Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

51–60 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#51

Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.

This is a case where an email from mod zero to security@crowdstrike.com should have been enough to get the SOC to read and route the vuln to the product team and get a fix implemented.

NDA? HackerOne? Personal Information with Identity and Credit History Verification, Cookies and Disclosure Agreements, and 3rd party terms? Why is it at all "interesting" that a security researcher is not interested in giving all of up in order to tell CrowdStrike that their core product is broken in a way that is completely inimical to its mission purpose?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#52
post #38

Earlier quoted context omitted.

I guess the specifics are the letters N, D and A and what they stand for. And the fact that there's absolutely nothing in it for them. Would you even consider signing an NDA if I sent you one? I surely hope not.

That’s not an answer to the parent’s question. HackerOne has a disclosure process despite the NDA, so what part of the process is the issue? Or is it simply “hackerone bad”?

They have no interest in signing away their right to disclose the vulnerability at the behest of a private, for-profit entity, because they believe public disclosure of security vulnerabilities is crucial to improving security.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#53
post #32

Refusing to interact with an existing security process (HackerOne) and demanding a personal contact instead for a minor issue is certainly an interesting take.

You find "interesting" that someone just wants to report a security vulnerability without having to accept any conditions first? Funny, I find it interesting that they want to pay a bugbounty even though nobody asked for it. But I guess paying hush money is just cheaper than having to seriously fix the issue.

>But I guess paying hush money is just cheaper than having to seriously fix the issue.

They did fix the issue, though.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#54

Earlier quoted context omitted.

Your sources are from thegrayzone? You should learn to consider your sources...

The GrayZone has been impeccable in their reporting, with any errors quickly being admitted and disclosed. Of course many people disagree with them, and love to try character assassination and other ad hominems, but I've found them informative and having integrity. Maybe you should elaborate your reasoning. To elaborate further: "Leaked emails reveal British journalist Paul Mason plotting with an intel contractor to…

Paul Mason isn't a journalist. He was a journalist, then he left and swerved hard left into Momentum. He's previously been members of groups best described as Marxist or at least radical left.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#55
post #32

Earlier quoted context omitted.

You find "interesting" that someone just wants to report a security vulnerability without having to accept any conditions first? Funny, I find it interesting that they want to pay a bugbounty even though nobody asked for it. But I guess paying hush money is just cheaper than having to seriously fix the issue.

>But I guess paying hush money is just cheaper than having to seriously fix the issue. They did fix the issue, though.

They just marked something the way exploit was done as "malacious", without fixing the root problem, or informing the the reporter that they "fixed" it. Instead claiming it was never there. That is very unprofessional!

And if these guys were to go though the NDA route, The company may choose just not to fix it at all, and tell these researchers to be quiet about it. And you'd never know there was such a exploit ever.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#56

Working as a developer inside large enterprise is increasingly intolerable by the day, made possible by tools such as crowdstrike falcon. By the time your workstation is saddled with endpoint security, DLP, zero trust networking, antivirus, etc. it barely functions. And you can get in trouble for doing anything. Installing tree from homebrew can get you flagged on some naughty list where you have to justify why you n…

I recently finished an internship in a large company. I wanted to install netcat to troubleshoot networking issues between windows and docker containers I was running. Right when it was downloaded from scoop, it got deleted and I got a scary automated email. My manager called me immediately, in the end it was cleared quickly but I did learn to be very carefull about what I try to download. At first I didn't understan…

Gosh netcat binaries on Windows get picked up by Windows Defender as malacious, it's so infuriating.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#57
post #18

Earlier quoted context omitted.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

They fixed it with an update this month, but CrowdStrike was hooking /every/ single call to NtCreateUserProcess on my work machine last month, and you /know/ how electron-based apps work. VSCode took so long to launch its sub processes it would pop up a crash reporter. "Hello World" compiled from C++ would take a minute to launch sometimes. WSL straight up could not be started because the TTY timed out waiting for it…

Your organization and your IT department expect you to work around these issues by doing development on your personal machine, and then copying it to your work machine while pretending like you never tunneled to your personal machine from the office.

That's what it feels like with some of these policies.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#58

Earlier quoted context omitted.

A bit speculative, but the word "NDA" appears four times in their post.

Yea I noticed that, but what do they specifically not like about the NDA? afaik, HackerOne still makes vulnerability disclosure possible (and automatic if taking too long?)

NDAs are expensive to review, usually over broad and always badly written.

Just say no to NDAs.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#59
post #18

Earlier quoted context omitted.

10% of Falcon is blocking dumb shit people do. 90% is blocking things people are supposed to be doing, and have been doing successfully so far. Nothing starts your week better than "After the latest definitions update, Falcon heuristic started quarantining your core business tools as suspicious".

I feel your pain at a deep and spiritual level. I have been in charge of at least half a dozen endpoint protection products over the years (deployment, configuration, management, etc.). Once a user experiences what you just described they are (rightfully) suspicious and sour towards endpoint protection. Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection mo…

Can I ask, since you're as a person who has administered endpoint protection products: how much legitimate stuff do they actually catch?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#60

Earlier quoted context omitted.

Your sources are from thegrayzone? You should learn to consider your sources...

The GrayZone has been impeccable in their reporting, with any errors quickly being admitted and disclosed. Of course many people disagree with them, and love to try character assassination and other ad hominems, but I've found them informative and having integrity. Maybe you should elaborate your reasoning. To elaborate further: "Leaked emails reveal British journalist Paul Mason plotting with an intel contractor to…

The Grayzone, home to impeccable reporting like https://thegrayzone.com/2022/03/18/bombing-mariupol-theater-...
Post reply on HN