Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

301–310 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#301
post #83

Earlier quoted context omitted.

What is wrong with shaming when it's warranted?

It’s an ineffective tool if your goal is change.

Like how Apple says about the App Store rejections:

> Running to the press never helps.

Except of course, in reality we know that it ABSOLUTELY DOES. In fact, it has been often times the ONLY thing that has helped.

Re: I pwned half of America's fast food chains simultaneously

#302
post #138

Earlier quoted context omitted.

Unfortunately, door 1 is maybe $200 bounty and weeks or months of back and forth (if the corp doesn't have a clear bounty program) whereas door 2 has infinite upside. Honestly, it might make sense for a gov group to run a standardized bounty program for exploits with notable financial / privacy impact.

Giving corps even more excuse not to run proper bug bounties, or care even less about shipping secure code? Pass.

I don't know. I think you could perhaps align incentives such that any bounty claimed via the government program is competitive, public, and companies are ranked by the number and severity of bounties. Then the company would have an incentive to run a bounty program where they had a chance of controlling the narrative a bit.

Re: I pwned half of America's fast food chains simultaneously

#303

Earlier quoted context omitted.

Yeah, what happened to the "Hacker" in Hacker News. (responding to people blaming the 'hacker', not the sites). This guy just grabbed publicly available information, and by 'public' I mean put out onto the web un-protected, just put out there. If you can just basically browse to something, is it really his fault for finding it. It's like if I have a front door on my house, and just in the front hallway I have a huge…

I think according to the law and related suits based on accessing publically available URLs without authorization is still technically prosecutable - I’m not a CFAA expert but I’d double check there

I think you are correct, that the law says that.

I think the law is pretty wrong.

It means I can break law by just accidentally browsing to something. Can be breaking the law just by seeing it, before knowing I'm doing something wrong.

Basically, just see something and be guilty before being able to look away.

Re: I pwned half of America's fast food chains simultaneously

#304
post #93

I was looking at jobs for my son at Safeway supermarkets and lazily put https://www.safeway.com/jobs in the browser. That redirects to https://www.careersatsafeway.com/desktop/home -- which is very much not about jobs at safeway -- appears to be an Indonesian gambling/gaming site. Safeway.com has zero email contacts published and expects communication to be via phone call or chatbot. I found their domain admin email…

Seems to be fixed: This request was blocked by our security service

Not fixed where I am.

Re: I pwned half of America's fast food chains simultaneously

#306

Earlier quoted context omitted.

It's not about companies. It's about their customers. Do you even know what Full Disclosure is?

Why should the researchers or other vulnerability spotters care about the company's customers? The companies don't care further than what they can profit from the customers. Yes, I know what full disclosure is. Companies don't do full disclosure about anything. Full disclosure is better than not disclosing publicly. But monetizing the vulnerability is akin to what companies do. I find it utterly bizarre that it's tot…

Full disclosure isn't something for _companies_ to do. It's what _researchers_ do. Full disclosure isn't compatible with the monetization incentives offered by companies. You're publishing in public and immediately.

I think you clearly do not understand what full disclosure is.

Re: I pwned half of America's fast food chains simultaneously

#308

You are a good human. Seems they had not tweaked the database rules correctly, maybe even left the default setup! That means you could have executed this: Firebase.database().ref('/').set('All your data is gone'). Better yet, download the whole DB and then: Firebase.database().ref('/').set('I have all your data, pay me to get it back').

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#310
post #143

Earlier quoted context omitted.

No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…

> No rules or laws that require it It will just be FTC knocking on your door…

Or the SEC, because one the breach/incident is public, the share price drops and failure to have disclosed those factors prior constitutes "securities fraud." Increasingly this it the default method of corporate regulation.
Post reply on HN