Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

21–30 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#21
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

All sorts of cleverness going on there. I'll bet they saved a ton of money on development by lowballing people on fiverr or whatever they did, and indirectly they'll also save a ton on bookkeeping when a russian ransomware group effortlessly takes them for everything they have.

Re: Researcher finds flaw in a16z website that exposed some company data

#22
When I create a new service and add LetsEncrypt cert to server via ACME. I immediately see logs filled with junk, obviously bots searching for shitty defaults that devs might leave open. I have even seen requests for the process env file lol.

How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker mindset is the first to reach out.

a16z should be fined heavily unfortunately there is no legal framework for this type of negligence

Re: Researcher finds flaw in a16z website that exposed some company data

#23
post #9

Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.

Ever had a bug in code you wrote?

Re: Researcher finds flaw in a16z website that exposed some company data

#24
post #10

they are busy writing a giant "architecture of generative AI" whitepaper. give them a pause, they are dreaming a future agentic world of half-assed chatbots. while the world burns with botched software updates.

world is already burning with effects of climate change.

botched software updates on a Friday is just the chef’s kiss

Re: Researcher finds flaw in a16z website that exposed some company data

#25
If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

Re: Researcher finds flaw in a16z website that exposed some company data

#26
post #7

when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

[deleted]

Re: Researcher finds flaw in a16z website that exposed some company data

#28
post #7

when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

More like complaining when your teenager takes a break from mowing on trash day and leaves the mower next to the trash and someone takes it.

Re: Researcher finds flaw in a16z website that exposed some company data

#29
post #7

when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If you put all your stuff on your front porch with a sign “please take what you want” and it’s all gone the next day - then you can’t say you were robbed.

I think this is a more apt analogy to what az16 did here

Post reply on HN