Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

161–170 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#161
post #49
post #25

If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

Collecting the keys from a public source-code of a web page is legal (and can be safely reported). Using these keys to access unauthorized systems is a crime. This is a major difference.

Parent comment never suggested it was legal. They said it would be bad if this info was in their SalesForce and they leaked the key, which they did.

Re: Researcher finds flaw in a16z website that exposed some company data

#163
post #27

[flagged]

Having a curious look is alright but it's the "beg bounty" attitude that these researchers need to rein in. It's like the sponge-and-bucket guy washing your grimy windscreen without you asking while you wait at the lights, then demanding cash for it. Thanks but no thanks.

Re: Researcher finds flaw in a16z website that exposed some company data

#164
post #3

>a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because: > there was no available contact on their main site > the email i could find engineering@a16z.com bounced my emails The age-old practice of screwing over security researchers over any possible technicality is still alive and well. Brings tears…

Any legal basis to challenge this practice ? If a company claims that they pay bug bounties but use flimsy reasons like this to chicken out of seemingly genuine cases like these

I'm guessing no, and even if their was they could make the litigation costs very high.

The sad thing here is what has to happen is the data needs sold off to blackhats to the point that entire countries get pissed and start putting near draconian level regulations and fines against companies like this to get them to stop this insecure bullshit.

Re: Researcher finds flaw in a16z website that exposed some company data

#165
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

All sorts of cleverness going on there. I'll bet they saved a ton of money on development by lowballing people on fiverr or whatever they did, and indirectly they'll also save a ton on bookkeeping when a russian ransomware group effortlessly takes them for everything they have.

Even more bookkeeping will be saved with lost business opportunities.

Re: Researcher finds flaw in a16z website that exposed some company data

#166

Earlier quoted context omitted.

It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.

Whoops I accidentally exposed all API keys ever to the public. No really this is unacceptable for a professional, it’s even bad for an amateur. If your processes are so insecure that a little tired breaks your whole company you done goofed.

Yes, the answer must be additional processes and procedures. That way, you’ll never make a mistake! /s

Also bizarre to frame this as “unacceptable behavior”, as if whoever is involved was in some way aware of their mistake and/or would say “this is acceptable behavior!” when confronted with it or something.

Re: Researcher finds flaw in a16z website that exposed some company data

#168
post #27

[flagged]

>I remember there was an article "the six dumbest ideas in computer security" on HN a while ago, one of those was the mindset that "hacking is cool". I'm reminded a bit of this here.

Half of that post is unhinged nonsense. "Hacking is Cool" is listed right after a rant about pentesting being dumb because your software should just be designed to be secure.

Re: Researcher finds flaw in a16z website that exposed some company data

#169
post #133

Earlier quoted context omitted.

Alright then: you go to Andreessen Horowitz's website[1] and see if you can find a SINGLE email address in any of the normal places a business would list the (not-social-media) contact information. Because they did their damnedest to make sure you won't find any. [1] https://a16z.com/

I already linked to them in my comment below Click nav click “how to connect with us” -> https://a16z.com/connect/ See 4 emails at the bottom for each office See 4 links to social media pages where every single one has DMs open Wait at least a couple business days to see if anyone replies, if no one does or it’s not being taken seriously then you can announce it publicly on social media you found something but can’t…

Emailing an office manager with a company security issue would be incredibly irresponsible. They're in charge of managing the physical office and are about as "outside" as you can get in a company while still being employed by that company.

Re: Researcher finds flaw in a16z website that exposed some company data

#170

Earlier quoted context omitted.

This what you expect from VCs. I always prefer to report these incidents to GDPR authorities if user data is leaked. Then they pay the fines and some get a criminal record. Money is something VCs “print” and manipulate.

>Implying the Eu will actually do anything at all whatsoever upon reporting a gdpr issue >Money is something VCs “print” and manipulate. You wot m8

It is the member state authority, although EU GDPR is a Directive, is up to the member state. It doesn’t just apply to the EU, it can be UK ICO.
Post reply on HN