Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

391–400 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#391
post #367

Earlier quoted context omitted.

The best approach is not to do it. Demanding money from someone that didn't hire you is never ethical - just childish. Would you like it if I showed up at your house, mowed your lawn, and then started banging on your door demanding $100 for mowing your lawn? Also, what marketing value - if you're just pwning random web sites rather than getting hired to test a site's security you aren't in any market.

The grass in the lawn may not be that dangerous to other people. However, if your house is emitting radiation, and a hero breaks in to clean it up for the sake of other people you service, (because the town does not need to wait for you to hire someone) the hero deserves a reward and the owner of the house deserves punishment.

Unless the "hero" is law enforcement or some other government agent with a warrant, he will likely have broken a bunch of laws by breaking into a person's house uninvited, and not very likely rewarded.

That's modern society for ya.

Re: I pwned half of America's fast food chains simultaneously

#392

Earlier quoted context omitted.

OK, make the comparison more direct, then. Say you have a filing cabinet with all of your important and \ or embarrassing documents in it. Are you OK with houseguests giving the handle a little wiggle when they come over to check if its locked? What about the neighborhood kids?

A closer analogy would be your friendly neighbour warning you that you left your garage door open. And yes I would appreciate him telling me.

The closer analogy would be your friendly neighbour warning you that he determined your garage door code was easily guessable after he spent 45 minutes entering different codes.

Re: I pwned half of America's fast food chains simultaneously

#393
post #58

Earlier quoted context omitted.

> It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan Pretty clear to me, "it was searching for exposed Firebase credentials on any of the hundreds of recent AI startups.", running a script to scan hundreds of startups > Sadly, many companies will freak out and get the law involved, even if you are a good samaritan. Yeah, but that also ends with that company being shamed a lot of…

[flagged]

> "remembered chattr.ai"

They didn't say that, you just made that up.

This is what they said:

"when we remembered the existence of a scanner we made for firebase and found https://chattr.ai"

And in MrBruh's post, the way they found it was scanning .ai domains, using the same scanner that Eva remembered they had made.

Re: I pwned half of America's fast food chains simultaneously

#394

Earlier quoted context omitted.

They reworded things since yesterday: Before, one collaborator had them in a chat sneering about chattr, checking their Javascript, then getting a GUI pwn tool for firebase. i.e targeted attack with malice, followed up a blog post wildly exaggerating what happened, with a disclosure policy of 'we emailed them once and they fixed and didn't email us back so we'll just publish' Only spelling this out because it's impor…

> Before, one collaborator had them in a chat sneering about chattr "Wow this thing looks crappy" > checking their Javascript "I wonder if it is crappy" > then getting a GUI pwn tool for firebase. "Huh, it seems crappy. Let's just check to be sure" > with a disclosure policy of 'we emailed them once and they fixed ...' "Well, this thing is really crappy. we don't want to harm people. Let's tell them about how crappy…

Note I'm not claiming disclosure is bad, but rather, this is a copy of a copy of a copy of a copy of a copy of a copy of how professionals handle these situations, to the point there's nothing left except the "1) pick a target 2) email them 3) write a blog post when fixed" parts.

Re: I pwned half of America's fast food chains simultaneously

#395
post #393

Earlier quoted context omitted.

[flagged]

> "remembered chattr.ai" They didn't say that, you just made that up. This is what they said: "when we remembered the existence of a scanner we made for firebase and found https://chattr.ai " And in MrBruh's post, the way they found it was scanning .ai domains, using the same scanner that Eva remembered they had made.

You're absolutely right: thing is, they rewrote it between the comment you're replying to and your comment. (overnight EST)

Re: I pwned half of America's fast food chains simultaneously

#396

Earlier quoted context omitted.

Nope, shame is ineffective as a tool for change. More often people shut down or ignore you if you attempt to shame them than actually make the change you want. Besides, it's frequently just about vengeance anyway. Shame is really hate of other, for the most part. As a tool for oppression however, yes it's quite effective.

Shame isn't always for oppression, although it certainly can be - it's also a pretty useful tool to impose reasonable rules that allow you to live peacefully among your neighbors.

That's not shame, that's guilt. Shame is existential, guilt is situational. The cost of shame is too high for whatever value it may bring.

Re: I pwned half of America's fast food chains simultaneously

#398
post #48

Earlier quoted context omitted.

Yea, and if they were actually breached and there were victims, the first thing they would do is issue a press release telling the world "We Take Security Very Seriously."

Is it legally differentiated if they respond to the reporter? Or is there some weird loophole of "We didn't take action because of your message. We just happened to patch the same vulnerability after you mentioned it. We are not aware of any penetrations, because we didn't notice your message"?

> Is it legally differentiated if they respond to the reporter?

Nobody knows.

But between taking an unknown legal risk, vs being seen as ungrateful, the choice for legal is quite clear.

Re: I pwned half of America's fast food chains simultaneously

#399
post #143

Earlier quoted context omitted.

No rules or laws that require it. Closest requirement would be PCI around credit cards but you need lots of volume to be required to do an audit. HIPPA just requires you to do risk analysis and implement risk management. SOX is up to the auditor, when I was CTO at a public company, they were fine with me signing at attestation of all things we had implemented. Same with banks, no explicit requirement in both glba and…

HIPAA requires that no entity involved leak any PHI or penalties will be applied, you absolutely have to do more than "do risk analysis/management".

https://www.hhs.gov/hipaa/for-professionals/security/laws-re...

Re: I pwned half of America's fast food chains simultaneously

#400

How much would this leak go for in the darknet?

Deciding to sell this on the darknet is a life changing decision, white to black overnight and imagine not really something most would contemplate. Payment in BTC probably from an already compromised address so loads of factors. Probably an easy + quick 2BTC though

Yeah it's like the difference between buying a handgun to go to the range and buying one to rob a liquor store
Post reply on HN