Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

141–150 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#141

Earlier quoted context omitted.

No, your "correctness" is established. The credibility of your report is established. But your credibility as a professional non-extortionist is absolutely still in question, unfortunately. Again, I've been on both sides. Being the only professional in the room is sometimes the way things work out. But that's OK, because you can walk away from the conversation still being the professional , and they cannot. This pays…

If I'm asked to be more professional or to prove my credibility to someone leaking the data of their customers , I just laugh. I owe nothing to the company being negligent. A notification email with all the pertinent details is what you get. If a company isn't going to act on it after confirming my "correctness" just because they want me to show them my diploma and resume, that says a lot more about the company than…

I think we're talking past each other.

Of course you don't owe them anything. And the disclosure is a gift, unless you also use it for self-promotion, which is the usual compensation model aside from bounty programs.

But if you want to improve the ratio of reasonable-to-hostile responses, it's worth spending an extra couple minutes composing your presentation in the most digestible way. Also it's good for business.

If you're serious about helping to improve the net, or being a good netizen, you'll understand that recipients come in all shapes, and you have the best chance of achieving your goals if you make a small extra effort.

If you're at all worried that your report will evoke a hostile response, you always have the option of reporting it anonymously. I've done this, and it does work (vulnerability gets fixed).

Or if you just want to laugh at the colossal morons who don't take you as seriously as you believe you deserve, then sure whatever.

Re: 'Impossible-to-hack' security turns out to be no security

#142

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Even in a professional setting, you are not obligated to coddle aggressive stupidity. That's how we end up in a world where nobody says what they mean, everything is just BS on top of BS, and nothing improves. Being direct, being honest, and being accurate are critically important in professional technical work, and while it's not necessary to be antagonistic, it is completely reasonable and socially acceptable to respond in kind to the energy you get. People who are aggressively stupid do not get a pass.

Re: 'Impossible-to-hack' security turns out to be no security

#143

Earlier quoted context omitted.

Personally, I find the tone of the article appropriate for the response received. The first email clearly set the tone as cordial and friendly while still being urgent. The response was in a clearly adversarial tone. So the prompter adjusted their tone accordingly. It wasn't necessary to match tones with the person whom wanted to be uncharitable, but it definitely feels more human to me, which is who the writing is f…

While there's a large audience for Jerry Springer style content, verbal abuse and stooping to the level of someone you're criticizing are not required. I don't read HN for name calling or childish taunting. It is always dispiriting to read, and even more so to read people defending. Humans, as you note, have base instincts, but giving into them and catering to them should be left to X and other sites devoted to pande…

Where precisely is the "verbal abuse" and "name calling"?

Chill. I think you are the one overescalating, here.

Re: 'Impossible-to-hack' security turns out to be no security

#144
post #6

Even if a guy is an easily hackable asshole, usually accessing the stuff directly and downloading his database is still a crime (at least in the US), stay safe buddy.

Is it hacking when there is no "breach?"

If I serve a file with info I didn't intend for the world to see at example.com/secret and you access it, did you commit a crime? Clearly no.

Given that, you have no way to even know if the data which was available publicly contained any private information. This guy is doing a fine public service, and any company he helps should pay him for saving their asses.

Re: 'Impossible-to-hack' security turns out to be no security

#145
post #144
post #6

Even if a guy is an easily hackable asshole, usually accessing the stuff directly and downloading his database is still a crime (at least in the US), stay safe buddy.

Is it hacking when there is no "breach?" If I serve a file with info I didn't intend for the world to see at example.com/secret and you access it, did you commit a crime? Clearly no. Given that, you have no way to even know if the data which was available publicly contained any private information. This guy is doing a fine public service, and any company he helps should pay him for saving their asses.

You can still get dragged to court for it[1], even if you may (eventually) win, lawyers are expensive.

[1]: https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-...

Re: 'Impossible-to-hack' security turns out to be no security

#146
post #144

Earlier quoted context omitted.

Is it hacking when there is no "breach?" If I serve a file with info I didn't intend for the world to see at example.com/secret and you access it, did you commit a crime? Clearly no. Given that, you have no way to even know if the data which was available publicly contained any private information. This guy is doing a fine public service, and any company he helps should pay him for saving their asses.

You can still get dragged to court for it[1], even if you may (eventually) win, lawyers are expensive. [1]: https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-...

But he wasn't dragged to court for it.

https://missouriindependent.com/2022/02/11/prosecutor-isnt-p...

Re: 'Impossible-to-hack' security turns out to be no security

#147

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Personally, I find the tone of the article appropriate for the response received. The first email clearly set the tone as cordial and friendly while still being urgent. The response was in a clearly adversarial tone. So the prompter adjusted their tone accordingly. It wasn't necessary to match tones with the person whom wanted to be uncharitable, but it definitely feels more human to me, which is who the writing is f…

If you want all the clicks and comments and drama you can get, staying professional is just boring.

Professionalism minimizes the risk of derailing or devaluing your argument by you being rude, inappropriate, etc. and avoids aggravating your counterparty. If - as in this case - the goal is NOT Internet drama but rather an improvement in security - the best way to do that would be to remain professional.

It is a question for the author of the piece which angle they prefer - consider that keeping it cool calm and collected is the slow way to build an audience.. even if the audience it builds is more engaged.

Re: 'Impossible-to-hack' security turns out to be no security

#148
post #133

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Concur. Tone comes off as "toxic manboy". Not sure why the author chose that tone. I would not hire them for their security services just yet, no matter how big a genius they are. Maybe once they understand the world is made of people, not rational actors.

I see this kind of take every time someone exposes incompetence. I get it - you'd rather hire a marketing person to use buzzwords than someone like OP. That's your prerogative.

Re: 'Impossible-to-hack' security turns out to be no security

#149
New Zealander here, really thrilled to see our national medical testing service (primarily blood tests) in here. I've sent a note to them to make sure they're aware of this.

Also I feel like I took the wrong path, trying to be a serious and responsible software developer - seems like all the money is in throwing shit together and making wild claims about it.

Re: 'Impossible-to-hack' security turns out to be no security

#150
post #133

Earlier quoted context omitted.

Concur. Tone comes off as "toxic manboy". Not sure why the author chose that tone. I would not hire them for their security services just yet, no matter how big a genius they are. Maybe once they understand the world is made of people, not rational actors.

I see this kind of take every time someone exposes incompetence. I get it - you'd rather hire a marketing person to use buzzwords than someone like OP. That's your prerogative.

Hardly. There are simply two ways to expose incompetence. You can be nice or you can be a prick. Your choice. Seeing your handle, you may find it interesting to note that my master's degree in CS was completed at the Technion. I am not looking for marketing people or buzzwords. I am looking for people mature enough to handle other people and get the job done. For example, if you tasked a security boy genius with pushing a fix and all they ended up doing was alienating the dev team, then you are scoring an own goal. I want bright AND mature. I am picky that way.
Post reply on HN