying, "I don't know you" and sitting down, he knows he needs to watch what he says because there are a lot of things that th…
hello! thanks for this comment would you be able to contact me on twitter @me9187 (this account is mentioned in the secjuice article for verification) and tell us a little bit more about your experiences?