Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

111–120 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#111
post #88

Earlier quoted context omitted.

Trying more than one email is not jumping through hoops when it's one of the worst possible vulnerabilities hitting all of their databases/platforms. Being a research means being an adult and having a basic level of responsibility. Just like being a gun owner, it's a powerful tool that needs to be treated with utmost respect. A lot of pentesters are just kids who are angry at the world and the poor state of security,…

A researcher should not have to “try different emails”. Period. There should be a clearly disclosed email provided by the company to report such issues. Very obviously plastered. Or just use the standard abuse@, security@, infosec@, etc. It is by far in the company’s best interests for this to happen because the alternative is public disclosure or disclosure to black hats instead. Anything more is jumping through hoo…

Yes of course company's should do that, but in the real world a lot of companies don't think to do that, especially a marketing site for a VC firm.

Any dev knows what it's like having a million responsibilities, a lot of things get put on TODO lists that never get completed. Them being owned by a wealthy company doesnt mean they have a huge dev team running 247 to handle this stuff. Which is probably why such a obvious failure even happened...

Security researchers get high and mighty extremely quickly, which is immature IMO.

Re: Researcher finds flaw in a16z website that exposed some company data

#112

I made a similar mistake actually. We used a nodejs cms called apostrophecms that had an admin panel called global settings. We used that for managing api keys to our auth server. We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it. Annoyingly we paid a reasonable amount of mon…

> it was in their docs. So not blaming them. We glossed over it. You should be blaming them. You can't excuse dangerous behaviour by documenting it. I feel like this lesson should be known by now.

If the panel setting was specifically for API keys, then yes, that's on apostrophecms.

If it's just some kind of generic settings with name/value pairs, then it might make sense to expose those to the browser, and make that very clear up front.

Re: Researcher finds flaw in a16z website that exposed some company data

#113

Earlier quoted context omitted.

[flagged]

Actually, they posted that a vulnerability existed, https://x.com/xyz3va/status/1807330215955177937 : > someone from @a16z get in touch, now. its bad. security related

What's the relevant difference?

Re: Researcher finds flaw in a16z website that exposed some company data

#114
post #88

Earlier quoted context omitted.

Why should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.

Trying more than one email is not jumping through hoops when it's one of the worst possible vulnerabilities hitting all of their databases/platforms. Being a research means being an adult and having a basic level of responsibility. Just like being a gun owner, it's a powerful tool that needs to be treated with utmost respect. A lot of pentesters are just kids who are angry at the world and the poor state of security,…

Alright then: you go to Andreessen Horowitz's website[1] and see if you can find a SINGLE email address in any of the normal places a business would list the (not-social-media) contact information. Because they did their damnedest to make sure you won't find any.

[1] https://a16z.com/

Re: Researcher finds flaw in a16z website that exposed some company data

#115
post #61
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

Am I blind? I don't seem to find the email address at all on that page

Re: Researcher finds flaw in a16z website that exposed some company data

#116
post #102

Earlier quoted context omitted.

So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.

> So you’d rather researchers reach out to black hats with this information instead? That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.

They didn't post publicly about the vulnerability; they reached out via twitter to tell them that they had one, without giving any details about it whatsoever.

Re: Researcher finds flaw in a16z website that exposed some company data

#117

Earlier quoted context omitted.

[flagged]

Actually, they posted that a vulnerability existed, https://x.com/xyz3va/status/1807330215955177937 : > someone from @a16z get in touch, now. its bad. security related

So they didn't disclose the bug publically... They simply disclosed that there was a bug.

That isn't IMO disclosure. Nearly anything has a bug if you look hard enough.

Re: Researcher finds flaw in a16z website that exposed some company data

#118
post #104

Stuff like this is what gives the entire security and white hat community a bad name. 1. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you. 2. If the company doesn't have a published bug bounty program, they don't owe yo…

> If you are actively breaking into websites

They viewed the source code. Despite what the governor of Missouri[1] thinks, that's not hacking.

[1]: https://www.theverge.com/2021/12/31/22861188/missouri-govern...

Re: Researcher finds flaw in a16z website that exposed some company data

#119

Earlier quoted context omitted.

Why will giving someone a cash reward mean you have a better chance of getting your wallet back in the future?

Because the next person will know there's a good chance you'll give them a cash reward, and that will tip the "immorally take all the cash" vs "return it and hope for a reward" balance more in favour of it being returned. I would have thought that was completely obvious so maybe that's not what you were asking? (On the other hand this is HN...)

It’s just that the analogy breaks down a bit. It’s fair to say a dropped wallet in a city is a one-shot game—it’s reasonable to expect neither the participants nor their acquaintances will ever encounter each other again; whereas a security vulnerability is closer to a repeated one—it’s a fairly small world. (Some kind of neighbourly behaviour would work better here, but then again, it’s more difficult to find a universal experience of that kind.) I didn’t misunderstand this, but perhaps GP did?..

Re: Researcher finds flaw in a16z website that exposed some company data

#120
post #64

The fact that this VC firm didn't provide bug bounty for such a gaping hole does not instill trust.

Yes, if they can’t do web development what does that say about their ability to deploy capital?

If my endodontist can't rebuild a car engine, what does that say about his ability to perform a root canal?

Turns out, not much.

Post reply on HN