It seems crazy that no thanks or recognition has been given. Is this because doing so might be seen as an admission of liability, and could be used in any legal cases that are brought?
I pwned half of America's fast food chains simultaneously
261–270 of 513 posts
Re: I pwned half of America's fast food chains simultaneously
#262If you view this page in Safari, it’s just a text document
Re: I pwned half of America's fast food chains simultaneously
#263>With an upbeat pling my console alerted me that my script had finished running Forget the pwn how do I do this Also, HN used to think this was cool now there are 20 posts blaming the hacker…
on macos I just add `; say done` to my command. If I didn't think of doing it before starting the command (which is most of the time), I just type it and press enter while the command is runnign, it gets buffered and executed right after the command finishes (be careful that it's not an interactive program that you're executing though, or it might take your "say done" as an interactive entry)
Re: I pwned half of America's fast food chains simultaneously
#264>With an upbeat pling my console alerted me that my script had finished running Forget the pwn how do I do this Also, HN used to think this was cool now there are 20 posts blaming the hacker…
I'm not sure whether it's HN thinking this is uncool (it is cool!) or it's HN taking the unfortunate realistic position that this type of stuff only gets the reporters into trouble, after seeing it happening time and time ago. People doing cool stuff get in trouble, and it's sad to watch.
Re: I pwned half of America's fast food chains simultaneously
#265I would have stopped once I confirmed the leaked keys were valid. Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that. If there was a pentester agreement, safe harbor, or other protection that's different. Be careful out…
> Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that. I'd argue that it was absolutely necessary to gauge the severity of this misconfiguration and furthermore, that Chattr.ai must contact every affected user, not MrBruh…
Possibly. But what's the legal basis that allows random external parties to make that determination? Report the leaked credential, and let the company assess impact.
The problem is that pivoting to accessing user passwords may cause the companies to spend money notifying customers and harm their reputation. If they want to pursue legal action, those are clear damages.
> Chattr.ai must contact every affected user, not MrBruh.
Agreed, a pentester directly contacting impacted users would increase the risk legal gets involved.
> There is no telling whether and how many outside of this disclosure have previously accessed this information
Typically the company would review logs to determine that.
Re: I pwned half of America's fast food chains simultaneously
#266Earlier quoted context omitted.
For more crucial PII (such as SSN, health data, payment info, etc), vendors are generally required to have certifications from a third-party auditor (such as SOC2). If the big companies fail to check that, then yes, they can be made liable.
No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…
It will just be FTC knocking on your door…
Re: I pwned half of America's fast food chains simultaneously
#267Earlier quoted context omitted.
> Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that. I'd argue that it was absolutely necessary to gauge the severity of this misconfiguration and furthermore, that Chattr.ai must contact every affected user, not MrBruh…
That is not just negligence, that is stupidity on an order of magnitude that the responsible people should never again be allowed to work on a software project.
Re: I pwned half of America's fast food chains simultaneously
#268How much would this leak go for in the darknet?
Re: I pwned half of America's fast food chains simultaneously
#269It seems crazy that no thanks or recognition has been given. Is this because doing so might be seen as an admission of liability, and could be used in any legal cases that are brought?
To give the benefit of the doubt, it appears he only contacted them less than 48 hours ago. Their first priority should correctly be to fix the problem. They could be discussing a bug bounty right now and just haven't finalized the email yet
Re: I pwned half of America's fast food chains simultaneously
#270Who's to say they're the first to discover this? They're the first to discover it and do something to fix it. I thought there was a US law now where breaches like this have to be reported?
In the EU this would hurt so bad they probably would've needed to close shop.