Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

301–310 of 466 posts

Re: I found a vulnerability. they found a lawyer

#301
post #158

> No exploits, no buffer overflows, no zero-days. Just a login form, a number, and a default password that was set for each student on creation. ai;dr This is AI slop. Use your own words! I would rather read the original prompt!

A performative display of performative anti-AI purism.

Re: I found a vulnerability. they found a lawyer

#302
post #259

Earlier quoted context omitted.

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

Because Americans can never comprehend of literally anywhere on earth existing. Genuinely if any other place on earth tried this crap…the Americans would lose their minds.

Why don’t you just get a rotisserie chicken from Costco and put some money into your 401k? Be careful, the IRS knows exactly how much taxes you owe.

Re: I found a vulnerability. they found a lawyer

#303

Earlier quoted context omitted.

It's standard practice and it freaks managers the fuck out, esp if they're not familiar with hacker culture. Maybe the standard practice needs some work? I'm not sure, I understand the perspective of security researchers who want to force action on a fix. But I also completely understand how a deadline is perceived as a threat. Don't forget that there's lots of gray hat / black hat hackers out there as well, who will…

If this freaks them out maybe they shouldn’t roll their own SaaS?

How is an insurance company a SaaS?

Re: I found a vulnerability. they found a lawyer

#304

Earlier quoted context omitted.

It's illegal in the US, too. This is an incredibly stupid thing to do. You never, ever test on other people's accounts. Once you know about the vulnerability, you stop and report it. Knowing the front door is unlocked does not mean you can go inside.

Don't comment on topics you know nothing about. Nothing this guy did is illegal in the US. Everything this guy did followed standard procedures for reporting security issues. The company apparently didn't understand anything about running a secure software operation and did everything wrong. And there in lies the problem. Without civil penalties for this type of bad behavior, then it will continue. In the US, a lawye…

I know exactly what I'm talking about, I'm a security engineer lol. Who has worked with plenty of lawyers.

Yes, this is absolutely illegal. The CFAA is pretty fuzzy when it comes to vuln reporting but accessing other people's accounts without their permission is a line you don't cross. Having a badly secured site is usually not a crime, but hacking one is.

Several jobs ago, some dumbass tested a bunch of API keys that people had accidentally committed on github and then "reported" the vulnerability to us.

The in-house atty I was working with was furious and the guy narrowly avoided legal trouble. If he'd just emailed us about it, we'd've given him something.

Also, whistleblower laws are for employees, not randos doing dumb shit online.

Re: I found a vulnerability. they found a lawyer

#305

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

A lot of responses below talking about what a 'certified' or 'chartered' engineer should be able to do. I thought it would be noteworthy to talk about another industry, accountancy. This is how it works in the UK, but it is similar in other countries. They are called 'Chartered Accountants' here, because their institute has a Royal Charter saying they are the good guys. To become a Chartered Accountant has no prerequ…

I’m big on increasing accountability and responsibility for software engineering, but I’ve learned about SEI CMMI, and worked in an ISO 9001 shop.

In some cases, these types of structures make sense, but in most others, they are way overkill.

It’s a conundrum. One of the reasons for the crazy growth of software, is the extreme flexibility and velocity of development, so slamming the brakes on that, would have enormous financial consequences in the industry (so … good luck with that …).

But that flexibility and velocity is also a big reason for the jurassic-scale disasters that are a regular feature of our profession. It’s entirely possible for people that are completely unqualified, to develop software full of holes. If they can put enough lipstick on it, it can become quite popular, with undesirable consequences.

I don’t think that the answer is some structured standard and testing regime, but I would love to see improvement.

Just not sure what that looks like.

Re: I found a vulnerability. they found a lawyer

#306
IANAL but this is exactly it. They weren't being cartoonishly evil—they were in catastrophic liability mode and the blogger's specific choices forced them to show their hand.

The second you CC CSIRT Malta, you've triggered the 72-hour GDPR Article 33 clock with the Data Protection Commissioner. That's why they complained about "additional complexities"—they couldn't treat this as a theoretical bug anymore. They had 72 hours to either report a confirmed breach (€20M exposure) or silence the witness. They chose door number two.

And that 30-day deadline? To a non-technical GC, "fix this in 30 days or I go public" reads like extortion, not standard disclosure. As that Mustafabei comment noted, that's actionable language in many EU jurisdictions. They genuinely thought they were being shaken down, hence the immediate lawyer deployment.

The self-own is what gets me. Their strategy was rational—silence the guy, claim no "confirmed" breach occurred, avoid Article 34 notifications—but the execution turned a fixable IDOR bug into written evidence of witness intimidation. They managed to validate every suspicion that DAN (let's be real, it's DAN Europe) cares more about covering asses than protecting diver data.

The irony is if he'd skipped the CSIRT CC and just sent a casual "hey, noticed your student IDs look sequential, maybe check your auth?" they'd have fixed it quietly, never notified users, and learned absolutely nothing. Instead we got this mess. Better for the community, worse for his stress levels.

Re: I found a vulnerability. they found a lawyer

#307
post #225

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession.

How have they devalued the profession when the labor of that professions is worth the most in the US?

Re: I found a vulnerability. they found a lawyer

#308
post #300

Earlier quoted context omitted.

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t mean you have any right or legitimacy to impose a deadline on them, you’re not their boss. This is some vigilante shit and it has not justification whatsoever. Report to the org, report to the authorities as needed and move on.

Without a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity?

Re: I found a vulnerability. they found a lawyer

#309
post #225

Earlier quoted context omitted.

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?

Professional labour value isn't synonymous with late stage capitalism without ethics or morals.

Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.

Post reply on HN