Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

181–190 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#181

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

When you turn actual, creative and exhausting work (vulnerability research) into some kind of high stakes gig job you deserve this problem. I am not against bug hunting by any means, but if you want to me act like I care about your product and not about my money, pay me monthly.

Most vulnerability reports I see at work come from security researchers in Pakistan and India.

I have never found out if this is a side gig, a full-time job, or a hobby for people.

Re: I pwned half of America's fast food chains simultaneously

#182

> Timeline (DD/MM) > 06/01 - Vulnerability Discovered > 09/01 - Write-up completed & Emailed to them > 10/01 - Vulnerability patched Note those dates are DAY-MONTH. At least they patched it within a single day. I find it funny that the author found a massive vulnerability but chose to wait a couple days to report it so they could finish a nice write-up. Reminds me of my experience with HackerOne: We had some particip…

Yeah... Is it ok to do a public writeup on the same date the vuln was patched without an acknowledgement from the client? I would have scheduled this blog post at least a week later.

Once they changed the credentials and no longer share them, this particular issue should be gone, no?

Re: I pwned half of America's fast food chains simultaneously

#183
post #10

If this had been exploited and the job applicants to Target, Subway, Dunkin et al, had bank/credit fraud committed in their name's, would the big companies be liable for not performing due dilligence on chatter.ai? To be clear, I'm asking from a legal standpoint not a practical one.

Someone applying to work at Taco Bell or Subway couldn’t afford a lawyer even if they worked for a full year and saved every penny.

Re: I pwned half of America's fast food chains simultaneously

#184

Earlier quoted context omitted.

Yes, but that might also be caught by infosec users of said tool who have things similar to “littlesnitch” alerting them to the outbound API call attempt.

there used to be windows GUIs for forcing new connections to ask, but i haven't seen anything like it. I can't recall the name of the one i used to use, but it scored perfectly on shieldsUp - oh, Zone Alarm. Littlesnitch iirc is macos only, but it sounds lovely for this sort of thing.

The generic term is “outbound firewall”.

Re: I pwned half of America's fast food chains simultaneously

#185
post #143
post #44

Earlier quoted context omitted.

For more crucial PII (such as SSN, health data, payment info, etc), vendors are generally required to have certifications from a third-party auditor (such as SOC2). If the big companies fail to check that, then yes, they can be made liable.

No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#186

Earlier quoted context omitted.

When you turn actual, creative and exhausting work (vulnerability research) into some kind of high stakes gig job you deserve this problem. I am not against bug hunting by any means, but if you want to me act like I care about your product and not about my money, pay me monthly.

How do you measure productivity? How do you budget for a bug hunting department?

Measuring productivity in a useful way is pretty close to impossible in a vast swath of jobs, though people make a killing (and make everyone involved considerably more miserable) pretending otherwise

The reason most people have converged on a preference for salaried work is that most jobs don't actually need consistency to be useful, but most people do need consistent pay to focus on a job

Re: I pwned half of America's fast food chains simultaneously

#187
post #83

Earlier quoted context omitted.

What is wrong with shaming when it's warranted?

It’s an ineffective tool if your goal is change.

Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.

Re: I pwned half of America's fast food chains simultaneously

#188
post #138
post #84

Earlier quoted context omitted.

There is a big difference between discovering a vulnerability that allows you to forge tokens and immediately reporting it versus dumping terabytes of data on the darknet for sale.

Unfortunately, door 1 is maybe $200 bounty and weeks or months of back and forth (if the corp doesn't have a clear bounty program) whereas door 2 has infinite upside. Honestly, it might make sense for a gov group to run a standardized bounty program for exploits with notable financial / privacy impact.

The solution is to have fines in place for insecurities and award them to discoverers.

Re: I pwned half of America's fast food chains simultaneously

#189
> If you grab the list of admin users from /orgs/0/users, you can splice a new entry into it giving you full access to their Administrator dashboard.

I'm not clear on this. Splice a new entry into what? The list of admin users? And then do what with it?

Re: I pwned half of America's fast food chains simultaneously

#190

Earlier quoted context omitted.

It’s an ineffective tool if your goal is change.

Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.

Nope, shame is ineffective as a tool for change. More often people shut down or ignore you if you attempt to shame them than actually make the change you want. Besides, it's frequently just about vengeance anyway. Shame is really hate of other, for the most part.

As a tool for oppression however, yes it's quite effective.

Post reply on HN