Live data from Hacker News

Ask HN: Maybe found huge security problem, unsure what to do

news.ycombinator.com

31–40 of 52 posts

Re: Ask HN: Maybe found huge security problem, unsure what to do

#31

Earlier quoted context omitted.

Defamation/libel/etc. is only when you claim something false to be a fact.

Depends on the country. In UK truth is no defense for libel. Also if you are sued for libel in US and prove that they indeed have a security hole that gives them the evidence directly to sue you for 'hacking' their site.

US courts (at a state level) have occasionally ruled similarly, it is a worrying trend.

> The court ruled in the case of Noonan v. Staples that truth published with “actual malice” gleaned from the context of the statement can give rise to a libel lawsuit.

http://itlaw.wikia.com/wiki/Noonan_v._Staples

Re: Ask HN: Maybe found huge security problem, unsure what to do

#32

Earlier quoted context omitted.

Defamation/libel/etc. is only when you claim something false to be a fact.

Depends on the country. In UK truth is no defense for libel. Also if you are sued for libel in US and prove that they indeed have a security hole that gives them the evidence directly to sue you for 'hacking' their site.

> In UK truth is no defense for libel.

What?

http://www.senseaboutscience.org/data/files/A_quick_guide_to...

> Justification: a defendant must show that the substance and fact of what they have written is true. However, a judge decides what the words meant, and therefore what a defendant must prove to be true – sometimes not what a defendant expects.

http://en.wikipedia.org/wiki/English_defamation_law

> Allowable defences are justification (i.e. the truth of the statement),

Edit:

http://en.wikipedia.org/wiki/Defamation_Act_2013

> and introducing new statutory defences of truth, honest opinion, and 'publication on a matter of public interest' or privileged publications (including peer reviewed scientific journals),

Re: Ask HN: Maybe found huge security problem, unsure what to do

#33
post #10
post #4

When it comes to vulnerability reporting and/or disclosure, there are two schools of thought; "responsible disclosure" and "full disclosure". Unfortunately, what "full disclosure" and "responsible disclosure" actually mean can vary a whole lot. For example, some define "full disclosure" as immediately publishing/disclosing the vulnerability and/or with working exploit code, but more level-headed folks define "full di…

Thank you so much for this. (xpto123 as well). I tried calling but just got bounced around and I'm not sure anyone actually understood/cared. I've got a nice early season cold going so not really interested in sitting on the phone for hours so I've given up on that. I'm going to email blast as many of the emails I can get and if I don't hear anything back from them by Monday I'll pass it onto CERT.

I know at least one fellow who's entire group is employed because the company got a phone call from the government that their network was exposed. In that case, it was also known to be actively exploited by a state actor, but the point stands that management takes phone calls from Uncle Sam quite seriously.

If a house is on fire, don't be a hero. Call 911.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#34
You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it.

1. You haven't given them enough time to acknowledge it.

2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew about the bug before it was exploited.

You've done all you should do for now. You should now wait long enough for them to fix it. Take into account that there may be complications you are unaware of due to how their backend works, or due to how their development and testing is done, or how their bureaucracy works, so be generous.

Then check to see if the problem is still there. If it is, then go public anonymously, with just the technical details. Leave out the history of attempting to contact them (it could compromise your anonymity).

Re: Ask HN: Maybe found huge security problem, unsure what to do

#35

With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…

This cannot be emphasized enough. Just keep your mouth shut or you will quite likely be sued. The only thing you should do is simply not just trust that particular company with your data anymore. If the risk to public good is great enough and the bug simply must be revealed then it should be done anonymously and with full disclosure. Contacting the company will only give your address to them.

How about passing the information to someone like the EFF and let them inform the owners?

The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?

Re: Ask HN: Maybe found huge security problem, unsure what to do

#36
Everyone here seems to be saying "oh god, don't do it, CFAA!"

Respectfully, this sort of fear is what holds the Internet back. You are incredibly unlikely to get sued unless: you are threatening to disclose publicly, you intentionally stole data from the site and are storing it now, you threaten to sell said stolen data to a journalist or anyone else, etc.

