Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

391–400 of 466 posts

Re: I found a vulnerability. they found a lawyer

#391
post #309

Earlier quoted context omitted.

Professional labour value isn't synonymous with late stage capitalism without ethics or morals. Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.

How do you explain the low quality of software coming out of all of the other countries you have mentioned with protected titles? The software is happening regardless of title and you haven’t given any examples of the value of where kissing the ring to get the certification has been critical to Canada/Germany/Switzerland producing better software.

Are all programmers called engineers in these countries?

You've made such a wild assumption that I'm convinced you're more interested in fighting then discussing

Re: I found a vulnerability. they found a lawyer

#392
post #309

Earlier quoted context omitted.

Professional labour value isn't synonymous with late stage capitalism without ethics or morals. Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.

How do you explain the low quality of software coming out of all of the other countries you have mentioned with protected titles? The software is happening regardless of title and you haven’t given any examples of the value of where kissing the ring to get the certification has been critical to Canada/Germany/Switzerland producing better software.

There are engineers, and there are brick layers.

You mean Android's great quality, or Chrome CVEs by the way?

Re: I found a vulnerability. they found a lawyer

#393

Earlier quoted context omitted.

> is illegal in Germany Germany is not exactly well-known for having reasonable IT security laws

It's not necessarily just Germany. Lots of countries have laws that basically say "you cannot log in to systems that you (should) know you're not allowed to". Technical details such as "how difficult is the password to guess" and "how badly designed is the system at play" may be used in court to argue for or against the severity of the crime, but hacking people in general is pretty damn illegal. He also didn't need t…

The main problem I have this with real-world analogies we use for hacking is we assume that, like a home owner, these companies ultimately care about security and are in good-faith trying to make secure systems.

They're not. They're malicious actors themselves. They will expose the absolute maximum amount of data they can with the absolute maximum amount of parties they can to make money. They will also collect the absolute maximum amount of data. Your screen is 1920 by 1080? Cool, record that, we can sell that.

All the common sense practices we were taught in school about data security, they do the opposite. And, to top it off, they don't actually want to fix ANYTHING because doing so threatens their image, their ego, and potentially their bottom line.

Re: I found a vulnerability. they found a lawyer

#394
post #392

Earlier quoted context omitted.

How do you explain the low quality of software coming out of all of the other countries you have mentioned with protected titles? The software is happening regardless of title and you haven’t given any examples of the value of where kissing the ring to get the certification has been critical to Canada/Germany/Switzerland producing better software.

There are engineers, and there are brick layers. You mean Android's great quality, or Chrome CVEs by the way?

Just because you have an engineering degree doesn't mean your code is of better quality and security than someone without an engineering degree.

Signed, someone with an CS engineering degree.

Re: I found a vulnerability. they found a lawyer

#396
post #390

Earlier quoted context omitted.

Your comment completely misses the point of my question. Those countries are regulating the title not the profession. Here is the difference: the Doctors have a liability for their medical practice, the real Engineers meaning those doing Bridges and Buildings that can kill thousands of people if they fall, have a professional obligation and responsability on the outcomes of their designs and implementation. I can gua…

That is the thing software can kill, or destroy lives in presence of bugs. Again, sign any legal documents as engineer, and a court visit might turn into reality.

If Oracle, IBM or Microsoft after 50 years, and employing thousands of Software Engineers ...include the standard disclaimers on their Software, I dont think those in title only should make much fuss of the Software Engineer badge...

Re: I found a vulnerability. they found a lawyer

#397

Earlier quoted context omitted.

We check the output of engineers tjats what infra audits and certs are for. We basically tell industry if you want to waste your money on poor engineers whose output doesn’t certify go ahead. you could do that with civil engineering. anyone gets to design bridges. bridge is done we inspect, sorry x isn’t redundant your engineering is bad tear it down.

You couldn't do that with civil engineering, because checking if a bridge was built correctly is actually really hard, and it's why it's such a process for engineers to sign off on phases of construction.

You could look at the blueprints and calcs that were used to build it and inspect it, which they do. There’s no fundamental difference. Firms will self enforce engineering rigor because it’s a waste of money not to. Making it more stringent when lives are at stake makes sense, thats the only reason you could use to separate them. Also that can even get blurry in eg avionics software.

Re: I found a vulnerability. they found a lawyer

#398

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

I forgot that US law applies everywhere.

Re: I found a vulnerability. they found a lawyer

#399

Earlier quoted context omitted.

How will you ensure the other people who were exploiting the hole have deleted their copies? What a weird way to think about this.

Is it? if 10 people may have committed a crime, should we exonerate 1 of them because he reported it and promises he didnt do anything?

That depends on provable intent,

and your societal goals for ensuring the next exploit is reported, not ignored or shared online.

Re: I found a vulnerability. they found a lawyer

#400
post #374

Earlier quoted context omitted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

Proton let's me bring my own subdomain for those random emails and does a pretty good job of tracking which email is given to whom, and also supports hiding your email even if you want to initiate the email contact, not just reply (plus scheme in mail address doesn't allow this). Otherwise you can also use their domain too, to stay fully anonymous. So far I've been happy. I hope I'll stay happy.

I've been happy with Proton too. I use my own domain and Proton's catch all for this. I always register using addresses like service.name@matheusmoreira.com.
Post reply on HN