Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

101–110 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#101

It's pretty shocking how many commenters are blaming the individual for not "trying harder" to find contact information. It's pretty clear a16z didn't want to pay anything or appreciate the disclosure at all. Finding random email addresses and sending them a notice would have gone no where other than spam folders. I get dozens of "disclosures" every week from mostly script kiddies that think my DKIM setting is someho…

I’m surprised there is almost no discussion about the severity of reputational damage caused by an extremely amateur bug not expected of a prominent VC firm

Re: Researcher finds flaw in a16z website that exposed some company data

#102
post #61

Earlier quoted context omitted.

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.

> So you’d rather researchers reach out to black hats with this information instead?

That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.

Re: Researcher finds flaw in a16z website that exposed some company data

#103
post #3

>a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because: > there was no available contact on their main site > the email i could find engineering@a16z.com bounced my emails The age-old practice of screwing over security researchers over any possible technicality is still alive and well. Brings tears…

Just a heads up, another comment was posted here that shows right on their website's contact page a list of e-mails for contacting them.

Re: Researcher finds flaw in a16z website that exposed some company data

#104
Stuff like this is what gives the entire security and white hat community a bad name.

1. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you.

2. If the company doesn't have a published bug bounty program, they don't owe you anything. Yes they can still be nice and pay you, but they definitely won't if you disclose the vulnerability to the rest of the world without giving them a heads up and enough time to fix it.

3. "Oh I couldn't find an email address" is the worst excuse in the world. I found one after exactly 5 seconds of Googling (at the bottom of https://a16z.com/connect). And even otherwise there's Twitter, Instagram, LinkedIn and a hundred other ways to reach someone at the company if you really want to.

This is classic case of clout chasing over responsible disclosure.

Re: Researcher finds flaw in a16z website that exposed some company data

#105
post #94

Earlier quoted context omitted.

Why should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.

I don't think the onus should be on the researcher, and I think A16Z should have paid them. But if they actually wanted to get in touch, I'm just saying they could have. If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional. You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to sec…

> You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to secure their own site". The researcher is in this to find holes and make a few bucks (which is fine!). The job is complete when you get in touch.

Presumably, the company wants to be as secure as possible. It’s in their best interest to make this process as painless as possible. A security researcher has many options for what to do with a found exploit, some far less moral than others. The company has very few, relatively. They are the ones that are limited and therefore should be doing everything in their power to ensure the best outcome, a responsible disclosure that is fixed as quickly as possible.

The best way to ensure they do this is to provide an obvious, easy to find avenue for these things. This includes reasonable, well-displayed emails (or using something like a standard abuse@, etc) and a bug bounty.

Simply put, the company is the one that should be going out of their way or else they will just have researchers either disclosing it publicly or selling the exploit for likely far more money than a bug bounty.

Re: Researcher finds flaw in a16z website that exposed some company data

#106
post #27

[flagged]

> I too, as the good samaritan that I am, like to stroll through my neighborhood and give all the cars and bikes I encounter a quick pentest, purely for the benefits of the owners of course.

In my neighborhood, "security researchers" can often be seen checking houses for vulnerabilities. During the day, it's usually a woman or a kid with a clipboard who knocks on front doors, checks for cameras, tests if the front door is locked, etc. I'm told they work with crews of men who will come back later to do a more thorough investigation when everyone is gone so as not to bother the homeowner.

Every night, there are other "security researchers" who test all the doors of all the cars parked on the street and in driveways. If you leave your car door unlocked just once, you'll be informed about it the next morning!

It's really something to live in these times!

Re: Researcher finds flaw in a16z website that exposed some company data

#107
post #85
post #68

Earlier quoted context omitted.

Let's imagine your backpack is open. It's polite to say thanks if someone informs you that you accidentally left your backpack open. But in no way you are supposed to give them anything. Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.

It's not the same. Figuring out a bagpack is open takes no effort. Finding a backdoor takes a lot of effort.

Not when you find it on first "inspect element". That really is the equivalent of looking through someone's window and seeing their bank information and credits cards just lying in full view of anyone who'd look in.

Re: Researcher finds flaw in a16z website that exposed some company data

#108
post #102

Earlier quoted context omitted.

So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.

> So you’d rather researchers reach out to black hats with this information instead? That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.

So you’d rather this happen? That is the question I asked.

Because this is explicitly what happens when a company doesn’t have a good process for accepting and responding to exploits.

The onus should entirely be on the company to invite researchers to find and report exploits in a responsible way. They are the ones at risk of losing millions of dollars over an exploit.

Re: Researcher finds flaw in a16z website that exposed some company data

#110

Earlier quoted context omitted.

Well it could be this person that is professional and does not sell all your data to North Korean ransomware gangs - or it could be the one that does. Which one do you prefer?

I (we) would obviously prefer the professional person who is doing good for society. The problem is, this behaviour isn't good for them. I am not an expert or anything but from what I know, pentesting without explicit prior permissions can easily lead to huge lawsuits. I would rather that the careless people get their cars stolen than the good people all lose heart completely.

One thing is true about what you said: you're definitely not an expert.
Post reply on HN