Live data from Hacker News

Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

strix.ai

11–20 of 112 posts

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#12
post #6
post #3

Would it be possible to stop using aXXb nomenclature within the titles? Some of us aren't hip enough to know what all of them mean.

Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.

I'll be honest - I was thinking authorization (a11n?) - so I didn't read it closely enough. But despite that, and being on HN from almost the beginning (with a different account I lost the password to), I still didn't know what a16z was, though I do recognize Andreessen-Horowitz.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#13
post #12
post #6

Earlier quoted context omitted.

Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.

I'll be honest - I was thinking authorization (a11n?) - so I didn't read it closely enough. But despite that, and being on HN from almost the beginning (with a different account I lost the password to), I still didn't know what a16z was, though I do recognize Andreessen-Horowitz.

Opposite for me, I've seen a16z tons of time on HN, and also the domain where sometimes, but the full name would have meant nothing to me.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#14
post #12
post #6

Earlier quoted context omitted.

Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.

I'll be honest - I was thinking authorization (a11n?) - so I didn't read it closely enough. But despite that, and being on HN from almost the beginning (with a different account I lost the password to), I still didn't know what a16z was, though I do recognize Andreessen-Horowitz.

I didn't either. This is an ancient debate that can never be resolved completely, though — because the articles that HN submissions point to don't follow a style guide and there are always assumptions about audience priors. Best to just resolve it and move on.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#15
post #12
post #6

Earlier quoted context omitted.

Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.

I'll be honest - I was thinking authorization (a11n?) - so I didn't read it closely enough. But despite that, and being on HN from almost the beginning (with a different account I lost the password to), I still didn't know what a16z was, though I do recognize Andreessen-Horowitz.

[deleted]

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#16

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

They could sell the next one to an adversary for a lot more money if they're going to act like that.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#17

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

They could sell the next one to an adversary for a lot more money if they're going to act like that.

[deleted]

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#18

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?"

I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you".

I have a pre-written reply for these kinds of messages now.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#19

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

They could sell the next one to an adversary for a lot more money if they're going to act like that.

Yes, there are also many other lucrative illegal activities.
Post reply on HN