Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

161–170 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#163
post #61

Earlier quoted context omitted.

> Good Samaritan The web is insecure enough as it is, I just want to do my part to make it that little bit safer :)

From one Paul to another, best of luck! For the goal of improving overall web security, widespread shame doesn't work. My hunch is that we need to be more prideful about having verifiably robust security practices. Kind of like getting corporations to realize that the data is more valuable if you can prove that nobody can breach it.

Thank you, the kindness goes a long way!

Re: I pwned half of America's fast food chains simultaneously

#164

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

Companies can always better align incentives by paying more and not try to downplay vulnerabilities.

Re: I pwned half of America's fast food chains simultaneously

#165
post #162

Earlier quoted context omitted.

It’s an ineffective tool if your goal is change.

How so?

Because everyone makes mistakes, if you antagonize someone they are less likely to care about you and feel more obligation to protect their own.

Re: I pwned half of America's fast food chains simultaneously

#166
post #138
post #84

Earlier quoted context omitted.

There is a big difference between discovering a vulnerability that allows you to forge tokens and immediately reporting it versus dumping terabytes of data on the darknet for sale.

Unfortunately, door 1 is maybe $200 bounty and weeks or months of back and forth (if the corp doesn't have a clear bounty program) whereas door 2 has infinite upside. Honestly, it might make sense for a gov group to run a standardized bounty program for exploits with notable financial / privacy impact.

Giving corps even more excuse not to run proper bug bounties,

or care even less about shipping secure code?

Pass.

Re: I pwned half of America's fast food chains simultaneously

#169

From Eva’s post: > we didnt know much about firebase at the time so we simply tried to find a tool to see if it was vulnerable to something obvious and we found firepwn, which seemed nice for a GUI tool, so we simply entered the details of chattr's firebase Genuinely curious (I’ve no infosec experience), wouldn’t there be a risk that a tool like this could phone home and log everything you find while doing research?

Yes, but that might also be caught by infosec users of said tool who have things similar to “littlesnitch” alerting them to the outbound API call attempt.

Re: I pwned half of America's fast food chains simultaneously

#170
post #58
post #56

It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan. If it is indeed the latter, I wonder how they are so brazen about it. Does chattr.ai have a responsible disclosure policy? In my eyes people should be free to pentest whatever as long as there is no intent to cause harm and any findings are reported. Sadly, many companies will freak out and get the law involved, even if you are…

> It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan Pretty clear to me, "it was searching for exposed Firebase credentials on any of the hundreds of recent AI startups.", running a script to scan hundreds of startups > Sadly, many companies will freak out and get the law involved, even if you are a good samaritan. Yeah, but that also ends with that company being shamed a lot of…

Plain text passwords, seriously. At that point, I'm not sure what would be a similarity with any other engineering profession. The plain text passwords are beyond any rhyme or reason... and then returned to the end user client. If anything, I'd consider it malicious negligence - in the EU the leak would be a GDPR issue as well.
Post reply on HN