Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

321–330 of 466 posts

Re: I found a vulnerability. they found a lawyer

#321

Earlier quoted context omitted.

I’m big on increasing accountability and responsibility for software engineering, but I’ve learned about SEI CMMI, and worked in an ISO 9001 shop. In some cases, these types of structures make sense, but in most others, they are way overkill. It’s a conundrum. One of the reasons for the crazy growth of software, is the extreme flexibility and velocity of development, so slamming the brakes on that, would have enormou…

> but in most others, they are way overkill. As an accountant I am able to enforce an accounts regime appropriate to my entity, with concepts like 'materiality' to help. I'm not sure about ISO9001, I'm more familiar with PCIDSS, and I found it to be very proscriptive, and 'all or nothing', compared with accounting standards. For instance in a small company, it is perfectly reasonable to state verbally to your auditor…

> PCIDSS

Just got a PTSD flashback...

Re: I found a vulnerability. they found a lawyer

#322
post #317

Earlier quoted context omitted.

Without a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity?

> Without a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity? You set a deadline after an initial conversation and urging them to fix it, if they don’t respond. I think the idea would be to escalate slowly. Like the original poster said large tech companies like know how to do this and streamlined the process. But, to someone not familiar…

But that is the intention, isn't it? The company showed neglect. The researcher has a moral right ( and I would say duty) to make that public. It's nice of them to give the company some time to get their shit together. After the vulnerability has been fixed there is no issue for customers in publishing about the neglect. The bad press for the company is deserved.

Re: I found a vulnerability. they found a lawyer

#323

Earlier quoted context omitted.

If this freaks them out maybe they shouldn’t roll their own SaaS?

They almost certainly did not. They likely just hired a cheap contractor to get their service up, and went with it when "it worked". The contractor (who was certainly incompetent) probably looked at a bunch of nightmarishly complex identity API's and said "F** it!", combine that with being grossly underpaid and you get stuff like this. It's a bad situation, of course, and involving threatening lawyers makes it even m…

Sure they might get rightfully scared because their neglect caused potential issues for their customers and having that public might decrease revenue.

But that is ok I think. They should get scared enough to not risk such a neglect again

Re: I found a vulnerability. they found a lawyer

#324

Earlier quoted context omitted.

Same with me. I started to get spam from the email I used for a Portuguese airline. They didn't even respond.

always cc the local GDPR office when reporting such things

They'll just be incorporated in Ireland who are more than happy to be a haven for such criminals.

Re: I found a vulnerability. they found a lawyer

#325
post #259

Earlier quoted context omitted.

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

IANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html

Can a non specific password constitute a specific protection? I guess no

Re: I found a vulnerability. they found a lawyer

#326

Last year I found a vulnerability in a large annual event's ticket system, allowing me to download tickets from other users. I had bought a ticket, which arrived as a link by email. The URL was something like example.com/tickets/[string] The string was just the order number in base 64. The order number was, of course, sequential. I emailed the organizer and the company that built the order system. They immediately fi…

And you are not worried enough about other users that you reported the compsny or at least name them here?

Re: I found a vulnerability. they found a lawyer

#328
post #247

Earlier quoted context omitted.

> You'd be surprised how many SE's would love for this to happen I'm one of them, and for exactly the reason you say. I worked as a physical engineer previously and I think the existence of PEs changes the nature of the game. I felt much more empowered to "talk back" to my boss and question them. It was natural to do that and even encouraged. If something is wrong everyone wants to know. It is worth disruption and ev…

I think you’re taking the professional responsibility that engineers are given too far. They are not given that responsibility to make political decisions, as you seem to be implying. Engineers are professionals in the hard sciences, not in social sciences. They only have power over ethical and safety issues directly pertaining to technical matters. I think ethics in this sense includes only very widely accepted ethi…

Engineers are citizens too.

Re: I found a vulnerability. they found a lawyer

#329
post #225

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title.

Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?

Post reply on HN