Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

111–120 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#111

Earlier quoted context omitted.

I can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling…

FWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they…

Agreed that the wording to fully understand my intent might not be present on the email and is only achieved when you look at the whole email and what information I provide etc, I've been trying different things to see what works as unfortunately I get ignored totally, A LOT.

That is also the reason there is no direct link to my publications on the actual emails, another link to add suspicion of phishing that leads to being ignored. I do provide a link to my index with all my public finds on the signature of the email though.

Also a google search of my handle which I sign and mention on the email would get multiple hits for reputable news websites such as Databreaches.net, TechCrunch, The Register, Publimetro, but doesn't seem companies do much vetting at all before ignoring the alerts.

Re: 'Impossible-to-hack' security turns out to be no security

#112
post #15

Not very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.

OP here, the one who found the exposed data. Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies. Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.

Welcome to Hacker News. Thank you for the post and your advocacy.

Re: 'Impossible-to-hack' security turns out to be no security

#113

Earlier quoted context omitted.

> they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. brain dead take; the article was impolite, the email was an overt threat by an impotent exec *in response to someone trying to help*! Dang it bobby, it's not worse to respond to respond to asshattery (the email) with irreverent sunlight (the article). I also wouldn't call you a bicycle because you're not going an…

I'm not defending him so much as advocating for understanding, grace, transparency, and de-escalation. You of course are welcome to conduct yourself in the ways that you see fit.

> I'm not defending him so much as ...

Nah, it's clear to me that you're defending the CEO, and blaming the researcher. In a manner that's as you state is just my opinion, is inverse from what justice would be.

Re: 'Impossible-to-hack' security turns out to be no security

#114
post #97

Earlier quoted context omitted.

If my first email contains everything required for you to locate and fix your security issue, my motivations are pretty clear.

Your motivations are clear to you, the person drafting the email. If they were clear to the CEO, he likely would not have responded the way he did. Look, I understand that you reached out with the best of intentions and that my criticism is not welcome, mainly because of that. What you are doing is important. I just think if you added a bit more info to your initial email about what you want, things could have gone d…

Motivations are stated after I explain why I'm emailing.

"I'm an independent researcher who posts under the name JayeLTee. I look for publicly exposed data online on my free time and alert the companies affected to try and close the exposure."

There is nothing more than that, want me to make a fairy tale story to tell the companies? I try to be as clear as possible and pass the message as clean as possible with no BS on the email, again because I'm not selling a product or a service.

Re: 'Impossible-to-hack' security turns out to be no security

#115

Earlier quoted context omitted.

FWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they…

> They should have linked to their website where they publish reports, and been more plain about their intentions from the outset. I don't get this. Their intentions should be clear by the fact that they reveal the entirety of the issue (what's wrong, why it's wrong, where to find it) in the first email. They don't ask for money, hide information behind further correspondence, or anything else that would raise suspic…

Like I said, it was "good", and better than most.

But as the reader of lots of these emails, I'm always happier to hear from someone who is able to establish their credibility and intentions with public evidence from the beginning of the conversation.

I'd like to know that I'm dealing with a professional, who takes their work seriously. And I'd like to know if I'm going to be dealing with fallout from next month's feature article as a matter of course, or if I'm being extorted to avoid publishing. (This is a thing).

Re: 'Impossible-to-hack' security turns out to be no security

#116
CEO felt a threat to his company and responded accordingly. He is clearly green and impolite. Sending a vulnerability disclosure to someone without knowing their experience, and given the amount of spam on the web, one should not be surprised at the response. Trying to do a good thing and getting scolded for it feels terrible, though. One might understand why the researcher would put up database details for the world to see and fail to realize it is petty to do so. I hope both gentlemen learned their lesson.

Re: 'Impossible-to-hack' security turns out to be no security

#117

Earlier quoted context omitted.

I don't know how you could see the CEO as a bully in this situation. The researcher clearly has "power" in this situation over the CEO, he pretty much has caught him with his pants down, so in this case the CEO is lashing out at a perceived threat. You are entitled to the opinion that the researcher responded proportionately in this situation, I happen to disagree. I would not want my friends or coworkers responding…

> I don't know how you could see the CEO as a bully in this situation. someone tried to help him, he responded by making threats, and being rude. This is bully behavior. Why do you think responding to either email with a direct threat is reasonable? > The researcher clearly has "power" in this situation over the CEO You don't work in, or around information security do you? You're the first person to ever make any cla…

> someone tried to help him, he responded by making threats

My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat.

> You're the first person to ever make any claim remotely close to saying any "researcher" has any kind of power.

Having the entirety of their application database including customer PII, possibly the capability to encrypt the database and extort the company with it, not to mention the possibility of other potentially undisclosed vulnerabilities, decidedly IS significant power over a company. That's how bad actors are able to use any combination of these things to make money.

> Much stronger than the expectations I have for security researchers, I wouldn't want my CEO to respond to them like a petty twat.

I agree whole-heartedly. As for the rest, we more or less agree, you just are putting the onus on the CEO. I also expect more out of a CEO. I just don't think that feedback is actually particularly constructive to the audience here at HN.

Re: 'Impossible-to-hack' security turns out to be no security

#118

Earlier quoted context omitted.

Your motivations are clear to you, the person drafting the email. If they were clear to the CEO, he likely would not have responded the way he did. Look, I understand that you reached out with the best of intentions and that my criticism is not welcome, mainly because of that. What you are doing is important. I just think if you added a bit more info to your initial email about what you want, things could have gone d…

Motivations are stated after I explain why I'm emailing. "I'm an independent researcher who posts under the name JayeLTee. I look for publicly exposed data online on my free time and alert the companies affected to try and close the exposure." There is nothing more than that, want me to make a fairy tale story to tell the companies? I try to be as clear as possible and pass the message as clean as possible with no BS…

Yes, I did read this line in your email. Possibly the CEO didn't after his trusted rockstar team told him the issue was fixed and that they were un-hackable. Look, I think you could change up your initial email slightly to reach a higher probability of positive interactions. You are welcome to disregard my opinion.

Re: 'Impossible-to-hack' security turns out to be no security

#119

Earlier quoted context omitted.

I'm not defending him so much as advocating for understanding, grace, transparency, and de-escalation. You of course are welcome to conduct yourself in the ways that you see fit.

> I'm not defending him so much as ... Nah, it's clear to me that you're defending the CEO, and blaming the researcher. In a manner that's as you state is just my opinion, is inverse from what justice would be.

Wild how I can state my intentions and then someone would just not believe me.

But seriously, it's not possible for me to frame how the researcher could improve future probability of success without framing it from the CEOs perspective. To do that I must recognize he is a human person with his own internal motivations for his behaviors, which likely are not so much monstrous as childish.

Re: 'Impossible-to-hack' security turns out to be no security

#120

Earlier quoted context omitted.

[flagged]

As I read it, he wants them to secure their systems and fulfill their legal and ethical obligations to their customers and regulators by notifying them of the breach. I'm not sure what you find ambiguous or confusing.

> by notifying them of the breach.

The breach that he actually did. They should fulfill their obligations under the law, and they should file a report with their national law enforcement agency with information about the person who is claiming to have done the crime in question.

Post reply on HN