Ask HN: Maybe found huge security problem, unsure what to do
21–30 of 52 posts
Re: Ask HN: Maybe found huge security problem, unsure what to do
#22Give them 28 days, then pastebin it and stick on reddit.
But now you can't do a thing because they know who you are and will sue you so forget about it and stop using their products.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#23Re: Ask HN: Maybe found huge security problem, unsure what to do
#24Earlier quoted context omitted.
Thank you so much for this. (xpto123 as well). I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice early season cold going so not really interested in sitting on the phone for hours so I've given up on that. I'm going to email blast as many of the emails I can get and if I don't hear anything back from them by Monday I'll pass it onto CERT.
1) Be careful, people who submit proof-of-concept exploits to websites have been arrested for circumventing digital security measures. 2) It's HIGHLY unlikely that you are the first person to discover this, especially if it's a top 100 site. Those sites are constantly probed by attackers looking for exploits precicely because they are so valuable. Something like XSS due to unsanitized input would he found quickly as…
The problem is, when you start poking at server-side flaws as opposed to ones that might exist in applications you run client side like mobile apps, you are entering some very dangerous territory as you are engaged in what is generally considered to be hacking someone else's infrastructure. In the last few years a lot of people in the security community have been probing sites for XSS, SQLi and many other server side vulnerabilities but they are doing so at fairly high risk and as such many use multiple techniques to remain anonymous. All it takes is someone on the receiving end to decide to call the FBI and it doesn't matter how good your intentions were, your life is most likely going to change. I've seen this happen first hand to people I know. One guy I know reported an XSS flaw, offered to help fix it, and was accused of extortion as the receiving company figured his offer to "fix it" came at some cost. Luckily they backed down & he only lost about a weeks worth of pay after being suspended while an investigation took place.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#25Earlier quoted context omitted.
This cannot be emphasized enough. Just keep your mouth shut or you will quite likely be sued. The only thing you should do is simply not just trust that particular company with your data anymore. If the risk to public good is great enough and the bug simply must be revealed then it should be done anonymously and with full disclosure. Contacting the company will only give your address to them.
What would happen if sah88 were to realise the site's name, but not the details, to warn other people to also not trust this company. Is this grounds for defamation or something like that?
Re: Ask HN: Maybe found huge security problem, unsure what to do
#26Earlier quoted context omitted.
What would happen if sah88 were to realise the site's name, but not the details, to warn other people to also not trust this company. Is this grounds for defamation or something like that?
Defamation/libel/etc. is only when you claim something false to be a fact.
Also if you are sued for libel in US and prove that they indeed have a security hole that gives them the evidence directly to sue you for 'hacking' their site.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#27You stated that you send them two messages via a form dedicated to reporting securities vulnerabilities and even tried to call them. I think you have done more than enough and can relax and wait. (Don't bombard them with too many emails.)
Some in these comments say that you might get sued. As long as you don't publish or threaten to publish the vulnerability, I don't see that happening (but than again IANAL).
It is always exciting when you find (your first) vulnerabilities on "high value" targets, but in the end of the day a laymen might not realize that most of the websites even in the Top 100 on Alexa have some security problems.
If you personally use the site and fear for your security, you may want to try a bit harder. For example I have tried multiple times to let my bank know about a vulnerability, but never got a satisfactory answer.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#28Earlier quoted context omitted.
What would happen if sah88 were to realise the site's name, but not the details, to warn other people to also not trust this company. Is this grounds for defamation or something like that?
Defamation/libel/etc. is only when you claim something false to be a fact.