Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

181–190 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#181
post #49
post #25

If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.

Collecting the keys from a public source-code of a web page is legal (and can be safely reported). Using these keys to access unauthorized systems is a crime. This is a major difference.

How can it possibly be a crime? They literally gave the keys to everyone who accessed their website

Re: Researcher finds flaw in a16z website that exposed some company data

#182
post #30

Earlier quoted context omitted.

The next time someone finds their keys, they're going to find this article and commit them to a public github repo instead...

You don't want to push secrets in their raw form on GitHub, secret scanning would disable keys from supported providers.

that's the point

Re: Researcher finds flaw in a16z website that exposed some company data

#183
post #111

Earlier quoted context omitted.

A researcher should not have to “try different emails”. Period. There should be a clearly disclosed email provided by the company to report such issues. Very obviously plastered. Or just use the standard abuse@, security@, infosec@, etc. It is by far in the company’s best interests for this to happen because the alternative is public disclosure or disclosure to black hats instead. Anything more is jumping through hoo…

Yes of course company's should do that, but in the real world a lot of companies don't think to do that, especially a marketing site for a VC firm. Any dev knows what it's like having a million responsibilities, a lot of things get put on TODO lists that never get completed. Them being owned by a wealthy company doesnt mean they have a huge dev team running 247 to handle this stuff. Which is probably why such a obvio…

The security researcher in this case worked for free to find a hole in their security, reached out via a provided email address, had that bounce, so then chose to reach out via a different messaging system to let them know that there was an issue. ALL OF THIS WAS UNPAID. They have 0 or less responsibility to this firm. The researcher was doing them a huge favor.

> Security researchers get high and mighty extremely quickly, which is immature IMO.

Immature would have been not trying to responsibly disclose this, or disclosing the hole before it was patched.

Re: Researcher finds flaw in a16z website that exposed some company data

#184
post #9

Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.

> how do you actually make this mistake while having the skills to build a web app of this complexity level? By not building this yourself and instead outsourcing the work to India, to people that work for 4.00$/h And I'm not blaming the person that has to work for this little cash for delivering shoddy work like this.

[dead]

Re: Researcher finds flaw in a16z website that exposed some company data

#185
post #104

Stuff like this is what gives the entire security and white hat community a bad name. 1. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you. 2. If the company doesn't have a published bug bounty program, they don't owe yo…

> If you are actively breaking into websites They viewed the source code. Despite what the governor of Missouri[1] thinks, that's not hacking. [1]: https://www.theverge.com/2021/12/31/22861188/missouri-govern...

> They viewed the source code.

No.

"i like to do this thing where i search twitter, looking for companies, and then try giving them a quick pentest"

"the compromised list of services: their database (containing PII), their AWS, their salesforce (never checked, account may be limited), mailgun (arbitrary emails from a16z domains, and also could read older emails) ... and probably more"

By their own admission, this is a "pentest", and they were able to access a16z's "database" and ascertain that it contains PII. Amongst other services used by a16z.

I'm not the one to judge whether they crossed any legal (or moral) lines though.

Re: Researcher finds flaw in a16z website that exposed some company data

#186
post #94

Earlier quoted context omitted.

Why should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.

I don't think the onus should be on the researcher, and I think A16Z should have paid them. But if they actually wanted to get in touch, I'm just saying they could have. If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional. You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to sec…

> If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional.

They did. They emailed, and when that was bounced, they used a different medium to reach out. Twitter is a place that many companies actively engage with the public.

> The job is complete when you get in touch.

They got in touch. If A16Z aren't going to respond to people via email, but they do on twitter, they don't get to decide that twitter isn't a viable communication platform.

Re: Researcher finds flaw in a16z website that exposed some company data

#188
post #175
post #138

Earlier quoted context omitted.

> not responsible disclosure. The researcher found an email address, tried it, it bounced, then reached out over Twitter with: > someone from @a16z get in touch, now. its bad. security related. https://x.com/xyz3va/status/1807330215955177937 That doesn't seem irresponsible to me. Sure they could have searched the bottom of a connect page for the office emails to try, but I don't see any significant issue with what th…

"an" email address, not the one on their contact page.

The email the researcher found (engineering) seems more appropriate than the office info emails (menlopark-info, ...) at the bottom of the Connect page (an actual "contact" page used to exist, but is now 404 with no redirect). I don't see anything irresponsible about trying engineering then reaching out over social media.

Re: Researcher finds flaw in a16z website that exposed some company data

#189
post #174
post #154

Earlier quoted context omitted.

Yea, I'm sure the Russian/China/NK/Iran hackers are deeply afraid of the CFAA, you got them shaking dude (and vice versa when someone in the US hacks one of their sites). The particular problem here is we think of the crime on the web in a civil/criminal manner... "People should just follow the law or be punished for a crime". This is not the internet. Regardless of what you think about the internet, it is an interna…

None of this at all applies to this thread. It’s true, but also irrelevant to this discussion being had.

All of this applies to this thread.

Do you cultivate vines with fruit, or do you cultivate brambles and eat thorns?

Remember white hats don't need to exist. Black hats will exist by the very nature they are parasitic and thrive where exploits exist. We can either have a community that warns you that "Hey, the stuff on your porch is going to get stolen" or we can have a community that calls their buddy when they see some stuff fresh for the taking.

A huge portion these discussions under this article are people arguing the minutia of a puddle in the lawn while a 10 meter high tsunami is rushing their way.

Re: Researcher finds flaw in a16z website that exposed some company data

#190

Earlier quoted context omitted.

It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.

Perhaps some processes should be put into place to make exposing the entire company into a multi-step failure?

I've considered tracing outgoing responses from nginx/traefik/whatever to watch for known API keys. The difficulty would be identifying the keys amongst the noise.
Post reply on HN