Earlier quoted context omitted.
always cc the local GDPR office when reporting such things
They'll just be incorporated in Ireland who are more than happy to be a haven for such criminals.
I found a vulnerability. they found a lawyer
341–350 of 466 posts
Re: I found a vulnerability. they found a lawyer
#342Earlier quoted context omitted.
Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".
I'm a diver, DAN is the only company I can name that specialises in diving insurance. Huh, apparently they're registered in Malta, what a coincidence...
Re: I found a vulnerability. they found a lawyer
#343Earlier quoted context omitted.
> You don't need to retrieve other people's data to demonstrate the vulnerability. If you’re reporting to a nontechnical team…which sometimes you are…sometimes you do?
If you flip it, we have a dude here admitting to breaching a large number of accounts and gaining access to PII -- including PII about minors. Are we and the Maltese government just going to trust this guy and assume he has actually deleted everything, with no investigation?
What a weird way to think about this.
Re: I found a vulnerability. they found a lawyer
#344Re: I found a vulnerability. they found a lawyer
#345Re: I found a vulnerability. they found a lawyer
#346Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…
Re: I found a vulnerability. they found a lawyer
#347AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…
> I verified the issue with the minimum access necessary to confirm the scope - and stopped immediately after.
No notion of a script, "every password" out of a set of a single default password may be open to interpretation, no mention of data downloads (the wording suggests otherwise), no mention of actual number of accesses (the text suggest a low number, as in "minimum access necessary to confirm the scope").
Still, some data was accessed, but we don't know to what extent and what this actually was, based on the information provided in the article. There's a point to be made about the extent of any confirmation of what seems to be a sound theory at a given moment. But, in order to determine whether this is about a stalled number generator or rather a systematic, predictable scheme, there's probably no way around a minimal test. We may still have a discussion, if a security alert should include dimensions like this (scope of vulnerability), or should be confined to a superficial observation only.
Re: I found a vulnerability. they found a lawyer
#348I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…
> I am offering a window of 30 days from today the 28th of April 2025 for [the organization] to mitigate or resolve the vulnerability before I consider any public disclosure.
> Please note that I am fully available to assist your IT team with technical details, verification steps and recommendations from a security perspective.
He is offering a window of 30 days and that he will consider public disclosure only after that window. He didn't say that this was the full and final window. He didn't say that he will absolutely and definitely disclose. He is being more than co-operative by willing to offer his time and knowledge in this matter, even if he doesn't need to.
If they are not Google, then instead of push-and-shove legal threats, they could have been forthcoming and said something like, "We are not an IT company with expertise in this matter. We will definitely need more than 30 days to resolve this matter. Please let us know if you are agreeable to a longer time Window of before you consider disclosure."
To top it all, they ask to keep this matter away from the authorities despite:
> The Maltese National Coordinated Vulnerability Disclosure Policy (NCVDP) explicitly requires that confirmed vulnerabilities be reported to both the responsible organization and CSIRTMalta.
So he followed the law and that is bad, how?
> I don’t think cc’ing the national agency was that necessary given the scale of the problem that necessary given the scale of the problem.
Children's addresses were publicly accessible via the vulnerability - does the urgency solely require the matter to be large scale to be taken seriously?
> Maybe should’ve just given them a call and have had a friendly chat over the phone. You would’ve helped them and stayed friends.
The same could be said about the company. Why are only people expected to be nice and friendly while it is fine for companies to issue legal threats?
Re: I found a vulnerability. they found a lawyer
#349Earlier quoted context omitted.
In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.
>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?
Software Engineering degrees are certified by the Engineering Order, universities cannot call themselves that just because they feel like it, and any kind of legal binding documents when notarised required the professional validity.
Re: I found a vulnerability. they found a lawyer
#350I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.