Live data from Hacker News

Hacking into an insurance company by exploiting their premium calculator

eaton-works.com

11–20 of 113 posts

Re: Hacking into an insurance company by exploiting their premium calculator

#11
>October 18, 2023: I noticed the vulnerability is now fixed – the email sending API now requires authentication. I ask CERT-In if TTIBI can offer a bug bounty reward.

>TTIBI never responded to the question, so I decided to close the case on December 22 and CERT-In sent me a nice appreciation letter.

The letter:

"Dear Eaton Zveare,

This email is written in appreciation and recognition of your efforts for bringing our attention to the "Cryptographic Failures" in one of the Indian websites on 08.08.2023. The role of responsible security researchers is pivotal for creating a secure cyber ecosystem and CERT-In strongly believes in working actively with a researcher like you for the discovery of cyber security vulnerabilities and their subsequent remediation in a responsible manner.

We look forward to your valuable contribution in future as well.

Thanks & Regards"

https://eaton-works.com/cdn-cgi/imagedelivery/VwwCqBIYNXeyNQ...

Re: Hacking into an insurance company by exploiting their premium calculator

#12

This is a boggling level of disdain for customer security - even putting aside the insanely low levels of data security, it's mind boggling that the website remained up for months after the disclosure, and that even after being taken down the vulnerability remained open. Great post!

This is a boggling level of disdain for customer security

To be fair, this usually doesn't start as a boggling level of disdain. It usually starts out as 100% ignorance. It's how the people and the group respond to the negative feedback from experts and from reality, which brings in the disdain, even spiraling to boggling levels.

There are two deep lessons herein, rooted in game theory.

EDIT: In this case, op did everything right!

Re: Hacking into an insurance company by exploiting their premium calculator

#13
post #11

>October 18, 2023: I noticed the vulnerability is now fixed – the email sending API now requires authentication. I ask CERT-In if TTIBI can offer a bug bounty reward. >TTIBI never responded to the question, so I decided to close the case on December 22 and CERT-In sent me a nice appreciation letter. The letter: "Dear Eaton Zveare, This email is written in appreciation and recognition of your efforts for bringing our…

[deleted]

Re: Hacking into an insurance company by exploiting their premium calculator

#14
"Appreciation letter" is why most of these vulnerabilities are not reported or disclosed by whitehats and are actively exploited by hackers.

There should be a legal framework that holds companies liable for certain level of security mishandling when it comes to private customer data.

Re: Hacking into an insurance company by exploiting their premium calculator

#15
post #8

This is a boggling level of disdain for customer security - even putting aside the insanely low levels of data security, it's mind boggling that the website remained up for months after the disclosure, and that even after being taken down the vulnerability remained open. Great post!

Sometimes it feels like the only way to fix these problems is for the(ir) world to burn once.

There's a serious problem with human beings. A very loud, emotionally charged warning used to work perfectly for us. "SABERTOOTH TIGER!" is obvious and it's useful for the warning to be delivered with such emotional force.

However, there's a problem when the severe danger is disguised by layers of abstraction and complexity and obscured by time. Even emotionally neutral warnings will trigger our psychological attack defenses in these cases.

Note, I'm not saying op did anything wrong. What I am saying, is that delivering negative feedback about anything complex is itself a complex operation!

A security membrane which needs this kind of feedback to work correctly should be viewed as having a serious design flaw.

Re: Hacking into an insurance company by exploiting their premium calculator

#16
> Everything after October 18 is a back-and-forth between CERT-In and me trying to determine if there would be a bug bounty reward. TTIBI never responded to the question, so I decided to close the case on December 22 and CERT-In sent me a nice appreciation letter.

If a "leading Insurance Broker across India" can't afford to hire competent developers the least they can do is throw a couple bucks at someone who took the time to identify the multiple severe problems that jeopardized their customers and who notified them responsibly.

The fact that they didn't and still haven't reset the password of the compromised email account blows my mind. Why would I ever trust a company that acts like this to do anything right? It seems like Toyota Tsusho Insurance Broker India should be avoided like the plague.

Re: Hacking into an insurance company by exploiting their premium calculator

#18
Let’s also appreciate that a monitoring email endpoint that was designed more or less as a communication worker/agent/runner has been abandoned and was basically matastasizing. That tells me that they aren’t monitoring email utilization or any other compensatory mechanism for identifying anamolous behavior - eg “hey why is email alias costing us [multiple of others]/month in storage”

“The noreply account could be the most important account in an organization because it could potentially have a record of everything they have ever sent to customers”

Re: Hacking into an insurance company by exploiting their premium calculator

#20

> Everything after October 18 is a back-and-forth between CERT-In and me trying to determine if there would be a bug bounty reward. TTIBI never responded to the question, so I decided to close the case on December 22 and CERT-In sent me a nice appreciation letter. If a "leading Insurance Broker across India" can't afford to hire competent developers the least they can do is throw a couple bucks at someone who took th…

Most likely there are few alternatives

which likely led to this issue in the first place

Post reply on HN