I found a vulnerability. they found a lawyer
251–260 of 466 posts
Re: I found a vulnerability. they found a lawyer
#252I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.
Same with me. I started to get spam from the email I used for a Portuguese airline. They didn't even respond.
blah1381812301.318719@somedomain.com would never be guessed.
Re: I found a vulnerability. they found a lawyer
#253I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…
Re: I found a vulnerability. they found a lawyer
#254Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…
Re: I found a vulnerability. they found a lawyer
#255Earlier quoted context omitted.
In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…
You'd be surprised how many SE's would love for this to happen. The biggest reason, as you said, being able to push back. Having worked in low-level embedded systems that could be considered "system critical", it's a horrible feeling knowing what's in that code and having no actual recourse other than quitting (which I have done on few occasions because I did not want to be tied to that disaster waiting to happen). I…
Re: I found a vulnerability. they found a lawyer
#256Earlier quoted context omitted.
He didn't have to crack the site. He could have reported up to that point. We need a change in law but more to do with fining security breaches or requiring certification to run a site above X number of users.
Showing up without a PoC complicates things.
Re: I found a vulnerability. they found a lawyer
#257I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.
How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?
Re: I found a vulnerability. they found a lawyer
#258Earlier quoted context omitted.
always cc the local GDPR office when reporting such things
They won't do anything. Had this exact scenario with two Shopify-based sites where my address somehow ended up with the second shop. Reported it, shop 1 investigated themselves and found themselves to be innocent, case closed.
Re: I found a vulnerability. they found a lawyer
#259Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…
Re: I found a vulnerability. they found a lawyer
#260Earlier quoted context omitted.
I'm a diver, DAN is the only company I can name that specialises in diving insurance. Huh, apparently they're registered in Malta, what a coincidence...
checks out with both Perplexity[0] and top Google results [0]: https://www.perplexity.ai/search/maltese-scuba-diving-insura...