Live data from Hacker News

Ask HN: Maybe found huge security problem, unsure what to do

news.ycombinator.com

41–50 of 52 posts

Re: Ask HN: Maybe found huge security problem, unsure what to do

#41

With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…

I agree. If it doesn't impact you, turn around and walk away. If you do want to make a difference, sell the exploit to the chinese. You'll still be arrested and charged for hacking, but at least you'll have made some money and made the exploit visible.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#42
post #35

Earlier quoted context omitted.

This cannot be emphasized enough. Just keep your mouth shut or you will quite likely be sued. The only thing you should do is simply not just trust that particular company with your data anymore. If the risk to public good is great enough and the bug simply must be revealed then it should be done anonymously and with full disclosure. Contacting the company will only give your address to them.

How about passing the information to someone like the EFF and let them inform the owners? The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?

The EFF exists to influence court cases that are likely to set a precedent.

They are not a general 'help everyone' organization for people who get into technological legal trouble- the closest they come is having a list of law firms they refer uninteresting legal business to.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#43
post #35

Earlier quoted context omitted.

How about passing the information to someone like the EFF and let them inform the owners? The OP said he used a form for reporting security vulnerabilities on the site. Does he still have to be afraid to get sued in such a case?

The EFF exists to influence court cases that are likely to set a precedent. They are not a general 'help everyone' organization for people who get into technological legal trouble- the closest they come is having a list of law firms they refer uninteresting legal business to.

That's why I wrote "like the EFF". I figured, when you life in a country where you actually can get sued for things like that, there must/should be an organisation or site one can use as a middleman. I wasn't aware of CERT.

I'm still wondering if it has any legal influence in the US when a site provides a form for reporting vulnerabilities.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#45

With all due respect, most of the replies here are missing the most important point. Does the company have a bug bounty policy? No? Then keep your mouth shut and get on with your life . A significant percentage of people in power will react to unsolicited warnings of security vulnerabilities by attacking you as though you were their enemy. Worse, the law is at least not clearly on your side. This is not theoretical:…

Yeah. People don't like this answer because it's so obviously suboptimal in technical and security terms, but you're absolutely right. There's no upside to disclosure and only downside. If they don't welcome disclosures, beware.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#46
post #12

Earlier quoted context omitted.

1) Be careful, people who submit proof-of-concept exploits to websites have been arrested for circumventing digital security measures. 2) It's HIGHLY unlikely that you are the first person to discover this, especially if it's a top 100 site. Those sites are constantly probed by attackers looking for exploits precicely because they are so valuable. Something like XSS due to unsanitized input would he found quickly as…

A couple of years ago in Australia a security consultant noticed that firststatesuper.com.au had a gaping security hole in that he could manually change an ID in the URL and gain access to other users' account information. He kindly notified First State like any good samaritan, and so what do First State do in return? Disable his account, report the "offence" to the police, demand that their IT dept examine his compu…

The same thing happened this year with a teenager who found a SQL injection in the Victorian public transport website: http://www.pcworld.idg.com.au/article/549362/australian_teen...

He disclosed to the organisation who then set the police onto him. Luckily he got off with a warning from police, but that's after having equipment seized etc.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#47
post #36

Everyone here seems to be saying "oh god, don't do it, CFAA!" Respectfully, this sort of fear is what holds the Internet back. You are incredibly unlikely to get sued unless: you are threatening to disclose publicly, you intentionally stole data from the site and are storing it now, you threaten to sell said stolen data to a journalist or anyone else, etc. It costs companies, generally, a lot of money to sue someone.…

This kind of law is what holds the internet back. Why should I risk bankruptcy, litigation and imprisonment over some intern forgetting to sanitize HTML? Like that never happened before on the internet.

I'm a kind person, but my #1 obligation is to my family, not random internet website users.

Internet can not ever be risk free. You post data online, you can expect a low probability of it getting lost / stolen. You're fine with that, because most data is actually not that private, and because you somehow benefit from posting it online.

Security vulnerability reporting must be risk free, because it's possible for it to be. You just need a proper law.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#48
post #39
post #34

You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…

In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…

> What I would really like is for them to email me back and say either "Oh wow yeah thanks for catching that" or "God damn you dumbass, no that's not actually a problem because xyz"

They're not going to acknowledge any issue until they've patched it if they're smart.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#49
post #39
post #34

You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…

In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…

It's always fun to learn the first time how little some big organizations care about security.

I received an offer about 10 years ago, on a Friday evening, to sell me 100k stolen credit cards, and was given a sample of 10k stolen credit cards to show they were serious. I did some checking and determined that samples seemed real.

I called the FBI to report this. They were not interested, and suggested I try the Secret Service. I did, and they were not interested.

I tried a couple major credit card companies. One was not interested. One gave me an email address to forward the sample list and the full list offer to and said someone would look at it Monday morning.

Re: Ask HN: Maybe found huge security problem, unsure what to do

#50
post #39
post #34

You reported it through their security bug reporting form, twice. That's sufficient for now. There are two reasons they may not have acknowledged it. 1. You haven't given them enough time to acknowledge it. 2. They are not acknowledging it to limit their liability. Suppose a black hat subsequently finds it and uses it to cause harm, and a victim sues. The acknowledgement to you could be used as proof that they knew a…

In 95% of cases I wouldn't have even posted this. The company is huge though and they do a lot of transactions like ALOT ALOT. The amount of information that could be exposed is a lot higher than your average website. My problem is really the company should probably have 24/7/365 security support standing by given the industry. I sent in two reports but I never got a confirmation email for either. The original item(t…

You would be surprised. The BBC has been reporting on a similar XSS vulnerability on over a hundred eBay listings with custom Javascript for months now, to no avail [1,2,3]. I guess people really like their parallax sparkles nowadays.

[1] http://www.bbc.com/news/technology-29310042

[2] http://www.bbc.com/news/technology-29279213

[3] http://www.net-security.org/secworld.php?id=17377

Post reply on HN