> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…
Researcher finds flaw in a16z website that exposed some company data
21–30 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#22How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker mindset is the first to reach out.
a16z should be fined heavily unfortunately there is no legal framework for this type of negligence
Re: Researcher finds flaw in a16z website that exposed some company data
#23Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.
Re: Researcher finds flaw in a16z website that exposed some company data
#24they are busy writing a giant "architecture of generative AI" whitepaper. give them a pause, they are dreaming a future agentic world of half-assed chatbots. while the world burns with botched software updates.
botched software updates on a Friday is just the chef’s kiss
Re: Researcher finds flaw in a16z website that exposed some company data
#25Re: Researcher finds flaw in a16z website that exposed some company data
#26when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”
If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…
Re: Researcher finds flaw in a16z website that exposed some company data
#27Re: Researcher finds flaw in a16z website that exposed some company data
#28when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”
If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…
Re: Researcher finds flaw in a16z website that exposed some company data
#29when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”
If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…
I think this is a more apt analogy to what az16 did here
Re: Researcher finds flaw in a16z website that exposed some company data
#30Pretty shitty to not even give a token amount bounty for such a broad hole