Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

121–130 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#121

Earlier quoted context omitted.

It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.

Perhaps some processes should be put into place to make exposing the entire company into a multi-step failure?

Perhaps some already exist.

But if they have five security processes that each has a 99% chance of catching a bug, that's still a 1-in-10,000 chance that something will slip through. And I'd wager that a16z has more than 10,000 "components" that goes through those processes.

Re: Researcher finds flaw in a16z website that exposed some company data

#122

I made a similar mistake actually. We used a nodejs cms called apostrophecms that had an admin panel called global settings. We used that for managing api keys to our auth server. We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it. Annoyingly we paid a reasonable amount of mon…

Why were you using a web-based content management system for secret management?

Re: Researcher finds flaw in a16z website that exposed some company data

#124
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

This what you expect from VCs. I always prefer to report these incidents to GDPR authorities if user data is leaked. Then they pay the fines and some get a criminal record. Money is something VCs “print” and manipulate.

>Implying the Eu will actually do anything at all whatsoever upon reporting a gdpr issue

>Money is something VCs “print” and manipulate.

You wot m8

Re: Researcher finds flaw in a16z website that exposed some company data

#125
post #27

[flagged]

> I too, as the good samaritan that I am, like to stroll through my neighborhood and give all the cars and bikes I encounter a quick pentest, purely for the benefits of the owners of course. In my neighborhood, "security researchers" can often be seen checking houses for vulnerabilities. During the day, it's usually a woman or a kid with a clipboard who knocks on front doors, checks for cameras, tests if the front do…

"These times" have been around since house doors had locks.

Re: Researcher finds flaw in a16z website that exposed some company data

#126
post #61
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

i think you're missing the fact that that indeed is not a security email, and the engineering/security email i found bounced.

i had no ill intentions. stop pretending i did.

Re: Researcher finds flaw in a16z website that exposed some company data

#127
post #102

Earlier quoted context omitted.

So you’d rather researchers reach out to black hats with this information instead? Because that’s what this line of thinking leads to. It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.

> So you’d rather researchers reach out to black hats with this information instead? That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.

As far as I can tell, their tweet was just:

> someone from @a16z get in touch, now. its bad. security related.

https://x.com/xyz3va/status/1807330215955177937

If your email bounces, I think reaching out over social media is reasonable for a fast response.

Re: Researcher finds flaw in a16z website that exposed some company data

#128
post #61

Earlier quoted context omitted.

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

Am I blind? I don't seem to find the email address at all on that page

Only thing I can find are office mails, which looks more like a trashbin than mail which would respond. Also not where I'd look for a contact mail.

They seem to only want you to connect via social media (which is a poor choice for primary contact IMO).

Re: Researcher finds flaw in a16z website that exposed some company data

#129
post #61
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

> They also have contact email addresses listed at the bottom of https://a16z.com/connect, which the researcher conveniently missed.

They have those now. Do we know they did when the researcher tried to reach out?

Edit: I decided to take a look at it myself. It does seem that that was available on June 3rd of this year [0]. (You'll have to look at the source since the archive doesn't do their animations.) It seems to be available on previous snapshots as well [1].

[0]: https://web.archive.org/web/20240603210532/https://a16z.com/... [1]: https://web.archive.org/web/20240000000000*/https://a16z.com...

[0]: https://web.archive.org/web/20240603210532/https://a16z.com/...

Re: Researcher finds flaw in a16z website that exposed some company data

#130

Earlier quoted context omitted.

Why will giving someone a cash reward mean you have a better chance of getting your wallet back in the future?

Because the next person will know there's a good chance you'll give them a cash reward, and that will tip the "immorally take all the cash" vs "return it and hope for a reward" balance more in favour of it being returned. I would have thought that was completely obvious so maybe that's not what you were asking? (On the other hand this is HN...)

The places you're most likely to get your wallet back in the world are the places you're also less likely to get a reward. The reward for returning a wallet is knowing you're doing your part to make the place you live in a nice place to live.
Post reply on HN