Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

221–230 of 466 posts

Re: I found a vulnerability. they found a lawyer

#221

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

We check the output of engineers tjats what infra audits and certs are for. We basically tell industry if you want to waste your money on poor engineers whose output doesn’t certify go ahead. you could do that with civil engineering. anyone gets to design bridges. bridge is done we inspect, sorry x isn’t redundant your engineering is bad tear it down.

You couldn't do that with civil engineering, because checking if a bridge was built correctly is actually really hard, and it's why it's such a process for engineers to sign off on phases of construction.

Re: I found a vulnerability. they found a lawyer

#222

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

Same with me. I started to get spam from the email I used for a Portuguese airline. They didn't even respond.

always cc the local GDPR office when reporting such things

Re: I found a vulnerability. they found a lawyer

#223
I am a lawyer and my field do cross this area which the events have transpired.

First, yes, everyone should acknowledge that this matter has been handled poorly by their corporate in-house and external lawyers. These should not have happened. The company should face consequences. I advise my data controller corporate clients to reach out to the reporter/whistleblower immediately and have the IT team collaborate, at the very least talk to the person to effectively replicate the exploit so it can be thoroughly fixed. There should even be procedures on how this should be handled. I understand from the article that this is not how it's so done.

However, I feel obligated to note some different aspects, all of which are absolutely not intended to condone how this company handled the situation. I want to re-iterate; they should have handled it better.

Things to note;

1. They might have already reached out to the data privacy board. The data privacy boards, especially in Europe are very involved in the reporting procedures and in my experience, their experts are very reluctant about public disclosures if the breach/data leak is caused by an exploit. They (sometimes rightfully) do not trust to the private sector's biased explanation that this vulnerabililty has been "fixed" and sometimes effectively prevent public disclosures about the event, allowing only the affected data subjects to be informed about the event. The potential danger of re-exploitation and protection of the public far outweighs the public's (that is persons who are not affected by this breach) right to be informed of such event. Affected persons should be notified. You might not have been aware that these happened. It is their legal obligation to notify the affected data subjects but it is not their legal obligation to notify the reporter that the notifications to the data subjects are made.

2. You did the right thing reaching out to the company and upon some radio silence, contacting the competent authority. But sadly, your duties as a citizen end there. You played your part and did all you could have done if not more. Contacting the company again was not really required. If you found yourself losing sleep, you could have re-contacted the authorities with a data subject request or a right to be informed request. They are legally obligated (under GDPR) to respond to you.

3. Sadly, your e-mail, especially the line below is actually a threat that is actionable under many EU juristictions;

   I am offering a window of 30 days from today the 28th of April 2025 for [the organization] to mitigate or resolve the vulnerability before I consider any public disclosure.
You cannot disclose this to public. Even with good intentions. This might enable the exploit to actually be exploited by ill-faithed persons and would cause more damage. The company is responsible for this vulnerability and they should face counsequences for their actions or the lack thereof, but going public about an exploit is absolutely ill-advised, even if this is intended to coerce the company into action.

Nevertheless, I wanted to re-iterate that this is not intended to condone the company's behaviors in any way. You did the right thing warning them and the authorities but further action might have caused more damage. It is always best to attend to this situations with the guidance of a data privacy legal consultant.

Re: I found a vulnerability. they found a lawyer

#225

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title.

It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession.

I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

Re: I found a vulnerability. they found a lawyer

#226

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Re: I found a vulnerability. they found a lawyer

#227

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Own the domain put catch-all for that domain. No need to generate anything.

Re: I found a vulnerability. they found a lawyer

#228
post #4

> Instead, I offered to sign a modified declaration confirming data deletion. I had no interest in retaining anyone’s personal data, but I was not going to agree to silence about the disclosure process itself. Why sign anything at all? The company was obviously not interested in cooperation, but in domination.

Getting them to agree to your terms pretty much nullifies their domination strategy, and in fact becomes legally binding on them.

It's clear that the intentions of the insurance company are selfish and they want to gain leverage over the reporter. Even if the reporter managed to add a clause about data deletion, the company could still make the reporter's life hell with the remaining clauses that were signed. This is not worth the risk.

Re: I found a vulnerability. they found a lawyer

#229

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

> is illegal in Germany

Germany is not exactly well-known for having reasonable IT security laws

Post reply on HN