Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

31–40 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#31
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

Counterpoint: OP is a security researcher and couldn’t find a single human email address at one of the most well-known VC firms on the planet? LinkedIn? Twitter? Facebook friends? Come on. They’re not hard to reach if one really wants to.

(Note: I still think A16Z should have paid them.)

Re: Researcher finds flaw in a16z website that exposed some company data

#32
post #9

Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.

> how do you actually make this mistake while having the skills to build a web app of this complexity level?

By not building this yourself and instead outsourcing the work to India, to people that work for 4.00$/h

And I'm not blaming the person that has to work for this little cash for delivering shoddy work like this.

Re: Researcher finds flaw in a16z website that exposed some company data

#33
post #9

Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.

It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.

Whoops I accidentally exposed all API keys ever to the public.

No really this is unacceptable for a professional, it’s even bad for an amateur.

If your processes are so insecure that a little tired breaks your whole company you done goofed.

Re: Researcher finds flaw in a16z website that exposed some company data

#37
post #22

When I create a new service and add LetsEncrypt cert to server via ACME. I immediately see logs filled with junk, obviously bots searching for shitty defaults that devs might leave open. I have even seen requests for the process env file lol. How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker m…

> How was such vuln not found and abused in this case?

Maybe it was..

There might have been more value in leaving this one open than just screwing with them.

Re: Researcher finds flaw in a16z website that exposed some company data

#38

Earlier quoted context omitted.

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If you put all your stuff on your front porch with a sign “please take what you want” and it’s all gone the next day - then you can’t say you were robbed. I think this is a more apt analogy to what az16 did here

There's no analog for the sign. You just put it in because without it your scenario still feels like theft (because it is) and you end up arguing against your own point.

Re: Researcher finds flaw in a16z website that exposed some company data

#39
I'm surprised he didn't try harder to contact someone in the company privately.

Surely any contact would have sufficed to at least try to get an introduction to their security team?

If you browse their website there are loads of email addresses for various offices and divisions.

Re: Researcher finds flaw in a16z website that exposed some company data

#40
post #25

If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

It would also be pretty damaging if it includes their LPs.
Post reply on HN