Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

101–110 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#101
post #87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

Releasing information increases the transparency of the market, allowing customers to make informed decisions. To hide things is not beneficial to the customers.

Always assume a bad guy has the 0-day before a security researcher.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#102
post #44

This seems extremely tame by vulnerability disclosure fuckup standards.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid. Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

If H1 was willing to take and triage reports without requiring acceptance of their terms and NDA, that would be fine.

We also need to be very clear that the moment a company, or it's authorized representative, flags something as a wontfix or "not a security issue", full and immediate disclosure is fair game.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#103
post #44

This seems extremely tame by vulnerability disclosure fuckup standards.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid. Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

Then they should provide a path that doesn't involve arbitrary NDAs if you're willing to forego the reward.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#104
post #88

Earlier quoted context omitted.

if they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything

They pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.

The only reason it's a "thing" is that the reporters in this case were attempting to do a responsible, coordinated disclosure. That's important for their own brand - many clients would be reluctant to hire a security consultant who just dropped 0days without a damn good reason. So this is documentation and justification for why they did a unilateral disclosure - the expectation is that you "show your work" and be clear that you tried to work with the vendor and they wouldn't work with you in good faith so you had no choice but to unilaterally disclose.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#105
post #90
post #71

Earlier quoted context omitted.

Well in this case the vulnerability is the ability to uninstall the program when you're not supposed to be able to uninstall it. So yes, if the program didn't exist at all, there would be no way to uninstall it in an unauthorized manor. So the vulnerability wouldn't exist. You wouldn't necessarily be any more secure though. If you have 10 layers of security and 5 have holes in them, you have 5 vulnerabilities, but yo…

What is the vulnerability here? An admin user can do admin stuff. Shocking.

if you believe you know the answer to the question, why ask it?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#106

Remove lawyers from the composite picture. Is there any rational reason for a NDA in that case? If the answer is no, then in one way or another they are trying to limit liability by limiting the researcher's ability to be paid for their discovery and then communicating that to the wider world.

This isn't about liability. It's about shifting the decision of whether to disclose, and on what timetable, entirely back on the vendor.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#107

Earlier quoted context omitted.

I think there is a lot of value in these tools for the enterprise. Even if it is just CYA insurance. If somebody steals data but you have a DLP tool you can just blame the vendor. My biggest issue with the tools is they have an insanely deleterious impact on performance and the harsh scrutiny applied has a chilling effect on employees. It turns people into drones that do not dare step outside the norm.

This is hands down one of the scariest and depressing comments I've ever read on HN.

Sadly it is becoming the norm. Even at small and medium sized companies.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#108
post #73

Earlier quoted context omitted.

This doesn't really address the part where they then said the issue doesn't exist.

I am not defending CrowdStrike here (my work laptop, that I am typing this on, is molasse-like thanks to them), but their PSIRT team (they have one right?) is just another team in the corp machinery. What PSIRT team and the engine team decide to respond have no effect on what the analyst team decides to do. Do no harm and cover your ass. No one is going to complain a false positive on a custom PoC binary....right? Ev…

Seriously, what does CrowdStrike Falcon do to slow down work computers so much? I recently switched gigs and no longer use Crowdstrike, and I didn't realize just how bad it was until I no longer had to deal with it.

I've heard there are workarounds to disable or remove CrowdStrike, but I was too concerned that the IT overlords would come after me at my previous employer.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#109
post #106

Remove lawyers from the composite picture. Is there any rational reason for a NDA in that case? If the answer is no, then in one way or another they are trying to limit liability by limiting the researcher's ability to be paid for their discovery and then communicating that to the wider world.

This isn't about liability. It's about shifting the decision of whether to disclose, and on what timetable, entirely back on the vendor.

Great. Imagine I sell a security product and I make a tidy sum telling you how secure that product is. Turns out, there's a security hole in my product that costs your company 100 million in lawsuits as customer data gets stolen via this hole. Now, you'd like to sue me on my claim on the basis that my security product was in fact, flawed.

How's that not about liability?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#110

Earlier quoted context omitted.

Your sources are from thegrayzone? You should learn to consider your sources...

Do you know who thegrayzone founders and editors are? Hint: they're not crazies, they're pro journos with classy reputations.

Telling the wrong truth is considered "crazy" these days.
Post reply on HN