Live data from Hacker News

iViewed your API keys

wale.id.au

111–116 of 116 posts

Re: iViewed your API keys

#111

Earlier quoted context omitted.

But why is the Australian government so "police state" minded? Is that really what the Australian people want? I'd guess they just don't care either way, but in that case why would the Australian politicians push for that? Canada has a pretty similar apathy towards politics but even then we don't see the government forcing Canadian citizens to implement backdoors or raiding the offices of a broadcaster. (Yes the rece…

Propaganda works, Rupert Murdoch has known it for decades. Keep the people scared and they won't question what you are doing.

This is so true. And something sadly I don't think enough Australians are aware of.

Re: iViewed your API keys

#112
post #20

I'd be careful about posting stuff like this as a young person in Australia. The modern situation is incredibly hostile towards this sort of disclosure. Especially regarding a government entity. It's not that you've done anything in the slightest bit wrong. It's that others with power can easily make it become wrong with little to no backlash in the current Australian climate. I understand the desire for recognition,…

They’ve been reasonable by waiting four months from initial contact, but in vulnerability disclosures it’s polite to add a better timeline of events. There’s still some detail that hasn’t been fully resolved, but it’s not clear what the residual impact is. This particular post doesn’t really seem to go into too much depth about what these keys are used for, or the damage that could be done, but I’m erring on the side…

> beloved by most Australians

That doesn't say much either way and isn't relevant - could just be that the propaganda is doing its job.

Re: iViewed your API keys

#113

To be fair, I think a lot of developers begin with that. There is a logistical problem in providing secrets to a process without getting the secret exposed. Environment variables are an often chosen approach. Of course when the software is tested and ready to be deployed, the step to use a secure container containing credentials is often neglected like it was probably done here. This isn't necessarily sloppy programm…

Environment variables on the server side, sure, but having those end up in the client...? If you find that this is a relatable mistake, I hope you have someone with more experience reviewing your code and processes before they touch anything remotely sensitive in production...

(Unless you're just trolling)

Re: iViewed your API keys

#114

Earlier quoted context omitted.

Both the first and third example you gave would strike me as crossing the line. Without permission to test the security of a system, you shouldn't be trying credentials you've stumbled upon or defaults. If you randomly try my front door and find that it's unlocked, don't expect me to be thanking you.

> If you randomly try my front door and find that it's unlocked, don't expect me to be thanking you. Why? If someone tries my front door, doesn't go in but confirms that it is unlocked by opening it by an inch (=verifies the DB credentials but doesn't run any queries) without really peering into my private spaces, then privately reaches out with "hey, hey, your door is not locked - I haven't went in but I know it's u…

If somebody tried my door handle, I’m immediately going to assume malicious intent.

Start trying door handles in your neighbourhood and I can guarantee you’ll either be assaulted by an unhappy resident or arrested pretty quickly. It’s not acceptable behaviour however altruistic you believe it to be.

Re: iViewed your API keys

#115

Earlier quoted context omitted.

Better one who would let me know, than someone who would steal everything and sell it, no?

Sure, but that doesn’t mean that I’d be thanking you. These arguments about computer crime law are always the same, and people with your view always shoot themselves in the foot with analogies like this. This is not a pre-existing social expectation. If someone comes to my front door, tells me that it’s unlocked, and tells me that they were trying peoples front doors for the intellectual thrill, there is a 0% chance…

These analogies to the real world fall apart when you realize that cyberspace is filled with millions of people trying to "break into your house".. If you have an internet-connected service you need to expect people to attack it. Not so with a house.

Of course, you have every right to be upset that someone tried to do that to you. But it's clear they don't have bad intentions at least, because they let you know.

Re: iViewed your API keys

#116

I'd be careful about posting stuff like this as a young person in Australia. The modern situation is incredibly hostile towards this sort of disclosure. Especially regarding a government entity. It's not that you've done anything in the slightest bit wrong. It's that others with power can easily make it become wrong with little to no backlash in the current Australian climate. I understand the desire for recognition,…

That's really sad. I've never been there but definitely romanticized the beers and beaches and kangaroos motif. Oh well.

It's also really untrue, don't believe the doom and gloomers!
Post reply on HN