Live data from Hacker News

Websmart, Inc. and 100,000 Vulnerable Websites

samsclass.info

21–30 of 74 posts

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#21

LOL http://www.websmartconsulting.com/profile.php?ClientID='

Its sad that this is 2013 and these basic fucking issues still plague websites (and the people who make them). I wonder if the root of these issues is in education or the tools used? Or both?

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#22

Earlier quoted context omitted.

It doesn't seem that he felt like taking any action since 2010

Are you sure he was notified in those previous incidents? Sure, that's really poor behavior of the company, but you don't know if he was even aware. Sam should have responsibly disclosed the information assuming that it was not already known - his actions were indeed unprofessional and could've been approached differently - if there was still no action taken, then that's a whole other story.

What's "responsible" about not telling the people who actually own the websites in question?

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#26

This is all fine and dandy but I actually find the approach taken by the professor in the first email to be quite unfriendly and perhaps even unprofessional. The guy from Websmart is actually right, there was no need to immediately contact his customers directly. You let the vendor handle the delicate subject with their customers and then take action directly (with a public disclosure) only if the vendor ignores you.

Customers don't actually belong to anyone, you know. None of the vendors I have purchased products or services from have my permission to act as gatekeeper for communication with me, and as such have absolutely no right to act in that capacity. If I learned that a vendor had threatened someone for contacting me, that vendor would never receive another dime from me, and I would investigate whether I had any legal cause of action against that vendor.

Any notion that a third party could threaten someone for communicating with me, or even the notion that someone should go through a third party I have given no gatekeeping-like permission to, is offensive to my basic dignity as a human being.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#27
post #2

Imagine if the local news outlet did a "consumer watchdog" piece on a contractor going around installing windows or doors in homes and businesses with locks that can be easily opened without a key. Then imagine the contractor acknowledged the issue but threatened to sue the news outlet for hurting their business.

Now imagine that the local news outlet displayed a list of addresses of the homes than can be easily opened without a key. That's closer to what happened here. The disclosure was irresponsible. He could have contacted each site owner individually with information limited to their site. Instead, he sent a mass email to total strangers, putting some of them at risk, then blogged about it. That's stupid and inconsiderat…

And now, realizing the danger they are in, they fix the door or harass their vendor into doing it. Finally, thanks to the efforts of one good samaritan, they're safe.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#28
Surprise, many websites are not secure. Does he go around testing people's door locks to see how vulnerable they are to being picked with a basic lock pick set? Maybe knock on some doors and tell the home owners that their home contractor doesn't take security seriously enough and demonstrate how easily the standard door lock can be picked?

I could understand if he was making a business out of this, selling improved security. But this way it just looks like he's out to show people that he knows something they don't know and publicly shame them into some kind of response.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#29
Wow. Just wow. I used to manage client accounts at an agency. Here's how I'm seeing this:

- Author sends a condescending, threatening, passive-aggressive, and shaming email to a vendor and its clients.

- Vendor respectfully explains that it was an unprofessional thing to do, because their client relationships were put at risk without them having a chance to correct their mistake.

- Author completely fails to understand why the vendor would think this, and interprets the email as an effort to "intimidate [him] into silence."

To be clear, I'm not excusing the vendor for their shoddy development work. I just think this professor is clueless about effective communication.

Re: Websmart, Inc. and 100,000 Vulnerable Websites

#30
Here's the thing, a lot of times people just don't care. I've sent emails to Amtrak, USPS, SallieMae and many others about bugs on their sites. Most of the time I just get canned responses saying they'll look into it or reply with something totally irrelevant. Sure it probably would have been the courteous thing to do by sending the webmaster an email first individually, but if you were the client, wouldn't you want to know about this vulnerability? Wouldn't you want to know your database has been compromised?
Post reply on HN