With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…
Ask HN: Maybe found huge security problem, unsure what to do
41–50 of 52 posts
Re: Ask HN: Maybe found huge security problem, unsure what to do
#42Earlier quoted context omitted.
This cannot be emphasized enough. Just keep your mouth shut or you will quite likely be sued. The only thing you should do is simply not just trust that particular company with your data anymore. If the risk to public good is great enough and the bug simply must be revealed then it should be done anonymously and with full disclosure. Contacting the company will only give your address to them.
How about passing the information to someone like the EFF and let them inform the owners? The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?
They are not a general 'help everyone' organization for people who get into technological legal trouble- the closest they come is having a list of law firms they refer uninteresting legal business to.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#43Earlier quoted context omitted.
How about passing the information to someone like the EFF and let them inform the owners? The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?
The EFF exists to influence court cases that are likely to set a precedent. They are not a general 'help everyone' organization for people who get into technological legal trouble- the closest they come is having a list of law firms they refer uninteresting legal business to.
I'm still wondering if it has any legal influence in the US when a site provides a form for reporting vulnerabilities.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#44Re: Ask HN: Maybe found huge security problem, unsure what to do
#45With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…
Re: Ask HN: Maybe found huge security problem, unsure what to do
#46Earlier quoted context omitted.
1) Be careful, people who submit proof-of-concept exploits to websites have been arrested for circumventing digital security measures. 2) It's HIGHLY unlikely that you are the first person to discover this, especially if it's a top 100 site. Those sites are constantly probed by attackers looking for exploits precicely because they are so valuable. Something like XSS due to unsanitized input would he found quickly as…
A couple of years ago in Australia a security consultant noticed that firststatesuper.com.au had a gaping security hole in that he could manually change an ID in the URL and gain access to other users' account information. He kindly notified First State like any good samaritan, and so what do First State do in return? Disable his account, report the "offence" to the police, demand that their IT dept examine his compu…
He disclosed to the organisation who then set the police onto him. Luckily he got off with a warning from police, but that's after having equipment seized etc.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#47Everyone here seems to be saying "oh god, don't do it, CFAA!" Respectfully, this sort of fear is what holds the Internet back. You are incredibly unlikely to get sued unless: you are threatening to disclose publicly, you intentionally stole data from the site and are storing it now, you threaten to sell said stolen data to a journalist or anyone else, etc. It costs companies, generally, a lot of money to sue someone.…
I'm a kind person, but my #1 obligation is to my family, not random internet website users.
Internet can not ever be risk free. You post data online, you can expect a low probability of it getting lost / stolen. You're fine with that, because most data is actually not that private, and because you somehow benefit from posting it online.
Security vulnerability reporting must be risk free, because it's possible for it to be. You just need a proper law.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#48You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…
In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…
They're not going to acknowledge any issue until they've patched it if they're smart.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#49You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…
In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…
I received an offer about 10 years ago, on a Friday evening, to sell me 100k stolen credit cards, and was given a sample of 10k stolen credit cards to show they were serious. I did some checking and determined that samples seemed real.
I called the FBI to report this. They were not interested, and suggested I try the Secret Service. I did, and they were not interested.
I tried a couple major credit card companies. One was not interested. One gave me an email address to forward the sample list and the full list offer to and said someone would look at it Monday morning.
Re: Ask HN: Maybe found huge security problem, unsure what to do
#50You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…
In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…
[1] http://www.bbc.com/news/technology-29310042