It's pretty shocking how many commenters are blaming the individual for not "trying harder" to find contact information. It's pretty clear a16z didn't want to pay anything or appreciate the disclosure at all. Finding random email addresses and sending them a notice would have gone no where other than spam folders. I get dozens of "disclosures" every week from mostly script kiddies that think my DKIM setting is someho…
Researcher finds flaw in a16z website that exposed some company data
101–110 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#102Earlier quoted context omitted.
The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.
So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.
That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.
Re: Researcher finds flaw in a16z website that exposed some company data
#103>a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because: > there was no available contact on their main site > the email i could find engineering@a16z.com bounced my emails The age-old practice of screwing over security researchers over any possible technicality is still alive and well. Brings tears…
Re: Researcher finds flaw in a16z website that exposed some company data
#1041. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you.
2. If the company doesn't have a published bug bounty program, they don't owe you anything. Yes they can still be nice and pay you, but they definitely won't if you disclose the vulnerability to the rest of the world without giving them a heads up and enough time to fix it.
3. "Oh I couldn't find an email address" is the worst excuse in the world. I found one after exactly 5 seconds of Googling (at the bottom of https://a16z.com/connect). And even otherwise there's Twitter, Instagram, LinkedIn and a hundred other ways to reach someone at the company if you really want to.
This is classic case of clout chasing over responsible disclosure.
Re: Researcher finds flaw in a16z website that exposed some company data
#105Earlier quoted context omitted.
Why should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.
I don't think the onus should be on the researcher, and I think A16Z should have paid them. But if they actually wanted to get in touch, I'm just saying they could have. If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional. You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to sec…
Presumably, the company wants to be as secure as possible. It’s in their best interest to make this process as painless as possible. A security researcher has many options for what to do with a found exploit, some far less moral than others. The company has very few, relatively. They are the ones that are limited and therefore should be doing everything in their power to ensure the best outcome, a responsible disclosure that is fixed as quickly as possible.
The best way to ensure they do this is to provide an obvious, easy to find avenue for these things. This includes reasonable, well-displayed emails (or using something like a standard abuse@, etc) and a bug bounty.
Simply put, the company is the one that should be going out of their way or else they will just have researchers either disclosing it publicly or selling the exploit for likely far more money than a bug bounty.
Re: Researcher finds flaw in a16z website that exposed some company data
#106[flagged]
In my neighborhood, "security researchers" can often be seen checking houses for vulnerabilities. During the day, it's usually a woman or a kid with a clipboard who knocks on front doors, checks for cameras, tests if the front door is locked, etc. I'm told they work with crews of men who will come back later to do a more thorough investigation when everyone is gone so as not to bother the homeowner.
Every night, there are other "security researchers" who test all the doors of all the cars parked on the street and in driveways. If you leave your car door unlocked just once, you'll be informed about it the next morning!
It's really something to live in these times!
Re: Researcher finds flaw in a16z website that exposed some company data
#107Earlier quoted context omitted.
Let's imagine your backpack is open. It's polite to say thanks if someone informs you that you accidentally left your backpack open. But in no way you are supposed to give them anything. Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.
It's not the same. Figuring out a bagpack is open takes no effort. Finding a backdoor takes a lot of effort.
Re: Researcher finds flaw in a16z website that exposed some company data
#108Earlier quoted context omitted.
So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.
> So you’d rather researchers reach out to black hats with this information instead? That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.
Because this is explicitly what happens when a company doesn’t have a good process for accepting and responding to exploits.
The onus should entirely be on the company to invite researchers to find and report exploits in a responsible way. They are the ones at risk of losing millions of dollars over an exploit.
Re: Researcher finds flaw in a16z website that exposed some company data
#109Re: Researcher finds flaw in a16z website that exposed some company data
#110Earlier quoted context omitted.
Well it could be this person that is professional and does not sell all your data to North Korean ransomware gangs - or it could be the one that does. Which one do you prefer?
I (we) would obviously prefer the professional person who is doing good for society. The problem is, this behaviour isn't good for them. I am not an expert or anything but from what I know, pentesting without explicit prior permissions can easily lead to huge lawsuits. I would rather that the careless people get their cars stolen than the good people all lose heart completely.