Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

371–380 of 466 posts

Re: I found a vulnerability. they found a lawyer

#371
post #259

Earlier quoted context omitted.

The blog is under a German domain, the company is from Malta. Why would they care about a US law again?

IANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html

Exactly. My apologies for not noticing this was over in Europe, but you'll find laws similar to CFAA all over the place. And in Europe it might be worse simply because you might have 27 different such laws _and_ the European arrest warrant, and you might not know which of those 27 laws applies. (I guess you could say the same about the U.S., with 50 instead of 27, but at least for this sort of thing in the U.S. it's mainly federal law that matters the most.)

Re: I found a vulnerability. they found a lawyer

#372

Earlier quoted context omitted.

Good guideline advice but it seems you didn't read the article. Their personal data was at risk here. Leaving them alone would very likely result in a breach of this person's data. Both he and you have an ethical responsibility to at minimum notify the business of this problem and follow up with it.

That’s not how it works. You are not ethically responsible to hack every company you interact with.

No, that's exactly how it works when you're Certified.

https://www.giac.org/policies/ethics/

"I will protect confidential and proprietary information with which I come into contact."

Re: I found a vulnerability. they found a lawyer

#373

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

I think it is obvious that the author just wants to come out as the great hero bounty hunter he is and in fact did reach the HN front page, so good for them.

If he wanted to solve it he would automatically sue them back for breaching his and his clients' personal data and not make any publicity blog post.

Re: I found a vulnerability. they found a lawyer

#374

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Proton let's me bring my own subdomain for those random emails and does a pretty good job of tracking which email is given to whom, and also supports hiding your email even if you want to initiate the email contact, not just reply (plus scheme in mail address doesn't allow this). Otherwise you can also use their domain too, to stay fully anonymous.

So far I've been happy. I hope I'll stay happy.

Re: I found a vulnerability. they found a lawyer

#375

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

This wasn’t a pen test? It was a drive by “oh fuck the platform I’m using is completely insecure”.

Re: I found a vulnerability. they found a lawyer

#376

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

> In other industries there are professional engineers.

I think this is mostly a US thing.

Re: I found a vulnerability. they found a lawyer

#377
post #225

Earlier quoted context omitted.

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?

Why the glib dismissal when you most certainly live in a country where the use of titles like 'doctor', 'dentist', 'officer' or 'lawyer' is most certainly regulated?

This isn't really that exceptional and as someone from a place where not just anyone can call themselves engineer I'm always baffled when people think that it is.

Re: I found a vulnerability. they found a lawyer

#378

Earlier quoted context omitted.

That’s not how it works. You are not ethically responsible to hack every company you interact with.

No, that's exactly how it works when you're Certified. https://www.giac.org/policies/ethics/ "I will protect confidential and proprietary information with which I come into contact."

GIAC has zero authority, any group of people can get together and make their own policies and print a nice little certificate when somebody applies.

Re: I found a vulnerability. they found a lawyer

#379

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

There's always a deadline, otherwise there is no incentive to remediate.

Re: I found a vulnerability. they found a lawyer

#380

I use a different email address for every service. About 15 years ago, I began getting spam at my diversalertnetwork email address. I emailed DAN to tell them they'd been breached. They responded with an email telling me how to change my password. I guess I should feel lucky they didn't try to have me criminally prosecuted.

Every single time I order from KFC, I get an e-mail by a hot girl in my area. You think I can sue them for free chicken wing buckets?

Those aren't spam. Its that hot girls really want your wings.
Post reply on HN