Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

381–390 of 466 posts

Re: I found a vulnerability. they found a lawyer

#381

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

This dive instructor was using this insurance company for his clients, and thus had a responsibility to prevent any known risk (data privacy loss in this case).

So he had two options: take his clients and his business to another insurer (and still inform all his current and previous clients about their outstanding risk), or try to help the insurer resolve the risk.

Re: I found a vulnerability. they found a lawyer

#382

Earlier quoted context omitted.

If you flip it, we have a dude here admitting to breaching a large number of accounts and gaining access to PII -- including PII about minors. Are we and the Maltese government just going to trust this guy and assume he has actually deleted everything, with no investigation?

How will you ensure the other people who were exploiting the hole have deleted their copies? What a weird way to think about this.

Is it? if 10 people may have committed a crime, should we exonerate 1 of them because he reported it and promises he didnt do anything?

Re: I found a vulnerability. they found a lawyer

#383
post #331

Earlier quoted context omitted.

If you flip it, we have a dude here admitting to breaching a large number of accounts and gaining access to PII -- including PII about minors. Are we and the Maltese government just going to trust this guy and assume he has actually deleted everything, with no investigation?

If his goal was to keep the data he wouldn't have reported it?

That doesnt necessarily track. He could have stolen the data, then reported it to clear his own name. He did access more data than he needed to prove that there is a likely breach.

Re: I found a vulnerability. they found a lawyer

#384

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

We had a situation in Sweden when a person found that if you remove a part of the url (/.../something -> /.../) for a online medical help line service, they got back a open directory listing which included files with medical data of other patients. This finding was then sent to a journalist that contacted the company and made a news article of it. The company accused the tipster and journalist for unlawful hacking and the police opened a case.

But was it? Is it pen testing to remove part of an URL? People debated this question a bit in articles, but then the case was dropped. The line between pen testing and just normal usage of the internet is not a clear line, but it seems that we all agree that there is a line somewhere and that common sense should guide us in some sense.

Re: I found a vulnerability. they found a lawyer

#385
post #377

Earlier quoted context omitted.

>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?

Why the glib dismissal when you most certainly live in a country where the use of titles like 'doctor', 'dentist', 'officer' or 'lawyer' is most certainly regulated? This isn't really that exceptional and as someone from a place where not just anyone can call themselves engineer I'm always baffled when people think that it is.

Your comment completely misses the point of my question. Those countries are regulating the title not the profession.

Here is the difference: the Doctors have a liability for their medical practice, the real Engineers meaning those doing Bridges and Buildings that can kill thousands of people if they fall, have a professional obligation and responsability on the outcomes of their designs and implementation.

I can guarantee you, no Software Engineer from Portugal to Germany will be willing to guarantee the behavior and fitness for purpose, of any System or Software product they develop :-) As you very well can see, if you bother to read the full details on the Software License disclaimers of any software from any large company. From Microsoft to Oracle, IBM and others.

As such those are Software Engineers on title only, what is convenient to be hired for post within Government and similar...

Re: I found a vulnerability. they found a lawyer

#386
post #349

Earlier quoted context omitted.

>> In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. Which countries are those? Are you also only allowed to call yourself a Musician if you a Conservatory Degree?

Portugal, Germany, Canada, Switzerland are the ones I am aware of. Software Engineering degrees are certified by the Engineering Order, universities cannot call themselves that just because they feel like it, and any kind of legal binding documents when notarised required the professional validity.

They regulate the title not the profession.

Re: I found a vulnerability. they found a lawyer

#387
post #247

Earlier quoted context omitted.

> You'd be surprised how many SE's would love for this to happen I'm one of them, and for exactly the reason you say. I worked as a physical engineer previously and I think the existence of PEs changes the nature of the game. I felt much more empowered to "talk back" to my boss and question them. It was natural to do that and even encouraged. If something is wrong everyone wants to know. It is worth disruption and ev…

I think you’re taking the professional responsibility that engineers are given too far. They are not given that responsibility to make political decisions, as you seem to be implying. Engineers are professionals in the hard sciences, not in social sciences. They only have power over ethical and safety issues directly pertaining to technical matters. I think ethics in this sense includes only very widely accepted ethi…

You're the one that brought up politics. You're right that they're hard to decouple from ethics as that's essentially how the parties form.

But where I disagree with you, and extremely, is that we should not have our own personal ethics and adopt that of what we believe is society's. You're asking the impossible. Such a thing doesn't exist. Whichever country you're in you'll find a diverse set of opinions. The most universal ethics are only the most basic. But if it did exist I'd still disagree as you're asking engineers to not be human. You'd be discriminating people based on religion. You'd be discriminating people based on culture. You'd be discriminating people based on their humanity. I'm extremely opposed to turning humans into mindless automata. Everyone has the right to their own beliefs and this is our advantage as our species.

Re: I found a vulnerability. they found a lawyer

#388
post #349

Earlier quoted context omitted.

Portugal, Germany, Canada, Switzerland are the ones I am aware of. Software Engineering degrees are certified by the Engineering Order, universities cannot call themselves that just because they feel like it, and any kind of legal binding documents when notarised required the professional validity.

They regulate the title not the profession.

I mentioned legal signatures for a reason.

Re: I found a vulnerability. they found a lawyer

#389
post #225

Earlier quoted context omitted.

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?

If I start calling "bananas" "apples" then I devalue the meaning of the word "apple". You can't differentiate which I'm referring to.

If I start calling "bananas" "apples" the price at the store doesn't change.

I think you don't understand what the word "value" means. You understand one meaning, but it has more than one.

Re: I found a vulnerability. they found a lawyer

#390
post #377

Earlier quoted context omitted.

Why the glib dismissal when you most certainly live in a country where the use of titles like 'doctor', 'dentist', 'officer' or 'lawyer' is most certainly regulated? This isn't really that exceptional and as someone from a place where not just anyone can call themselves engineer I'm always baffled when people think that it is.

Your comment completely misses the point of my question. Those countries are regulating the title not the profession. Here is the difference: the Doctors have a liability for their medical practice, the real Engineers meaning those doing Bridges and Buildings that can kill thousands of people if they fall, have a professional obligation and responsability on the outcomes of their designs and implementation. I can gua…

That is the thing software can kill, or destroy lives in presence of bugs.

Again, sign any legal documents as engineer, and a court visit might turn into reality.

Post reply on HN