Live data from Hacker News

Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

alexschapiro.com

151–160 of 301 posts

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#151
post #38
post #35

Earlier quoted context omitted.

Not every organization prioritizes being able to ship a code change at the drop of a hat. This often requires organizational dedication to heavy automated testing a CI, which small companies often aren't set up to do.

I can't believe that any company takes a month to ship something. Even if they don't have CI, surely they'd prefer to break the app (maybe even completely) than risk all their legal documents exfiltrated.

I can only say you havent worked anywhere i have.

I remember heartbleed dropping shortly after a deployment and not being allowed to patch for like ten months because the fix wasn't "validated". This was despite insurers stating this issue could cost coverage and legal getting involved.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#152
post #150

They took a month to fix this? That’s beyond inexcusable. I can’t imagine how any customer could justify working with them going forward. Also … shows you what a SOC 2 audit is worth: https://www.filevine.com/news/filevine-proves-industry-leade... Even the most basic pentest would have caught this.

It looks like SOC 2 (and the other SOCs) where developed by accountants?

I wouldn't expect them to find any computer problems either to be honest.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#153

The bigwigs at my company want to build out a document management suite. After talking to VP of technology about requirements I ask about security as well as what the regulatory requirements are and all I get is a blank stare. I used to think developers had to be supremely incompetent to end up with vulnerabilities like this. But now I understand it’s not the developers who are incompetent…

There's enough incompetence at all levels to go around.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#154
post #150

They took a month to fix this? That’s beyond inexcusable. I can’t imagine how any customer could justify working with them going forward. Also … shows you what a SOC 2 audit is worth: https://www.filevine.com/news/filevine-proves-industry-leade... Even the most basic pentest would have caught this.

Where did it say that they took a month to fix? The hacker just checked in 2 weeks later and it was fixed by that point.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#155
post #38

Earlier quoted context omitted.

I can't believe that any company takes a month to ship something. Even if they don't have CI, surely they'd prefer to break the app (maybe even completely) than risk all their legal documents exfiltrated.

I can only say you havent worked anywhere i have. I remember heartbleed dropping shortly after a deployment and not being allowed to patch for like ten months because the fix wasn't "validated". This was despite insurers stating this issue could cost coverage and legal getting involved.

What? That's crazy, wow!

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#156
post #91

Earlier quoted context omitted.

Oh man this is so true. In this sort of org, getting something fixed out-of-band takes a huge political effort (even a critical issue like having your client database exposed to the world).

While there were numerous problems with the big corporate structures I worked in decades ago where everything was done by silos of specialists, there were huge advantages. No matter where there was a security, performance, network, hardware, etc. issue, the internal support infrastructure had the specialist’s pagers and for a problem like this, the people fixing it would have been on a conference call until it was fi…

Interesting. Wouldn't the performance department have their fingers in all the pies anyway, too, or how was that handled?

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#157

Earlier quoted context omitted.

A lot of the time it’s less “nobody checked the security inbox” and more “the one person who understands that part of the system is juggling twelve other fires.” Security fixes are often a one-hour patch wrapped in two weeks of internal routing, approvals, and “who even owns this code?” archaeology. Holiday schedules and spam filters don’t help, but organizational entropy is usually the real culprit.

It could also be someone "practicing good time management." They have a specific time of day, when they check their email, and they only give 30 minutes to that time, and they check emails from most recent, down. The email comes in, two hours earlier, and, by the time they check their email, it's been buried under 50 spams, and near-spams; each of which needs to be checked, so they run out of 30 minutes, before they…

The system would be mostly sane, if you could sort by some measure of importance, not just recency.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#159
post #150

They took a month to fix this? That’s beyond inexcusable. I can’t imagine how any customer could justify working with them going forward. Also … shows you what a SOC 2 audit is worth: https://www.filevine.com/news/filevine-proves-industry-leade... Even the most basic pentest would have caught this.

Unless im missing something, they replied stating they would look into it and then its totally vague when they patched, with Alex apparently randomly testing later and telling them in a "follow up" that it was fixed.

I dont at all get why there is a paragraph thanking their communication if that is the case.

Re: Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files

#160
post #150

They took a month to fix this? That’s beyond inexcusable. I can’t imagine how any customer could justify working with them going forward. Also … shows you what a SOC 2 audit is worth: https://www.filevine.com/news/filevine-proves-industry-leade... Even the most basic pentest would have caught this.

Soc2 and most other certifications are akin to the tsa, security theater. After seeing the info sec security space from the inside i can only say that it blows my mind how abhorrent the security space is. Prod db creds in code? A ok. Not using some stupid vendors “pen testing” software on each mr, blasphemy?
Post reply on HN