> No exploits, no buffer overflows, no zero-days. Just a login form, a number, and a default password that was set for each student on creation. ai;dr This is AI slop. Use your own words! I would rather read the original prompt!
I found a vulnerability. they found a lawyer
301–310 of 466 posts
Re: I found a vulnerability. they found a lawyer
#302Earlier quoted context omitted.
The blog is under a German domain, the company is from Malta. Why would they care about a US law again?
Because Americans can never comprehend of literally anywhere on earth existing. Genuinely if any other place on earth tried this crap…the Americans would lose their minds.
Re: I found a vulnerability. they found a lawyer
#303Earlier quoted context omitted.
It's standard practice and it freaks managers the fuck out, esp if they're not familiar with hacker culture. Maybe the standard practice needs some work? I'm not sure, I understand the perspective of security researchers who want to force action on a fix. But I also completely understand how a deadline is perceived as a threat. Don't forget that there's lots of gray hat / black hat hackers out there as well, who will…
If this freaks them out maybe they shouldn’t roll their own SaaS?
Re: I found a vulnerability. they found a lawyer
#304Earlier quoted context omitted.
It's illegal in the US, too. This is an incredibly stupid thing to do. You never, ever test on other people's accounts. Once you know about the vulnerability, you stop and report it. Knowing the front door is unlocked does not mean you can go inside.
Don't comment on topics you know nothing about. Nothing this guy did is illegal in the US. Everything this guy did followed standard procedures for reporting security issues. The company apparently didn't understand anything about running a secure software operation and did everything wrong. And there in lies the problem. Without civil penalties for this type of bad behavior, then it will continue. In the US, a lawye…
Yes, this is absolutely illegal. The CFAA is pretty fuzzy when it comes to vuln reporting but accessing other people's accounts without their permission is a line you don't cross. Having a badly secured site is usually not a crime, but hacking one is.
Several jobs ago, some dumbass tested a bunch of API keys that people had accidentally committed on github and then "reported" the vulnerability to us.
The in-house atty I was working with was furious and the guy narrowly avoided legal trouble. If he'd just emailed us about it, we'd've given him something.
Also, whistleblower laws are for employees, not randos doing dumb shit online.
Re: I found a vulnerability. they found a lawyer
#305Earlier quoted context omitted.
In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…
A lot of responses below talking about what a 'certified' or 'chartered' engineer should be able to do. I thought it would be noteworthy to talk about another industry, accountancy. This is how it works in the UK, but it is similar in other countries. They are called 'Chartered Accountants' here, because their institute has a Royal Charter saying they are the good guys. To become a Chartered Accountant has no prerequ…
In some cases, these types of structures make sense, but in most others, they are way overkill.
It’s a conundrum. One of the reasons for the crazy growth of software, is the extreme flexibility and velocity of development, so slamming the brakes on that, would have enormous financial consequences in the industry (so … good luck with that …).
But that flexibility and velocity is also a big reason for the jurassic-scale disasters that are a regular feature of our profession. It’s entirely possible for people that are completely unqualified, to develop software full of holes. If they can put enough lipstick on it, it can become quite popular, with undesirable consequences.
I don’t think that the answer is some structured standard and testing regime, but I would love to see improvement.
Just not sure what that looks like.
Re: I found a vulnerability. they found a lawyer
#306The second you CC CSIRT Malta, you've triggered the 72-hour GDPR Article 33 clock with the Data Protection Commissioner. That's why they complained about "additional complexities"—they couldn't treat this as a theoretical bug anymore. They had 72 hours to either report a confirmed breach (€20M exposure) or silence the witness. They chose door number two.
And that 30-day deadline? To a non-technical GC, "fix this in 30 days or I go public" reads like extortion, not standard disclosure. As that Mustafabei comment noted, that's actionable language in many EU jurisdictions. They genuinely thought they were being shaken down, hence the immediate lawyer deployment.
The self-own is what gets me. Their strategy was rational—silence the guy, claim no "confirmed" breach occurred, avoid Article 34 notifications—but the execution turned a fixable IDOR bug into written evidence of witness intimidation. They managed to validate every suspicion that DAN (let's be real, it's DAN Europe) cares more about covering asses than protecting diver data.
The irony is if he'd skipped the CSIRT CC and just sent a casual "hey, noticed your student IDs look sequential, maybe check your auth?" they'd have fixed it quietly, never notified users, and learned absolutely nothing. Instead we got this mess. Better for the community, worse for his stress levels.
Re: I found a vulnerability. they found a lawyer
#307Earlier quoted context omitted.
In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…
In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.
How have they devalued the profession when the labor of that professions is worth the most in the US?
Re: I found a vulnerability. they found a lawyer
#308Earlier quoted context omitted.
This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.
Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t mean you have any right or legitimacy to impose a deadline on them, you’re not their boss. This is some vigilante shit and it has not justification whatsoever. Report to the org, report to the authorities as needed and move on.
Re: I found a vulnerability. they found a lawyer
#309Earlier quoted context omitted.
In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.
>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?
Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.