Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

351–360 of 466 posts

Re: I found a vulnerability. they found a lawyer

#351

Earlier quoted context omitted.

> By even flagging the issue and the potential fallout, I’ve put my career at risk. Simple as. Not your company? not your problem? Notify, move on.

Their websites says they're a freelance cloud architect. The article doesn't say exactly, but if they used their company e-mail account to send the e-mail it's difficult to argue it wasn't related to their business. They also put "I am offering" language in their e-mail which I'm sure triggered the lawyers into interpreting this a different way. Not a choice of words I would recommend using in a case like this.

This is a good point. I think we get a couple of emails a week for exactly this kind of bottom feeder 'consulting firm' 'offering' to tell us all about some massive security issue they found, as long as we sign up for a 'consulting engagement'[1]. On the other hand, we generally ignore them, not threaten to sue them.

[1] We get about as many 'pay us a bounty or we'll tell the world about this horrid vulnerability we found'. I have suggested to legal we treat those like extortion attempts to make them go away and stop wasting our time but legal doesn't want to spend time on it.

Re: I found a vulnerability. they found a lawyer

#353

Earlier quoted context omitted.

IANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html

Can a non specific password constitute a specific protection? I guess no

It can. The fact there is a password, even if you can trivially find said password, is considered a protection. The German law is completely absurd here.

Re: I found a vulnerability. they found a lawyer

#354
Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over disclosure.. Not worth the risk these days.

Re: I found a vulnerability. they found a lawyer

#355

One way how to improve cybersecurity is let cyber criminals loose like predators hunting prey. Companies needs to feel fear that any vulnerability in their systems is going to be weaponized against them. Only then they will appreciate an email telling them about security issue which has not been exploited yet.

One way how to improve cybersecurity is let cyber criminals loose like predators hunting prey.

Who, exactly, is holding them back now?

Re: I found a vulnerability. they found a lawyer

#356

Earlier quoted context omitted.

Web is already mostly centralized, and corporations which should be scrutinized in way they handle security, PII and overall software issues are without oversight. It is also a matter of respect towards professionals. If civil engineer says that something is illegal/dangerous/unfeasible their word is taken into the account and not dismissed - unlike in, broadly speaking, IT.

The question is who defines security. I, as a self-proclaimed dictator of my empire, require, in the name of national security, all chat applications developed or deployed in my empire to send copies of all chat messages to the National Archive for backup in a form encrypted to the well-known National Archive public key. I appoint Professional Software Engineers to inspect and certify apps to actually do that. Distri…

It is my understanding that bridges in Switzerland have bombs, or at least holes for bombs.

Re: I found a vulnerability. they found a lawyer

#357

Earlier quoted context omitted.

If this freaks them out maybe they shouldn’t roll their own SaaS?

How is an insurance company a SaaS?

Most likely, the insurance company handles the actually insurance policies, claims, payouts, etc themselves, but uses a contractor to build their website, user portals, etc.

Re: I found a vulnerability. they found a lawyer

#358
post #125

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

That could be a hack or something the company sold to a third party.

During a property search for rentals in the UK I created a throwaway alias email (to my regular account) as I did not really trust them with my data. This was not for those requiring me to provide credit check papers and name of children (!! yes, you read it right, name of children!) at the very first contact in their web form just to start conversation about if there is viewing ability or not, and then perhaps schedule one. No. Those were avoided completely (despite the desperate property market for renters, I am not that desperate: eventually we left the UK in a big part because of property troubles). Two of those were reported to the relevant authority (one case got confirmed after several months, but still pending after more than a year. The other sank, apparently. My trust in the UK institutions is not elevated). There were more than two requiring full set of data on the prospective viewing candidate.

The throwaway email was for the ""reliable"" ones. The trusted names. Or those without over-reaching data collection (one big name, Cheffin, one of the reported one, had over-reaching habit).

Having a throwaway alias proved benefitial. From zero spam to my email suddenly spam started to arrive with about 4 / week frequency. Kept coming until the alias got disabled. Cannot tell which was the culprit, only have a shortlist based on timing. But that never ever elsewhere used email somehow got to fraudster elements from the few UK property agent organizations I contacted. In very shor time (few weeks).

Re: I found a vulnerability. they found a lawyer

#359
post #317

Earlier quoted context omitted.

> Without a deadline of some form, when do you escalate to public knowledge so customers can know they might get defrauded in some capacity? You set a deadline after an initial conversation and urging them to fix it, if they don’t respond. I think the idea would be to escalate slowly. Like the original poster said large tech companies like know how to do this and streamlined the process. But, to someone not familiar…

But that is the intention, isn't it? The company showed neglect. The researcher has a moral right ( and I would say duty) to make that public. It's nice of them to give the company some time to get their shit together. After the vulnerability has been fixed there is no issue for customers in publishing about the neglect. The bad press for the company is deserved.

The idea was change the initial approach and not mention deadlines and just see if they’ll fix it. Point to the law indicating they should notify the authorities. Then if they don’t respond, give them a timeline tell them you’re notifying them. Like the original post said this is not Google, not a tech company, this looks like extortion of some sort to them. So it’s not that surprising what their response was.

It all depends on the goal. Is the goal for them to fix it most of all? To get them embarrassed? To make a blogpost and get internet points?

Re: I found a vulnerability. they found a lawyer

#360
post #135

Earlier quoted context omitted.

Maybe. Or maybe they took what they know to sell to the black hats.

This is legal, correct?

If you can reasonably know they're criminal? No. If you sell an exploit instead of knowledge of a vulnerability? No. If they pay you with something they stole? No.

But otherwise? Usually, yes.

Post reply on HN