Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

171–180 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#171
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

But it also teaches security researchers to sell that info next time instead of reporting.

Seriously, if anyone from a16z is reading this, all you're doing is incentivizing the next exploit to be sold and used against you.

Re: Researcher finds flaw in a16z website that exposed some company data

#172

Earlier quoted context omitted.

Yes, if they can’t do web development what does that say about their ability to deploy capital?

If my endodontist can't rebuild a car engine, what does that say about his ability to perform a root canal? Turns out, not much.

Not a great analogy. Its more like if your endodontist hired a secretary who leaves the medical records unlocked, do you really trust them to be up to date with modern dental sensibilities when the rest of their office is ran so carelessly?

Re: Researcher finds flaw in a16z website that exposed some company data

#173
post #141

Earlier quoted context omitted.

They didn't post publicly about the vulnerability; they reached out via twitter to tell them that they had one, without giving any details about it whatsoever.

Telling everyone that there's a vulnerability is usually as bad as providing detailed steps. No one was looking, and now you've pointed them in the right direction.

[flagged]

Re: Researcher finds flaw in a16z website that exposed some company data

#174
post #154
post #48

Earlier quoted context omitted.

Using those credentials is still a violation of the he CFAA, no reasonable person would think they were invited to access the systems protected by those credentials.

Yea, I'm sure the Russian/China/NK/Iran hackers are deeply afraid of the CFAA, you got them shaking dude (and vice versa when someone in the US hacks one of their sites). The particular problem here is we think of the crime on the web in a civil/criminal manner... "People should just follow the law or be punished for a crime". This is not the internet. Regardless of what you think about the internet, it is an interna…

None of this at all applies to this thread. It’s true, but also irrelevant to this discussion being had.

Re: Researcher finds flaw in a16z website that exposed some company data

#175
post #138
post #61

Earlier quoted context omitted.

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

> not responsible disclosure. The researcher found an email address, tried it, it bounced, then reached out over Twitter with: > someone from @a16z get in touch, now. its bad. security related. https://x.com/xyz3va/status/1807330215955177937 That doesn't seem irresponsible to me. Sure they could have searched the bottom of a connect page for the office emails to try, but I don't see any significant issue with what th…

"an" email address, not the one on their contact page.

Re: Researcher finds flaw in a16z website that exposed some company data

#176

It's pretty shocking how many commenters are blaming the individual for not "trying harder" to find contact information. It's pretty clear a16z didn't want to pay anything or appreciate the disclosure at all. Finding random email addresses and sending them a notice would have gone no where other than spam folders. I get dozens of "disclosures" every week from mostly script kiddies that think my DKIM setting is someho…

I’m surprised there is almost no discussion about the severity of reputational damage caused by an extremely amateur bug not expected of a prominent VC firm

Probably because a16z reputation has already been quite tarnished in recent years. This is par for the course. People will still take their massive bags of money and name brand boost but "these are smart, technical, 'making the world a better place' visionaries" as opposed to wealth chasing bankers, has already run the gamut.

See crypto, Clubhouse, "it's time to build [not in my Atherton neighborhood]", e/acc Nick Land manifesto, Trump '24 support, etc.

Re: Researcher finds flaw in a16z website that exposed some company data

#177
post #141

Earlier quoted context omitted.

Telling everyone that there's a vulnerability is usually as bad as providing detailed steps. No one was looking, and now you've pointed them in the right direction.

what do you want them to do? nothing? we've already established that they tried to make contact.

How about - go to the company's contact page, look at the email address there, and use that?

Re: Researcher finds flaw in a16z website that exposed some company data

#178
post #61
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.

I'm generally sympathetic to what you're saying, but I also detest a16z and Horowitz personally for being the epitome of "software guy decides he's expert at everything now" and his role in the crypto bubble.

Should the hacker have tried more? Sure, maybe. Do I really care? Definitely not

Re: Researcher finds flaw in a16z website that exposed some company data

#179
post #130

Earlier quoted context omitted.

Because the next person will know there's a good chance you'll give them a cash reward, and that will tip the "immorally take all the cash" vs "return it and hope for a reward" balance more in favour of it being returned. I would have thought that was completely obvious so maybe that's not what you were asking? (On the other hand this is HN...)

The places you're most likely to get your wallet back in the world are the places you're also less likely to get a reward. The reward for returning a wallet is knowing you're doing your part to make the place you live in a nice place to live.

Doing free work for A16Z or any of the awful companies ruining our world is not helping make anything better.

Re: Researcher finds flaw in a16z website that exposed some company data

#180

I made a similar mistake actually. We used a nodejs cms called apostrophecms that had an admin panel called global settings. We used that for managing api keys to our auth server. We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it. Annoyingly we paid a reasonable amount of mon…

I think I'd be looking for at least a refund on that pen test. I've never come across one that was anymore than a box ticking exercise.
Post reply on HN