Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

41–50 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#41
> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately.

I just don't understand this petty attitude. This almost guarantees next time somebody that finds vulnerability with a16z or any of its companies to seek black market rewards that will do far more damage.

This is just like when KakaoTalk refused to payout bug bounty because you had to be a Korean citizen which ended up causing more vulnerabilities to be discovered in the wild.

Companies and billionaires reading this, please don't be petty like Andreesen. Guy went from a leader to a borderline security fraud artist. You don't want to be earning more ire from the public in the current political climate. It's dangerous.

Re: Researcher finds flaw in a16z website that exposed some company data

#42
post #7

when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If I leave other people’s stuff that I promised to take care of on the street and it gets stolen, I would be to blame.

Re: Researcher finds flaw in a16z website that exposed some company data

#44

Earlier quoted context omitted.

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If you put all your stuff on your front porch with a sign “please take what you want” and it’s all gone the next day - then you can’t say you were robbed. I think this is a more apt analogy to what az16 did here

More like if they kept their wallets in an open basket on the porch.

It's not an invitation to take it, it's just really stupid.

Re: Researcher finds flaw in a16z website that exposed some company data

#45
post #26

Earlier quoted context omitted.

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

[deleted]

[deleted]

Re: Researcher finds flaw in a16z website that exposed some company data

#46
post #27

[flagged]

Well it could be this person that is professional and does not sell all your data to North Korean ransomware gangs - or it could be the one that does. Which one do you prefer?

I (we) would obviously prefer the professional person who is doing good for society. The problem is, this behaviour isn't good for them. I am not an expert or anything but from what I know, pentesting without explicit prior permissions can easily lead to huge lawsuits. I would rather that the careless people get their cars stolen than the good people all lose heart completely.

Re: Researcher finds flaw in a16z website that exposed some company data

#47
post #9

Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.

my guess is internal tool that wasn't expected to be exposed publicly.

additionally, i didn't realize there are tools to automatically discover unreferenced subdomains like this. i would have just assumed security by obscurity

Re: Researcher finds flaw in a16z website that exposed some company data

#48

Earlier quoted context omitted.

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If you put all your stuff on your front porch with a sign “please take what you want” and it’s all gone the next day - then you can’t say you were robbed. I think this is a more apt analogy to what az16 did here

Using those credentials is still a violation of the he CFAA, no reasonable person would think they were invited to access the systems protected by those credentials.

Re: Researcher finds flaw in a16z website that exposed some company data

#49
post #25

If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

Collecting the keys from a public source-code of a web page is legal (and can be safely reported).

Using these keys to access unauthorized systems is a crime.

This is a major difference.

Re: Researcher finds flaw in a16z website that exposed some company data

#50
post #42

Earlier quoted context omitted.

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

If I leave other people’s stuff that I promised to take care of on the street and it gets stolen, I would be to blame.

blame isn't mutually exclusive. you can still blame the person that stole it too!
Post reply on HN