Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

151–160 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#154
post #48

Earlier quoted context omitted.

If you put all your stuff on your front porch with a sign “please take what you want” and it’s all gone the next day - then you can’t say you were robbed. I think this is a more apt analogy to what az16 did here

Using those credentials is still a violation of the he CFAA, no reasonable person would think they were invited to access the systems protected by those credentials.

Yea, I'm sure the Russian/China/NK/Iran hackers are deeply afraid of the CFAA, you got them shaking dude (and vice versa when someone in the US hacks one of their sites).

The particular problem here is we think of the crime on the web in a civil/criminal manner... "People should just follow the law or be punished for a crime". This is not the internet. Regardless of what you think about the internet, it is an international war zone. If you leave the hatch of a tank open and a drone blows it up, that was you being stupid. If you leave an ammunition truck unguarded and the enemy takes it, again, that is you being stupid.

History will look back and say WWIII started on the web, but as of now it seems a huge number of people are in denial about it.

Re: Researcher finds flaw in a16z website that exposed some company data

#155

Earlier quoted context omitted.

> I too, as the good samaritan that I am, like to stroll through my neighborhood and give all the cars and bikes I encounter a quick pentest, purely for the benefits of the owners of course. In my neighborhood, "security researchers" can often be seen checking houses for vulnerabilities. During the day, it's usually a woman or a kid with a clipboard who knocks on front doors, checks for cameras, tests if the front do…

"These times" have been around since house doors had locks.

Whoosh

Re: Researcher finds flaw in a16z website that exposed some company data

#156
post #10

they are busy writing a giant "architecture of generative AI" whitepaper. give them a pause, they are dreaming a future agentic world of half-assed chatbots. while the world burns with botched software updates.

> engineering@a16z.com bounced my emails

No surprise there.

Re: Researcher finds flaw in a16z website that exposed some company data

#157
post #65
post #51

Earlier quoted context omitted.

Exactly, if he even just browsed their website a bit he'd have stumbled across loads of email addresses that could have been a useful point of contact.

It’s more fun getting attention by doing it publicly and being the victim (security researchers love hitting the 'nobody respects us' button) than putting basic effort in. A single email bouncing is frustrating of course, but he then posted that an easily found vulnerability existed on Twitter, while a16z: - has a contact page page https://a16z.com/connect/ with 4x emails to their offices at the bottom (despite claim…

[flagged]

Re: Researcher finds flaw in a16z website that exposed some company data

#158

The HN mods changed the title to a less embarrassing one. Not surprised

Oh, my comment must have been too critical of a16z as well. I see it has been moved from top to way bottom without a score change.

That's certainly one way to offer a response!

Re: Researcher finds flaw in a16z website that exposed some company data

#159
post #7

when companies say they are “hacked”, it’s now a corporate term for “we were negligent in securing important credentials, but please shift blame to this no-name entity we called a ‘hacker’”

If you accidentally leave your front door wide open and somebody steals all your stuff, you'll also say that you were robbed. There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed…

Good analogy, from a personal perspective.

In this case, a person was yelling through the front door "Your door is wide open!" and no-one was listening.

For a 42B AUM company, at a time where running an IT operation means "use CrowdStrike so that you pass audits", leaving the front door open all night should get you fired, regardless of whether you blame hackers or not.

Re: Researcher finds flaw in a16z website that exposed some company data

#160
post #49
post #25

If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

Collecting the keys from a public source-code of a web page is legal (and can be safely reported). Using these keys to access unauthorized systems is a crime. This is a major difference.

Oh no CRIME! Thank goodness that something being a crime stops people from committing them.

Thank goodness the internet isn't an international operation filled with nation state level actors and questionable companies running data gathering operations from places they cannot be touched.

Always assume your data has been stolen by an assailant in a place that's only reachable by launching nukes at them. Also assume there is some competitor on the other side of the world now using your data against you.

Please stop treating data theft like Barney Fife level candy store theft. A huge portion of the time even if you know the name of the exact person who did it, there isn't going to be shit you can do about it.

Post reply on HN