It costs companies, generally, a lot of money to sue someone. They aren't interested in doing it unless you seriously piss them off or actually cause their business/revenue harm.

If you are not weev, trolling them publicly and saying you'll sell their data, you can likely disclose and be fine. Just be nice about it.

By being nice, I have disclosed hundreds of vulnerabilities over the years, in this manner. Sometimes they even let me write a blog post about it afterward.

If you want, email me and we can discuss in more detail. Email is in my profile.

tl;dr: find someone to contact via LinkedIn or email (CISO or CTO usually works well), be incredibly nice and non-threatening about it, and you'll be fine.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#37
post #35

Earlier quoted context omitted.

This cannot be emphasized enough. Just keep your mouth shut or you will quite likely be sued. The only thing you should do is simply not just trust that particular company with your data anymore. If the risk to public good is great enough and the bug simply must be revealed then it should be done anonymously and with full disclosure. Contacting the company will only give your address to them.

How about passing the information to someone like the EFF and let them inform the owners? The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?

I think the CERT would be a better idea.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#38
There's some great advice here. I'd like to add to it from the prospective of the people at the large internet service receiving the disclosure.

Every day they possibly get hundreds of emails to their security@ email address. The vast majority of it breaks down into categories of spam and support requests. Then when you have removed that you are left with a pile of "security disclosures", the vast majority of which are a very poor standard, or generated by some sort of scanner software that's returning garbage results.

After this gets filtered the remainder are legitimate issues that need to be investigated. Bear in mind you might not get one of these for weeks and weeks, but you still have to filter the other hundreds of emails.

For all but the largest internet companies (think apple and google), they can't afford to tend to this filtering process 24/7. So this happens Mon-Fri during business hours, and if it's a legitimate report it will make its way to a security engineer.

So, what am I getting at? You've taken the right steps to report this. What you have described sounds like a vulnerability, who knows how long its been there. Given that and the nature of the vulnerability, the likelihood of this been exploited over the coming days sounds low. So we don't have to go to DEFCON 5 just yet. Don't expect companies to react to these reports within hours or over the weekend, theres just too much noise to make this sort of thing feasible. Please give the company a chance to do their thing, this could take a business day or two, just to get acknowledged. And another couple of days to patch (depending on the technical difficulty).

By the way, this is pretty much outlines the value proposition of the Hacker One service[1] and why companies should use them. As bug bounties become more popular, the long tail of garbage security reports will increase and so will the overhead cost to run one of these programs effectively (quick response times, qualified engineers triaging the inbound queue, etc.).

[1] https://hackerone.com/

Re: Ask HN: Maybe found huge security problem, unsure what to do

#39
post #34

You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…

In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website.

My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(to emphasize I never published anything on the site, this item was posted by another user and I was actually interested in purchasing it until I got redirected) which I have reported by phone and by form is still up on their site redirecting users. This one redirect doesn't actually appear malicious though but I have no way of telling how many other items are affected. At some point I feel there is a moral obligation for me to disclose the information which leads me to my second problem.

I have no fucking idea if I'm just overly worried (judging by the comments it would seem so) about the vulnerability. I also have no real idea of how serious it is. But it seems to me that even if a fraction of a fraction of transactions are affected it would still amount to a large amount of stolen information.

What I would really like is for them to email me back and say either "Oh wow yeah thanks for catching that" or "God damn you dumbass, no that's not actually a problem because xyz"

Re: Ask HN: Maybe found huge security problem, unsure what to do

#40

With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…

The answer is not "sweep the problem under the rug", but rather "tell people who know what theyre doing". The idea of "oh lets just pretend this security hole doesnt exist" makes me cringe.

As JCR wrote: "The safe and sane approach is to contact CERT [3,4] through their vulnerability reporting page [5] and let them contact the vendor."

[4] https://www.cert.org

[5] http://www.kb.cert.org/vuls/html/report-a-vulnerability/

Post reply on HN