Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

251–260 of 466 posts

Re: I found a vulnerability. they found a lawyer

#252

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

Same with me. I started to get spam from the email I used for a Portuguese airline. They didn't even respond.

I've had multiple "big companies" leak my randomly generated email addresses. I create a unique one for each such account, like say my airline frequent flyer account for delta, and I've had several of those leak.

blah1381812301.318719@somedomain.com would never be guessed.

Re: I found a vulnerability. they found a lawyer

#253

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

Nope, this just didn't works either.

Re: I found a vulnerability. they found a lawyer

#254

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

I think the right way would be to sell this shit on darknet and then anonymously reveail the bug to the public.

Re: I found a vulnerability. they found a lawyer

#255

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

You'd be surprised how many SE's would love for this to happen. The biggest reason, as you said, being able to push back. Having worked in low-level embedded systems that could be considered "system critical", it's a horrible feeling knowing what's in that code and having no actual recourse other than quitting (which I have done on few occasions because I did not want to be tied to that disaster waiting to happen). I…

If you actually have that framework, then give it to someone with less to lose & all them to share it with the world.

Re: I found a vulnerability. they found a lawyer

#256

Earlier quoted context omitted.

He didn't have to crack the site. He could have reported up to that point. We need a change in law but more to do with fining security breaches or requiring certification to run a site above X number of users.

Showing up without a PoC complicates things.

He downloaded data of multiple users

Re: I found a vulnerability. they found a lawyer

#257

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Fastmail will let you create any number of "aliases" as they call them, with not too much friction.

Re: I found a vulnerability. they found a lawyer

#258
post #236

Earlier quoted context omitted.

always cc the local GDPR office when reporting such things

They won't do anything. Had this exact scenario with two Shopify-based sites where my address somehow ended up with the second shop. Reported it, shop 1 investigated themselves and found themselves to be innocent, case closed.

Shopify shares these I think, no?

Re: I found a vulnerability. they found a lawyer

#259

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

Re: I found a vulnerability. they found a lawyer

#260
post #88

Earlier quoted context omitted.

I'm a diver, DAN is the only company I can name that specialises in diving insurance. Huh, apparently they're registered in Malta, what a coincidence...

checks out with both Perplexity[0] and top Google results [0]: https://www.perplexity.ai/search/maltese-scuba-diving-insura...

Interesting that perplexity takes a random Redditor comment as fact...
Post reply on HN