Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

461–470 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#461

Earlier quoted context omitted.

The issue is it is often impossible to distinguish from a white hat or a black hat hacking your live systems. It can trigger expensive incident response and be disruptive to the business. Ethically, I think it crosses a line when you are wasting resources like this, live hacking systems. There is usually a pretty clear and obvious point where you can stop, not trigger IR, and notify the companies. Not saying that was…

> The issue is it is often impossible to distinguish from a white hat or a black hat hacking your live systems. It can trigger expensive incident response and be disruptive to the business. If your servers are connected to the internet, you can expect that people from countries that won't prosecute them will try to break in. This will happen, almost immediately, as soon as they're connected to the internet. If your s…

> This is obviously not the case.

It really is though. People just don't understand the ethics of white hat hacking.

> Suppose you suspect the company could be using a default admin password

Putting in that password on a system you don't own without any sort of permission to do so is very clearly against the law. You are accessing the system without permission. You just walk away if you want to be ethical about it.

The only ethical path is to let them know you have some reason to believe they are not using secure passwords or whatever. Accessing their system illegally is not the move. It just isn't the white hats problem.

Re: I pwned half of America's fast food chains simultaneously

#462

Earlier quoted context omitted.

It ends up leading to "word-inflation" where you have to keep shouting louder, stretching the truth to be acknowledged. The word "racist" changing meaning over the last 30-40 years is a great example.

Please elaborate on the change in meaning?

why isn't the word "prejudice" used anymore?

Re: I pwned half of America's fast food chains simultaneously

#463

Earlier quoted context omitted.

It ends up leading to "word-inflation" where you have to keep shouting louder, stretching the truth to be acknowledged. The word "racist" changing meaning over the last 30-40 years is a great example.

Please elaborate on the change in meaning?

https://www.pbs.org/race/000_About/002_04-experts-02-02.htm

Re: I pwned half of America's fast food chains simultaneously

#465

Earlier quoted context omitted.

Regarding your sources: One has to do with self-esteem, which has nothing to do with whether it is pro-social or beneficial, just that some types of shame harm self-esteem, which was never contested. The second study is about criminal populations, and I specifically mentioned that shame is about self-policing, and that obviously didn't work if someone is incarcerated for a crime.

Did you read them? If your goal is to effect change, hurting people's self esteem is a negative effect that is entirely unnecessary to change. And criminals aren't some ungovernable animals...

> If your goal is to effect change, hurting people's self esteem is a negative effect that is entirely unnecessary to change.

Yes, your self esteem will likely be harmed if you do something bad and it gets found out.

> And criminals aren't some ungovernable animals...

?

Re: I pwned half of America's fast food chains simultaneously

#466

Earlier quoted context omitted.

why isn't the word "prejudice" used anymore?

https://www.pbs.org/race/000_About/002_04-experts-02-02.htm

I didn't ask what GPT or 3 random people said. why can't you articulate your own position?

Re: I pwned half of America's fast food chains simultaneously

#467
post #131

Earlier quoted context omitted.

It is using the Avif format (for images) for a 2x compression bonus over PNG while still maintaining a higher quality over JPG. If you can't view the images then it means you are likely using an outdated browser, all current versions of browsers support it (afaik) except Internet Explorer.[0] ...And if you are using Internet Explorer, then god help you. [0] https://caniuse.com/avif

I'm on Edge 120 (released a month ago) and can't see it

I don't usually use edge 120 but have installed on my mac. the images are indeed broken.

Re: I pwned half of America's fast food chains simultaneously

#468
post #277

Earlier quoted context omitted.

> absolutely necessary to gauge the severity of this misconfiguration Possibly. But what's the legal basis that allows random external parties to make that determination? Report the leaked credential, and let the company assess impact. The problem is that pivoting to accessing user passwords may cause the companies to spend money notifying customers and harm their reputation. If they want to pursue legal action, thos…

> [...] may cause the companies to spend money notifying customers and harm their reputation. I'm sorry, but I don't quite understand. Are you saying that you feel a company should not notify customers when exposing passwords in plaintext and furthermore, that this fact alone isn't harmful to their reputation? Not notifying customers, in my eyes, would destroy any semblance of reputation further. > Typically the comp…

I'm not really commenting on the company side, but yes: plaintext passwords are bad, companies should notify customers when legally required, and I'd like companies to go further.

Legally, bypassing security controls, using credentials that are not yours, and accessing data without authorization is a crime[1]. I see no indication that this blog post was authorized. Others should not consider this blog post as a good approach.

Look instead to bug bounty programs and stay in-scope. Often that means creating your own account and avoiding other customer's data.

While it doesn't make a good blog post, I still emphasize that the author should have reported the leaked credentials and stopped.

[1] varies by jurisdiction, I'm not a lawyer, etc.

Re: I pwned half of America's fast food chains simultaneously

#469
post #286

Earlier quoted context omitted.

Every company I've worked for, and every pentest contract I've done has found plaintext passwords or credentials stored somewhere they shouldn't. It's unfortunately very common.

Customer credentials as in this example? I'll be totally frank, I'm having some trouble reconciling that with Article 34 of the GDPR and 1798.150 of the CCPA. Do none of these organizations have EU/CA customers or is the approach they take to laws the same as the one they employ for database security?

Less common with things that are directly "customer passwords", but common with other credentials and customer data. Those laws require reporting about breaches and I know I get notifications about breached data somewhat often.

Keep in mind, a good first step to improving security is to hire a pentester. So pentesters have a unique view into companies that are trying to improve. Often the starting place is quite poor. When I leave those contracts, to my knowledge, they are all on track to fix these sorts of defects.

Re: I pwned half of America's fast food chains simultaneously

#470

I would have stopped once I confirmed the leaked keys were valid. Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that. If there was a pentester agreement, safe harbor, or other protection that's different. Be careful out…

I would argue that looking at the type of data you're dealing with is actually a very important part to assess the impact, but looking at the data itself is beyond this part. Knowing that they store passwords in plaintext is a security issue on top of the R/W credential

Type of data is very important to assessing impact. But that doesn't grant anyone authority to breach customer data. The company can assess impact.
Post reply on HN