Live data from Hacker News

Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

strix.ai

51–60 of 112 posts

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#51

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

They could sell the next one to an adversary for a lot more money if they're going to act like that.

Legality aside there is no market for this really.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#52
post #21

Earlier quoted context omitted.

From the looks of it, they actually asked for a way to report.

email security@company

Sure that is perhaps a good way to inquire about the appropriate channels to disclose a security vulnerability, but email is not a secure communication method for sending the details about a security vulnerability

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#53
post #36

Two questions prompted by this disclosure: 1. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved? 2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher…

> How do independent researchers do this with legal safety? In my experience it’s usually foreign nationals from third-world countries doing drive-by beg-bounty testing. Presumably they don’t much consider legality.

> Presumably they don’t much consider legality.

Or the operation is not even illegal where they come from?

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#54

I've seen this at so many startups (and worked to patch the gaps and put in best practices) including those backed by top tier VCs. The problem is that it is rare for startups to have security minded people. It's usually designers, people who can raise money, and generalists who can stitch together apis. It's not generally platform, db, or security minded people. The proliferation of things like vercel and supabase h…

Yep, this has been my experience over 15 years in startups as well. There are barely any punishments, so there is no incentive for startups to change how they operate.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#55

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

Should have been handled better, but some context is necessary:

If your name is associated with a startup in a visible leadership position you will get mass-spammed from people claiming to have discovered critical vulnerabilities in your system. When you engage with them, the conversation will turn into requests to hire them for their services.

So the CEO handled it poorly, but it's also not a great choice to withhold the details of the vulnerability in initial contact. If the goal was to get something fixed it should have been included in an easy-to-forward e-mail that could have been sent to someone who could act upon it.

Anyone who works with security or bug bounties can tell you that the volume of bad reports was a problem before LLMs. Now that everyone thinks they're going to use LLMs to get gigs as pentesters the volume of reports is completely out of control.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#56

> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.

i have even more damning ones.

When the "good Samaritan" do not go to the vendor, they go to the client (i.e., they do not contact the DIB company, they contact the Gov agency).

I have seen government contractors getting pilloried, losing their livelihood when this happened. And, yes there is always a "quick fix offer" by the "good Samaritan" to the vendor and promised re-assurance to the Gov agency, only if this misguided vendor would go with their solution.

It is also not unusual to find out later on, that the identification or even the resource reported on was wrong - but by this time the Gov agency already punished the contractor and the reporting "good Samaritan" is laughing (sometimes to the bank).

they can get away with unethical vulnerability disclosure because think of the children, the threat to the nation, grandma off the cliff, and .

Yes, sore subject.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#58

Earlier quoted context omitted.

They could sell the next one to an adversary for a lot more money if they're going to act like that.

Legality aside there is no market for this really.

Data breaches of average people sell for quite a bit of money, often for phishing. I find it hard to believe no one would be interested in this.

Or any other dataset with a hyper targeted demographic.

Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability

#59
post #54

I've seen this at so many startups (and worked to patch the gaps and put in best practices) including those backed by top tier VCs. The problem is that it is rare for startups to have security minded people. It's usually designers, people who can raise money, and generalists who can stitch together apis. It's not generally platform, db, or security minded people. The proliferation of things like vercel and supabase h…

Yep, this has been my experience over 15 years in startups as well. There are barely any punishments, so there is no incentive for startups to change how they operate.

You could even say they're paid even more to "move fast and break things".
Post reply on HN