If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.
Collecting the keys from a public source-code of a web page is legal (and can be safely reported). Using these keys to access unauthorized systems is a crime. This is a major difference.
Researcher finds flaw in a16z website that exposed some company data
161–170 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#162Re: Researcher finds flaw in a16z website that exposed some company data
#163[flagged]
Re: Researcher finds flaw in a16z website that exposed some company data
#164>a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because: > there was no available contact on their main site > the email i could find engineering@a16z.com bounced my emails The age-old practice of screwing over security researchers over any possible technicality is still alive and well. Brings tears…
Any legal basis to challenge this practice ? If a company claims that they pay bug bounties but use flimsy reasons like this to chicken out of seemingly genuine cases like these
The sad thing here is what has to happen is the data needs sold off to blackhats to the point that entire countries get pissed and start putting near draconian level regulations and fines against companies like this to get them to stop this insecure bullshit.
Re: Researcher finds flaw in a16z website that exposed some company data
#165> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…
All sorts of cleverness going on there. I'll bet they saved a ton of money on development by lowballing people on fiverr or whatever they did, and indirectly they'll also save a ton on bookkeeping when a russian ransomware group effortlessly takes them for everything they have.
Re: Researcher finds flaw in a16z website that exposed some company data
#166Earlier quoted context omitted.
It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.
Whoops I accidentally exposed all API keys ever to the public. No really this is unacceptable for a professional, it’s even bad for an amateur. If your processes are so insecure that a little tired breaks your whole company you done goofed.
Also bizarre to frame this as “unacceptable behavior”, as if whoever is involved was in some way aware of their mistake and/or would say “this is acceptable behavior!” when confronted with it or something.
Re: Researcher finds flaw in a16z website that exposed some company data
#167Re: Researcher finds flaw in a16z website that exposed some company data
#168[flagged]
Half of that post is unhinged nonsense. "Hacking is Cool" is listed right after a rant about pentesting being dumb because your software should just be designed to be secure.
Re: Researcher finds flaw in a16z website that exposed some company data
#169Earlier quoted context omitted.
Alright then: you go to Andreessen Horowitz's website[1] and see if you can find a SINGLE email address in any of the normal places a business would list the (not-social-media) contact information. Because they did their damnedest to make sure you won't find any. [1] https://a16z.com/
I already linked to them in my comment below Click nav click “how to connect with us” -> https://a16z.com/connect/ See 4 emails at the bottom for each office See 4 links to social media pages where every single one has DMs open Wait at least a couple business days to see if anyone replies, if no one does or it’s not being taken seriously then you can announce it publicly on social media you found something but can’t…
Re: Researcher finds flaw in a16z website that exposed some company data
#170Earlier quoted context omitted.
This what you expect from VCs. I always prefer to report these incidents to GDPR authorities if user data is leaked. Then they pay the fines and some get a criminal record. Money is something VCs “print” and manipulate.
>Implying the Eu will actually do anything at all whatsoever upon reporting a gdpr issue >Money is something VCs “print” and manipulate. You wot m8