Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

121–130 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#121

Earlier quoted context omitted.

> I don't know how you could see the CEO as a bully in this situation. someone tried to help him, he responded by making threats, and being rude. This is bully behavior. Why do you think responding to either email with a direct threat is reasonable? > The researcher clearly has "power" in this situation over the CEO You don't work in, or around information security do you? You're the first person to ever make any cla…

> someone tried to help him, he responded by making threats My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat. > You're the first person to ever make any claim remotely close to saying any "researcher" has any kind of power. Having the entirety of their application database including customer PII, possibly the capability to encryp…

> I also expect more out of a CEO. I just don't think that feedback is actually particularly constructive.

Your attempts to put any onus on the researcher are actively harmful. No one should point finger at the researchers trying to help. We should all point fingers at the primary person who's able to prevent bad things happening. You haven't once attempted to put any responsibility on the CEO. This is the first time. You asked in another reply if everyone else is being dense; but you're the one blaming the researcher, did you stop to consider if everyone disagrees with you, that maybe you're the problem?

edit:

> My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat.

Yeah, and doing that was gross negligence. There's a reason you're not allowed waive harms arising from gross negligence.

Re: 'Impossible-to-hack' security turns out to be no security

#122
post #85

Earlier quoted context omitted.

I imagine the conversation between the CEO and his reports included something about "it's no biggie, the passwords were hashed using bcrypt, that's like irreversible encryption" without contextualizing that and mentioning that plaintext auth tokens were also exposed.

I think it was downplayed even more. Supposedly the initial email by the researcher only had evidence for leaking database sizes, and I think it's likely that the CEO only got confirmation for this evidence internally and nothing more.

Although I say:

"This server contains over 3,8GB of data exposed including the logins for 16,500 of your users and a lot of PII and credentials, you need to secure access to the server as soon as possible."

After all that transpired after etc I believe it's possible someone downplayed the severity of this to the CEO and he took that as an opportunity to ignore everything I wrote on the emails and reply that way to me assuming I was some cybersecurity vendor working for "Proton" trying to push something for the company to buy.

Re: 'Impossible-to-hack' security turns out to be no security

#123

Earlier quoted context omitted.

> I'm not defending him so much as ... Nah, it's clear to me that you're defending the CEO, and blaming the researcher. In a manner that's as you state is just my opinion, is inverse from what justice would be.

Wild how I can state my intentions and then someone would just not believe me. But seriously, it's not possible for me to frame how the researcher could improve future probability of success without framing it from the CEOs perspective. To do that I must recognize he is a human person with his own internal motivations for his behaviors, which likely are not so much monstrous as childish.

Your other comments across the larger topic refute your claimed good intentions. It's not that wild that no one would believe you, when you contradict yourself.

Re: 'Impossible-to-hack' security turns out to be no security

#124

Earlier quoted context omitted.

Wild how I can state my intentions and then someone would just not believe me. But seriously, it's not possible for me to frame how the researcher could improve future probability of success without framing it from the CEOs perspective. To do that I must recognize he is a human person with his own internal motivations for his behaviors, which likely are not so much monstrous as childish.

Your other comments across the larger topic refute your claimed good intentions. It's not that wild that no one would believe you, when you contradict yourself.

Okay.

Re: 'Impossible-to-hack' security turns out to be no security

#125
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#126

Earlier quoted context omitted.

> someone tried to help him, he responded by making threats My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat. > You're the first person to ever make any claim remotely close to saying any "researcher" has any kind of power. Having the entirety of their application database including customer PII, possibly the capability to encryp…

> I also expect more out of a CEO. I just don't think that feedback is actually particularly constructive. Your attempts to put any onus on the researcher are actively harmful. No one should point finger at the researchers trying to help. We should all point fingers at the primary person who's able to prevent bad things happening. You haven't once attempted to put any responsibility on the CEO. This is the first time…

The CEO is not here, and will never, ever be here, so criticism of him is not constructive, further the author already criticized him and so do many comments here. It is plain to see he acted like an idiot, and no one thinks he is the hero here. That's why it's not constructive. Maybe my response is actively harmful, I don't know, that's not what I'm after, of course.

Re: 'Impossible-to-hack' security turns out to be no security

#127

Earlier quoted context omitted.

