Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

271–280 of 466 posts

Re: I found a vulnerability. they found a lawyer

#271

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

Re: I found a vulnerability. they found a lawyer

#272

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

> is illegal in Germany Germany is not exactly well-known for having reasonable IT security laws

It's not necessarily just Germany. Lots of countries have laws that basically say "you cannot log in to systems that you (should) know you're not allowed to". Technical details such as "how difficult is the password to guess" and "how badly designed is the system at play" may be used in court to argue for or against the severity of the crime, but hacking people in general is pretty damn illegal.

He also didn't need to run the script to try more than one or maybe two accounts to verify the problem. He dumped more database than he needed to and that's something the law doesn't particularly like.

People don't like it when they find a well-intentioned lock specialist standing in their living room explaining they need better locks. Plenty of laws apply the same logic to digital "locksmiths".

In reality, it's pretty improbable in most places for the police to bother with reports like these. There have been cases in Hungary where prestigious public projects and national operations were full of security holes with the researchers sued as a result, but that's closer to politics than it is to normal police operations.

Re: I found a vulnerability. they found a lawyer

#273
post #259

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

Because Americans can never comprehend of literally anywhere on earth existing. Genuinely if any other place on earth tried this crap…the Americans would lose their minds.

Re: I found a vulnerability. they found a lawyer

#274

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

If you’re on Gmail, there’s “plus addressing” - this allows you to append any term after your email - and then sort accordingly.

So if your Gmail is foo.bar@gmail.com you can use foo.bar+servicename@gmail.com and the mail will still end up in your mailbox. Then you can create a rule that sorts incoming mails accordingly.

Re: I found a vulnerability. they found a lawyer

#275
post #115

> The security research community has been dealing with this pattern for decades: find a vulnerability, report it responsibly, get threatened with legal action. It's so common it has a name - the chilling effect. Governments and companies talk a big game about how important cybersecurity is. I'd like to see some legislation to prevent companies and governments [1] behaving with unwarranted hostility to security resea…

I'm not a lawyer, but I believe the EU's Cyber Resilience Act combined with the NIS2 Directive do task governments with setting up bodies to collaborate with security researchers and help deal with reports.

The law seems written to target vendors and products rather than services though, reading through this: https://www.acigjournal.com/Vulnerability-Coordination-under...

Re: I found a vulnerability. they found a lawyer

#276

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

It's standard practice and it freaks managers the fuck out, esp if they're not familiar with hacker culture. Maybe the standard practice needs some work? I'm not sure, I understand the perspective of security researchers who want to force action on a fix. But I also completely understand how a deadline is perceived as a threat.

Don't forget that there's lots of gray hat / black hat hackers out there as well, who will begin with an email similar to this, add a bitcoin address for the "bug bounty" in the next, and will end with escalating the price of the "bounty" for the "service" of deleting the data they harvested. It's hard even for tech-savvy managers to figure out which of these you're dealing with. Now put yourself into the shoes of the average insurance company middle manager.

For completeness, I don't think this company's behavior is excusable. I'm just saying that maybe also the security community should iterate a bit more on the nuances of the "standard practice" vulnerability reporting process, with the explicit goal of not freaking people out so bad.

Re: I found a vulnerability. they found a lawyer

#277
You typically disclose the vulnerability for one of these reasons: you want money, you want fame, you want to make a better world. There are others such as blackmail but let's settle for the typical ones.

If you do it for money or fame, you step cautiously not to annoy the company. You ask, you beg, etc. Not something to be proud of but this is life.

If you do this to make the world a better place, you get annoying. You explain the risks, possibly how to fix it and then send a few reminders with the threat of making it public. Depending on where you are this may be a danger for you or not (though you would usually go anonymous in that case).

OP did the right thing. Without setting deadlines, a company will ignore it. Or not - but in that case they will not be offended by the deadline and would discuss with the reporter (by agreeing on mitigation if a complete fix cannot be done easily).

There used to be a time when companies cared because it was an uncommon event. Today you get 3 "We are so sorry" emails a week, so one more or one less make it less stressful to have public disclosures or data leaks. There is simply no accountability.

Re: I found a vulnerability. they found a lawyer

#278
I disclosed a vulnerability much like this one. .gov website. Incrementing IDs. No password to crack, just a url parameter with a Boolean value. Pretty much

example.com/clients/fullz?id=123&butDoIReallyHaveToAuth=false

Changed param key but yeah. Just that. You did need to have an authenticated session, but any valid session token would do.

They hit me with same kind of response. I got a lawyer. Worked out in the end, but I was out three hundred bucks for the consultation

That was the last vulnerability I will ever disclose

Re: I found a vulnerability. they found a lawyer

#279
post #258
post #236

Earlier quoted context omitted.

They won't do anything. Had this exact scenario with two Shopify-based sites where my address somehow ended up with the second shop. Reported it, shop 1 investigated themselves and found themselves to be innocent, case closed.

Shopify shares these I think, no?

That would be illegal. I doubt Shopify are to blame here, it's more likely one of the gazillion plugins that every shop uses was the vector. Either way, it's highly likely the shop owner is the data controller, from a legal perspective.

(Scenario: E-Mail address A with shop A, address B with shop B, then received a newsletter I did not subscribe to [already illegal] from shop B to address A. Only common data point: PayPal account.)

Re: I found a vulnerability. they found a lawyer

#280

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

What is CFAA? I couldn't find anything about it in EU or Malta. Is it something in India or China? Or Japan? Hmm, maybe I'm missing another country.. Australia?
Post reply on HN