Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

171–180 of 466 posts

Re: I found a vulnerability. they found a lawyer

#171
post #109

[dead]

Reply: "sorry, before reaching out to you I already notified a major media organization with a 90 day release notice"

In case someone takes this as actual advice, I think this comment is best accompanied with a warning that this gets them to call a lawyer for sure ^^'

(OP mentions a lawyer in the title, but the post only speaks of a data protection officer, which is a very different role and doesn't even represent the organization's interests but, instead, the users', at least under GDPR where I'm from)

Re: I found a vulnerability. they found a lawyer

#172
post #86

This is extremely disappointing. The insurer in question has a very good reputation within the dive community for acting in good faith and for providing medical information free of charge to non-members. This sounds like a cultural mismatch with their lawyers. Which is ironic, since the lawyers in question probably thought of themselves as being risk-averse and doing everything possible to protect the organisation's…

> This sounds like a cultural mismatch with their lawyers.

Note that the post never mentions lawyers, only the title. It sounds to me like chatgpt came up with two dozen titles and OP thought this was the most dramatic one. In the post, they mention it was a data protection officer who replied. This person has the user's interests as their goal and works for the organization only insofar as that they handle GDPR-related matters, including complaints. If I'm reading it right, they're supposed to be somewhat impartial per recital 97 of the GDPR: "data protection officers [...] should be in a position to perform their duties and tasks in an independent manner"

Re: I found a vulnerability. they found a lawyer

#173

Earlier quoted context omitted.

It's kinda wild that you don't need to be a professional engineer to store PII. The GDPR and other frameworks for PII usually do have a minimum size (in # of users) before they apply, which would help hobbyists. The same could apply for the licensure requirement. But also maybe hobbyists don't have any business storing PII at scale just like they have no business building public bridges or commercial aircraft.

I'm wary of centralizing the powers of the web like that.

Web is already mostly centralized, and corporations which should be scrutinized in way they handle security, PII and overall software issues are without oversight.

It is also a matter of respect towards professionals. If civil engineer says that something is illegal/dangerous/unfeasible their word is taken into the account and not dismissed - unlike in, broadly speaking, IT.

Re: I found a vulnerability. they found a lawyer

#174
post #149
post #141

Earlier quoted context omitted.

Could you post on HN on that? Would be worth reading. And are you only talking about cybersecurity disclosure, liability, patent applications... And the scenario when you're both working for the same party, or opposing parties?

I'm talking about any situation where a principled person who is technically correct gets a threatening letter from a lawyer instead of a thank you. If you read enough lawyer messages (they show up on HN all the time) you will see they follow a pattern of looking tough, and increasingly threatening posture. But often, the laws they cite aren't applicable, and wouldn't hold up in court or public opinion.

> they follow a pattern of looking tough, and increasingly threatening posture. But often, the laws they cite aren't applicable, and wouldn't hold up in court

And it takes years to prove that and be judged as not guilty, or if guilty (as OP would likely be for dumping the database), that the punishment should be nil due to the demonstrated good faith even if it technically violated a law

Wouldn't you say the threats are to be taken seriously in cases like OP's?

Re: I found a vulnerability. they found a lawyer

#175
post #174
post #149

Earlier quoted context omitted.

I'm talking about any situation where a principled person who is technically correct gets a threatening letter from a lawyer instead of a thank you. If you read enough lawyer messages (they show up on HN all the time) you will see they follow a pattern of looking tough, and increasingly threatening posture. But often, the laws they cite aren't applicable, and wouldn't hold up in court or public opinion.

> they follow a pattern of looking tough, and increasingly threatening posture. But often, the laws they cite aren't applicable, and wouldn't hold up in court And it takes years to prove that and be judged as not guilty, or if guilty (as OP would likely be for dumping the database), that the punishment should be nil due to the demonstrated good faith even if it technically violated a law Wouldn't you say the threats…

No.

Re: I found a vulnerability. they found a lawyer

#176
post #147

Earlier quoted context omitted.

I'm curious to hear your take on the situation in the article. Based on your experience, do you think there are specific ways the author could have communicated differently to elicit a better response from the lawyers?

It would take a bit of time to re-read the entire chain and come up with highly specific ways. The way I read the exchange, the lawyer basically wants the programmer to shut up and not disclose the vulnerability, and is using threatening legal language. While the programmer sees themself as a responsible person doing the company a favor in a principled way. Some things I can see. I think the way the programmer worded…

> which the programmer did (offering a different document to sign). \n\n IIUC, at that point, the lawyer went away

The article says that the organization refused the counter-offer and doubled down instead

> he should have talked to his own lawyer for advice

Costing how much? Next I'll need a lawyer for telling the supermarket that their alarm system code was being overlooked by someone from the bushes

It's not bad legal advice and I won't discourage anyone from talking to a lawyer, but it makes things way more costly than they need be. There's a thousand cases like this already online to be found if you want to know how to handle this type of response

Sounds very usa-esque (or perhaps unusually wealthy) to retain a lawyer as "sounding board"

Re: I found a vulnerability. they found a lawyer

#177

I suspect that the direction of these situations often depends on how your initial email is routed internally in these organizations. If they go to a lawyer first, you will get someone who tries to fix things with the application of the law. If it goes to an engineer first, you will get someone who tries to fix it with an application of engineering. If it were me, I would have avoided involving third party regulators…

> If it were me, I would have avoided involving third party regulators in the initial contact at least.

I'm surprised to see this take only mentioned once in this thread. I think people here are not aware of the sheer amount of fraud in the "bug bounty" space. As soon as you have a public product you get at least 1 of these attempts per week of someone trying to shake you down for a disclosure that they'll disclose after you pay them something. Typically you just report them as spam and move on.

But if I got one that had some credible evidence of them reporting me to a government agency already, I'd immediately get a lawyer to send a cease and desist.

It seems like OP was trying to be a by the book law abiding citizen, but the sheer amount of fraud in this space makes it really hard to tell the difference from a cold email.

Re: I found a vulnerability. they found a lawyer

#178

There should exist a vulnerability disclosure intermediary. They can function as a barrier to protect the scientist/researcher/enthousiast and do everything by the book for the different countries.

National CERTs usually take up this role. I presume OP could have anonymously disclosed to the Maltese CERT, whom they already CC'd, though you'd have to check with them specifically to see if they offer that. Hackerspaces also often do this, especially if you're a member but probably also if not and they have faith that your actions were legal (best case, you can demonstrate exactly what you did, like by showing the script you ran, as OP could)

Re: I found a vulnerability. they found a lawyer

#179
post #101

There should exist a vulnerability disclosure intermediary. They can function as a barrier to protect the scientist/researcher/enthousiast and do everything by the book for the different countries.

Who compensates them for the risk?

What risk? It sounds to me like the worst they could get is a subpoena to produce the identity of the reporter

Besides, it's usually governmental organizations that do this sort of thing

Re: I found a vulnerability. they found a lawyer

#180

> No ..., no ..., no .... Just ... Am I the only one who can't stand this AI slop pattern?

It's one thing for your blog post to be full of faux writing style, but also that letter to the organization... oof. I wouldn't enjoy receiving that from someone who attached a script that dumps all users from my database and the email, as well as my access logs, confirm they ran it
Post reply on HN