Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

131–140 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#131

Earlier quoted context omitted.

Your other comments across the larger topic refute your claimed good intentions. It's not that wild that no one would believe you, when you contradict yourself.

My thoughts on the matter may have evolved over time while interacting with other people in the thread. While I do still believe it could have been an attempt at blackmail, I think it most likely was not, even though the researcher clearly must have downloaded the entire database ahead of time based on the chronology presented. In that case, I can see how I have apparently contradicted myself. But I can assure you, I…

I never thought you were acting in bad faith. My assumption was that you were gaslit like every other non-security person has been, where you were willing to shoot the messenger (the researcher) instead of the person creating the problem (the CEO). My problem wasn't that you were lied to, my only problem was that you were repeating a common lie that I think needs to die.

People operating in bad faith give up or hide when they notice their position is weakening, people working in good faith respond, and acknowledge the weaknesses in their ideas. Like you are doing.

Re: 'Impossible-to-hack' security turns out to be no security

#132

Earlier quoted context omitted.

Like I said, it was "good", and better than most. But as the reader of lots of these emails, I'm always happier to hear from someone who is able to establish their credibility and intentions with public evidence from the beginning of the conversation. I'd like to know that I'm dealing with a professional, who takes their work seriously. And I'd like to know if I'm going to be dealing with fallout from next month's fe…

> establish their credibility > I'd like to know that I'm dealing with a professional, who takes their work seriously As a sender of these emails, my credibility is established when you go to the location I say there's sensitive data being leaked, and you find sensitive data being leaked. Nothing else should matter. Are you just going to keep data exposed publicly if, for example, some curious kid notified you instea…

No, your "correctness" is established. The credibility of your report is established.

But your credibility as a professional non-extortionist is absolutely still in question, unfortunately.

Again, I've been on both sides. Being the only professional in the room is sometimes the way things work out. But that's OK, because you can walk away from the conversation still being the professional, and they cannot. This pays dividends.

I've run across people years later who apologized for being a jerk in our previous exchange. They were under pressure, didn't fully understand, felt insecure, blah blah whatever who cares. But they realized their error and got smarter for it. And I gained their respect. That doesn't work if you don't stay professional.

Re: 'Impossible-to-hack' security turns out to be no security

#133

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Concur. Tone comes off as "toxic manboy". Not sure why the author chose that tone. I would not hire them for their security services just yet, no matter how big a genius they are. Maybe once they understand the world is made of people, not rational actors.

Re: 'Impossible-to-hack' security turns out to be no security

#134

Usually like reading such posts but the author’s approach did seem very blackmail-like. The CEO is surely coming off as a crazy guy but the author isn’t a white knight or good Samaritan either. The company closed the database access and the guy says “now I will disclose it or you can do X” Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expe…

> Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expecting?

A bog-standard responsible disclosure that any tech CEO should either be familiar with or have someone at hand that is, as is clearly communicated in that e-mail.

Both e-mails are OP reaching out to help this company out, the first fixing the vulnerability, the second giving them a chance for compliance / potential regulatory aspects they might want to follow. It's not on random people reporting security vulnerabilities to tutor random companies on this and both behaviors (non-responsiveness, then hostility) of this CEO, despite being sadly common, are actively harmful if you want to get productive security reports in the future. (And the company unilaterally signing up for bug bounty programs is rather irrelevant for independent researchers as well if they have no interest in participating in those.)

Re: 'Impossible-to-hack' security turns out to be no security

#135

Earlier quoted context omitted.

> establish their credibility > I'd like to know that I'm dealing with a professional, who takes their work seriously As a sender of these emails, my credibility is established when you go to the location I say there's sensitive data being leaked, and you find sensitive data being leaked. Nothing else should matter. Are you just going to keep data exposed publicly if, for example, some curious kid notified you instea…

No, your "correctness" is established. The credibility of your report is established. But your credibility as a professional non-extortionist is absolutely still in question, unfortunately. Again, I've been on both sides. Being the only professional in the room is sometimes the way things work out. But that's OK, because you can walk away from the conversation still being the professional , and they cannot. This pays…

If I'm asked to be more professional or to prove my credibility to someone leaking the data of their customers, I just laugh. I owe nothing to the company being negligent. A notification email with all the pertinent details is what you get.

If a company isn't going to act on it after confirming my "correctness" just because they want me to show them my diploma and resume, that says a lot more about the company than it does me.

But don't fret, as I said the number of companies that forced me to jump through hoops to report a security issue, or threatened me after reporting one, has made it so I don't often bother anymore. Hopefully someone with a more professional tone emails instead, before the data gets sucked up by Lazarus Group or whoever.

Re: 'Impossible-to-hack' security turns out to be no security

#136

Usually like reading such posts but the author’s approach did seem very blackmail-like. The CEO is surely coming off as a crazy guy but the author isn’t a white knight or good Samaritan either. The company closed the database access and the guy says “now I will disclose it or you can do X” Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expe…

I just got offered to discuss a "token of appreciation" by another company that included deleting public posts and signing NDAs. I replied saying I don't accept bribes. If that's clear enough for you.

And I didn't say "I will disclose it or you can do X". I asked follow up questions as I always do. Related to intent on notifications to regulators or clients so I can delay my report until the company does their notifications if that is their intent. I've done this multiple times for multiple companies, some I delayed the post for 3-4 months.

I was actually trying to be nice to the company by not doing a disclosure before them, up until this point this was just like every other interaction I have. I sent the information, the server got closed and no one got back to me. None of my communications warranted the reply I got back from this.

Re: 'Impossible-to-hack' security turns out to be no security

#138

Earlier quoted context omitted.

It's not my place to define your ethics for you. I'm pointing out so any other readers can be innoculated from accidentally stumbling into this ethical minefield. I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing. No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.

I'm a participant in sub-criminal negligence rather than stealing. I'd call that a lesser offense. And it's a failure I have mitigated by working to protect the data. I can't claim innocence, but I sleep OK.

As your attorney I would not advise admitting that on a public website. Even posting it implicates this website in the risk registry.

Re: 'Impossible-to-hack' security turns out to be no security

#139

Earlier quoted context omitted.

I thoroughly enjoyed the post and thought your tone was appropriate, entertaining, and kind of kethartic. You didn't call them names, engage in ad hominem, or do anything click-batey. You were understandably irritated at how they talked to you and how they were clearly trying to hide a massive exposure from their users. And then you shredded them with data. A+ - And thanks for trying to keep folks like this honest!

> You didn't call them names, engage in ad hominem Well, the author wrote: > Teammate App CEO, Sean Banayan, who has the reading comprehension and IT knowledge of a toddler So it wasn't very nice, but deserved imo.

Fair - maybe there was a little name calling. But, I agree it was deserved.

Re: 'Impossible-to-hack' security turns out to be no security

#140

Earlier quoted context omitted.

I'm a participant in sub-criminal negligence rather than stealing. I'd call that a lesser offense. And it's a failure I have mitigated by working to protect the data. I can't claim innocence, but I sleep OK.

As your attorney I would not advise admitting that on a public website. Even posting it implicates this website in the risk registry.

[deleted]
Post reply on HN