Live data from Hacker News

Accessing Max Verstappen's passport and PII through FIA bugs

ian.sh

11–20 of 151 posts

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#11

Just use a framework to build your site. Don’t reinvent the wheel!

i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#13

Just use a framework to build your site. Don’t reinvent the wheel!

i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.

It can. But it can be very bad at producing wheels that don't break.

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#14

Just out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?

Actual legal threats are uncommon but I have seen some companies try to offer a bribe disguised as a retroactive bug bounty program, in exchange for not publishing. Obviously it is important to decline that.

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#15

Just use a framework to build your site. Don’t reinvent the wheel!

> Just use a framework to build your site. Don’t reinvent the wheel!

How do you arrive at that conclusion after reading an article on how an API had a broken access control vulnerability?

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#17

Just use a framework to build your site. Don’t reinvent the wheel!

> Just use a framework to build your site. Don’t reinvent the wheel! How do you arrive at that conclusion after reading an article on how an API had a broken access control vulnerability?

He’s being sarcastic and suggesting using some out of the box rbac thing.

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#18

Earlier quoted context omitted.

i respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.

It can. But it can be very bad at producing wheels that don't break.

Not if you understand how the wheel works. That's the whole point.

Re: Accessing Max Verstappen's passport and PII through FIA bugs

#20
post #4

Strange, the site is run by an Ian Carroll, but the examples show Sam Curry, who is a very famous bug bounty hunter.

From the post:

"Having been able to attend these events by hoarding airline miles and schmoozing certain cybersecurity vendors, Gal Nagli, Sam Curry, and I thought it would be fun to try and hack some of the different supporting websites for the Formula 1 events."

Post reply on HN