Wild how I can state my intentions and then someone would just not believe me. But seriously, it's not possible for me to frame how the researcher could improve future probability of success without framing it from the CEOs perspective. To do that I must recognize he is a human person with his own internal motivations for his behaviors, which likely are not so much monstrous as childish.

Your other comments across the larger topic refute your claimed good intentions. It's not that wild that no one would believe you, when you contradict yourself.

My thoughts on the matter may have evolved over time while interacting with other people in the thread. While I do still believe it could have been an attempt at blackmail, I think it most likely was not, even though the researcher clearly must have downloaded the entire database ahead of time based on the chronology presented. In that case, I can see how I have apparently contradicted myself. But I can assure you, I am not acting in bad faith.

Re: 'Impossible-to-hack' security turns out to be no security

#128

Earlier quoted context omitted.

> They should have linked to their website where they publish reports, and been more plain about their intentions from the outset. I don't get this. Their intentions should be clear by the fact that they reveal the entirety of the issue (what's wrong, why it's wrong, where to find it) in the first email. They don't ask for money, hide information behind further correspondence, or anything else that would raise suspic…

Like I said, it was "good", and better than most. But as the reader of lots of these emails, I'm always happier to hear from someone who is able to establish their credibility and intentions with public evidence from the beginning of the conversation. I'd like to know that I'm dealing with a professional, who takes their work seriously. And I'd like to know if I'm going to be dealing with fallout from next month's fe…

>establish their credibility

>I'd like to know that I'm dealing with a professional, who takes their work seriously

As a sender of these emails, my credibility is established when you go to the location I say there's sensitive data being leaked, and you find sensitive data being leaked. Nothing else should matter.

Are you just going to keep data exposed publicly if, for example, some curious kid notified you instead of a professional?

Hostility to good-faith security research, as shown in the OPs article and in some of the comments here (not specifically you), makes everyone worse off.

Having myself received hostility, demands to prove my credibility, and legal threats when sending notifications like OPs, in most cases now I don't bother to notify anyone. Instead, the data just sits there, accessible to the actual bad guys. Hurray!

Re: 'Impossible-to-hack' security turns out to be no security

#129

Earlier quoted context omitted.

FWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they…

Agreed that the wording to fully understand my intent might not be present on the email and is only achieved when you look at the whole email and what information I provide etc, I've been trying different things to see what works as unfortunately I get ignored totally, A LOT. That is also the reason there is no direct link to my publications on the actual emails, another link to add suspicion of phishing that leads t…

I think your email report was good.

I think your blog post was a bit juvenile. Amusing maybe, but you're a professional and there's no need to resort to name-calling. Let the toddler's behaviour speak for itself. You don't need to laugh at them in public. It's fun though, I get it. Just gratuitous.

My recommendation to you, to turn your email report from "good" to "great", would be something like this:

------------

> Hi, I'm an independent security researcher and I publish my findings under the name "Yyyy". My primary website is yyyy.com and I've had reports published in Blah, Blah, and Blah. A quick web search will tell you more about me and my background.

> I'm writing to report an issue I noticed in toddlerceo.com. Specifically:

> (your good and complete list of specifics here, including exposure risk and high level mitigation notes if practical).

> My intent is to improve the security of the Internet, and to write about the kinds of issues I've discovered. The issue I've described here will make for an interesting and valuable article, but I don't want to publish until you've had a chance to fix the issue, so my standard procedure is to delay publication for 30 days. I'll work on the article now, and schedule it for publication on March 24th, 2025.

> Please let me know if you need any more details on the issue I've found.

----------

This may be more than they deserve! But that's OK, because you're a professional and if you are lucky enough to get a professional on the other side of the conversation, you will earn their respect, at no cost to you.

And let's be honest: your motivation for writing this article is self-promotional. You want work. Impress the CEO/security officer/etc, and you will get work, or referrals for work. So it may be more than they deserve, but it works in your interests too.

Re: 'Impossible-to-hack' security turns out to be no security

#130
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

If I read the article correctly step 6 was using data from a previous dump to access files now.

So say the dumped data contained the URL of a file and you couldn't get the URL now (due to step 3) but you can still download the actual file.

Post reply on HN