Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

261–270 of 466 posts

Re: I found a vulnerability. they found a lawyer

#261

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

Would a better course of action here have been for him to generate a “test test” account under his?

they you could kick him out of the org for "creating a bogus account" - "our company isn't bad, you're the bad actor". The bad company he was try get to fix their thing didn't behave properly, end of story.

This happens over and over again because for so many companies their natural thing is to hid any problem and threaten to sue anyone who discloses. Software problems have broken that typical behavior, to some extent.

I salute the author of this post who dared to do the right thing. I hope the company comes to their senses and doesn't try to punish the diving instructor. Over and over companies have tried this same "attack the problem reporter" strategy when software problems are revealed.

Re: I found a vulnerability. they found a lawyer

#262
post #260
post #88

Earlier quoted context omitted.

checks out with both Perplexity[0] and top Google results [0]: https://www.perplexity.ai/search/maltese-scuba-diving-insura...

Interesting that perplexity takes a random Redditor comment as fact...

yeah, so many software engineers are not verify "ai search results". Hey people, llm generated search results aren't reliable, might well have hallucinations. You have to verify anything they say.

Re: I found a vulnerability. they found a lawyer

#263

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

I use addy.io

Re: I found a vulnerability. they found a lawyer

#264

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

Adding a deadline to a disclosure of a vulnerability of this nature is standard practice. Every day it's not patched is a day data could be compromised. Any halfway competent lawyer should be fully aware of this.

Disclosure without a deadline WILL be ignored.

It does not matter if it's Google or your local boyscouts club, any organization requiring users to provide information that can be abused in the wrong hands takes on a responsibility to handle such data responsibly.

Re: I found a vulnerability. they found a lawyer

#265

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

> companies should be categorically required to have an cyber audit

I work with a firm that has an annual pen test as part of its SOC2/GDPR/HIPAA audit, and it's basically an exercise in checking boxes. The pen test firm runs a standard TLS test suite, and a standard web vulnerability test suite, and then they click buttons for a while...

The pen test has never found any meaningful vulnerabilities, and several times drive-by white hats have found issues immediately after the pen test concluded

Re: I found a vulnerability. they found a lawyer

#266
post #158

> No exploits, no buffer overflows, no zero-days. Just a login form, a number, and a default password that was set for each student on creation. ai;dr This is AI slop. Use your own words! I would rather read the original prompt!

So strange that I have to scroll this far to find mention of AI writing. It's clearly AI, but apparently now even tech people get fooled not just boomers on Facebook. They don't name the company and the whole story is just way too perfect, and cookie cutter... If you're a human reading this, consider that the comments here may also be AI. Dead Internet and all..

Re: I found a vulnerability. they found a lawyer

#267
post #233
post #230

Of course he got a response by a lawyer. He shouldn't have hacked the whole site, that's highly illegal, and usually the police is coming knocking, not just a lawyer. Such a morally bankrupt weirdo

Rage bait.

The rage bait is the cookie cutter made up story with zero concrete info on the company (disclosure?!) and AI generated writing.

Re: I found a vulnerability. they found a lawyer

#268

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

[deleted]

Re: I found a vulnerability. they found a lawyer

#269

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

This is exactly what I thought. The person did something illegal by accessing random accounts and no explanation makes this better. Could have asked his diving students for their consent, could have asked past students for their consent to access their accounts - but random accounts you cannot access.

Since this is a Maltese company I would assume different rules apply, but no clue how this is dealt with in Malta.

How the company reacted is bad, no question, but I can’t glance over the fact how the person did the initial „recon“.

Re: I found a vulnerability. they found a lawyer

#270

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

Nope, this just didn't works either.

That's an assumption - maybe backed by experience, but still. The professional way would be to slowly escalate. Tell them nice and friendly. Wait a bit. Increase pressure bit by bit.

You also don't directly shout at anyone making a mistake - at least not the first time.

Post reply on HN