Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

281–290 of 466 posts

Re: I found a vulnerability. they found a lawyer

#281
OP discovered the state of Malta's InfoSec culture the hard way.

TLDR: infosec is screwed in Malta. The only people who benefit are malicious actors.

Some missing historical context is that there was no real legislation other than computer misuse up until the recent case known as the FreeHour case. A group of students discovered some pretty nasty vulnerabilities in an app aimed at matching student schedules. One of these vulns was exposing RW API keys for hundreds of student's google calendars, hanging out to dry on the open internet.

The students involved, together with one of their lecturers, sent a standard vuln disclosure notice via email to the company. Instead of what you'd expect, the students were arrested, strip searched and charged with computer misuse.

This really threw the entire local infosec scene off, with some very vocal voices saying how draconian the situation was. Finally they all receieved presidential pardons [1] although last I heard they don't have their hardware back yet. FreeHour and their tech supplier (never publicly mentioned but if you ask around you can find out who they are) never saw any consequences.

I've done two public disclosures [2] [3] which worked out well but only because I knew how to go about it. In such a tiny country is about who you know and how you know them, so in both cases I established contact via trusted intermediaries, both times ensuring I found someone who would know what I was talking about whilst also not immediately reach for the police.

I'm sitting on another issue I discovered because after a long conversation with CSIRT about it we figured the only way I can actually anonymously report it is by snail mailing it to them. I can't pull together the energy to complete it because I don't have the time right now in my life for another legal melodramatic situation.

Despite this, MITA (the government IT department) annually runs cybersec award ceremony [4]. I had once planned to nominate the students for the award but the nomination criteria forbids nominations for individuals who have "averse media publications" about them.

This is very much a deep socio-political problem in the country: we don't handle candour or bluntness of any kind in the public sphere. Being a very blunt person, it got me in all kinds of trouble growing up.

[1] https://timesofmalta.com/article/pardon-issued-students-lect...

[2] https://www.simonam.dev/accidental-pentest/

[3] https://www.simonam.dev/total-account-takeover/

[4] https://ncc-mita.gov.mt/cyber-awards/

Re: I found a vulnerability. they found a lawyer

#282

Earlier quoted context omitted.

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

It's standard practice and it freaks managers the fuck out, esp if they're not familiar with hacker culture. Maybe the standard practice needs some work? I'm not sure, I understand the perspective of security researchers who want to force action on a fix. But I also completely understand how a deadline is perceived as a threat. Don't forget that there's lots of gray hat / black hat hackers out there as well, who will…

If this freaks them out maybe they shouldn’t roll their own SaaS?

Re: I found a vulnerability. they found a lawyer

#283
post #124

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

There are jurisdictions (and cultures) where truth is not an absolute defence against defamation. In other words, it's one thing to disclose the issue to the authorities, it's another to go to the press and trumpet it on the internet. The nail that sticks out gets hammered down. Given that this is Malta in particular, the author probably wants to avoid going there for a bit. It's a country full of organized crime and…

> it's one thing to disclose the issue to the authorities

That's not how any of this works. You are basically arguing for the right to hide criminal actions. Filing with the CSIRT is the only legal action for the white hat to take. This is explicitly by design. Complaining about it is like complaining the police arrested you for a crime you committed.

Re: I found a vulnerability. they found a lawyer

#284

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

First day on the Internet huh. A word of advice, never go to Reddit or read the Youtube comment section.

Re: I found a vulnerability. they found a lawyer

#285

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

A lot of responses below talking about what a 'certified' or 'chartered' engineer should be able to do.

I thought it would be noteworthy to talk about another industry, accountancy. This is how it works in the UK, but it is similar in other countries. They are called 'Chartered Accountants' here, because their institute has a Royal Charter saying they are the good guys.

To become a Chartered Accountant has no prerequisites. You 'just' have to complete the qualification of the institute you want to join. There are stages to the exams that prior qualifications may gain you exemptions from. You also have to log practical experience proving you are working as an accountant with adequate supervision. It takes about 2-3 years to get the qualification for someone well supported by their employer and with sufficient free time. Interestingly many Accountants are not graduates, and instead took technician level qualifications first, often the Association of Accounting Technicians (AAT). The accounting graduates I have interviewed wasted 3 years of their lives...

There are several institutes that specialise in different areas. Some specialise in audit. One specialises in Management Accounting (being an accountant at a company really). The Management accountants one specifically prohibits you from doing audit without taking another conversion course. All the institutes have CPD requirements (and check) and all prohibit you from working in areas that you are not competent, but provide routes to competency.

There are standards to follow, Generally Accepted Accounting Practice GAAP, UK Financial Reporting Standards FRS and the International equivalent IFRS. These cover how Financial Statements are prepared. There are superate standards setting bodies for these. There are also a set of standards that cover how an audit must be done. Then there is tax law. You are expected to know them for any area you are working in. All of these are legally binding on various types of corporation. See how that switches things around? Accountants are now there to help the company navigate the legal codes. The directors sign the accounts and are liable for misstatements, that encourages them to have a director who is an accountant...an audit committee etc.

How does that translate to software?

There are lots of standards, NIST, GDPR, PCI, some of which are legally or contractually binding. But how do I as a business owner know that a software engineer is competent to follow them. Maybe I am a diving company that wants a website. How do I know this person or company is competent to build it? It requires software engineers with specific qualifications that say they can do it, and software engineers willing to say, 'I'm sorry I am not able to work in this field, unless I first study it'.

Re: I found a vulnerability. they found a lawyer

#286

This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.

HN's comment section new favourite sport, trying to guess if an article was generated by LLM. It's completely pointless. Why not focus on what's being said instead?

Because I find LLM-generated content very annoying to read. It's sloggish, bloated, and the speaker always has this cringe way of trying to connect to the audience.

I don't believe the story itself is made up by an LLM but I'd argue that if you have an LLM write your story then it's no problem for you to have it add a TL;DR at the top so we can skip the slop.

Re: I found a vulnerability. they found a lawyer

#287

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

> "is illegal in Germany"

> "Whatever Europe is doing, do the opposite"

on brand

Re: I found a vulnerability. they found a lawyer

#288
post #259

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

IANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html

Re: I found a vulnerability. they found a lawyer

#289

Earlier quoted context omitted.

> is illegal in Germany Germany is not exactly well-known for having reasonable IT security laws

It's not necessarily just Germany. Lots of countries have laws that basically say "you cannot log in to systems that you (should) know you're not allowed to". Technical details such as "how difficult is the password to guess" and "how badly designed is the system at play" may be used in court to argue for or against the severity of the crime, but hacking people in general is pretty damn illegal. He also didn't need t…

And people wonder how the US can just turn off the electric grid of another country on demand...with laws like these, I expect there are local 6 year olds who can do the same.

Re: I found a vulnerability. they found a lawyer

#290

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

It's illegal in the US, too. This is an incredibly stupid thing to do. You never, ever test on other people's accounts. Once you know about the vulnerability, you stop and report it. Knowing the front door is unlocked does not mean you can go inside.

Don't comment on topics you know nothing about. Nothing this guy did is illegal in the US. Everything this guy did followed standard procedures for reporting security issues. The company apparently didn't understand anything about running a secure software operation and did everything wrong. And there in lies the problem. Without civil penalties for this type of bad behavior, then it will continue. In the US, a lawyer doing this would risk disbarment as this type of behavior dances on the edge of violating whistleblower laws.
Post reply on HN