If you could actually access their Salesforce instance, that would be very nerve wracking for founders, since usually Salesforce, etc, logs emails which may continue unannounced fundraising plans or M&A plans that haven’t been shared externally by portfolio company founders.
Collecting the keys from a public source-code of a web page is legal (and can be safely reported). Using these keys to access unauthorized systems is a crime. This is a major difference.
Researcher finds flaw in a16z website that exposed some company data
181–190 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#182Earlier quoted context omitted.
The next time someone finds their keys, they're going to find this article and commit them to a public github repo instead...
You don't want to push secrets in their raw form on GitHub, secret scanning would disable keys from supported providers.
Re: Researcher finds flaw in a16z website that exposed some company data
#183Earlier quoted context omitted.
A researcher should not have to “try different emails”. Period. There should be a clearly disclosed email provided by the company to report such issues. Very obviously plastered. Or just use the standard abuse@, security@, infosec@, etc. It is by far in the company’s best interests for this to happen because the alternative is public disclosure or disclosure to black hats instead. Anything more is jumping through hoo…
Yes of course company's should do that, but in the real world a lot of companies don't think to do that, especially a marketing site for a VC firm. Any dev knows what it's like having a million responsibilities, a lot of things get put on TODO lists that never get completed. Them being owned by a wealthy company doesnt mean they have a huge dev team running 247 to handle this stuff. Which is probably why such a obvio…
> Security researchers get high and mighty extremely quickly, which is immature IMO.
Immature would have been not trying to responsibly disclose this, or disclosing the hole before it was patched.
Re: Researcher finds flaw in a16z website that exposed some company data
#184Sincere question: how do you actually make this mistake while having the skills to build a web app of this complexity level? All the frontend and full stack frameworks that I’m familiar with try pretty hard to stop you.
> how do you actually make this mistake while having the skills to build a web app of this complexity level? By not building this yourself and instead outsourcing the work to India, to people that work for 4.00$/h And I'm not blaming the person that has to work for this little cash for delivering shoddy work like this.
Re: Researcher finds flaw in a16z website that exposed some company data
#185Stuff like this is what gives the entire security and white hat community a bad name. 1. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you. 2. If the company doesn't have a published bug bounty program, they don't owe yo…
> If you are actively breaking into websites They viewed the source code. Despite what the governor of Missouri[1] thinks, that's not hacking. [1]: https://www.theverge.com/2021/12/31/22861188/missouri-govern...
No.
"i like to do this thing where i search twitter, looking for companies, and then try giving them a quick pentest"
"the compromised list of services: their database (containing PII), their AWS, their salesforce (never checked, account may be limited), mailgun (arbitrary emails from a16z domains, and also could read older emails) ... and probably more"
By their own admission, this is a "pentest", and they were able to access a16z's "database" and ascertain that it contains PII. Amongst other services used by a16z.
I'm not the one to judge whether they crossed any legal (or moral) lines though.
Re: Researcher finds flaw in a16z website that exposed some company data
#186Earlier quoted context omitted.
Why should it be an onus on the researcher to find this information? It should be plainly provided in the first place. Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.
I don't think the onus should be on the researcher, and I think A16Z should have paid them. But if they actually wanted to get in touch, I'm just saying they could have. If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional. You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to sec…
They did. They emailed, and when that was bounced, they used a different medium to reach out. Twitter is a place that many companies actively engage with the public.
> The job is complete when you get in touch.
They got in touch. If A16Z aren't going to respond to people via email, but they do on twitter, they don't get to decide that twitter isn't a viable communication platform.
Re: Researcher finds flaw in a16z website that exposed some company data
#187Re: Researcher finds flaw in a16z website that exposed some company data
#188Earlier quoted context omitted.
> not responsible disclosure. The researcher found an email address, tried it, it bounced, then reached out over Twitter with: > someone from @a16z get in touch, now. its bad. security related. https://x.com/xyz3va/status/1807330215955177937 That doesn't seem irresponsible to me. Sure they could have searched the bottom of a connect page for the office emails to try, but I don't see any significant issue with what th…
"an" email address, not the one on their contact page.
Re: Researcher finds flaw in a16z website that exposed some company data
#189Earlier quoted context omitted.
Yea, I'm sure the Russian/China/NK/Iran hackers are deeply afraid of the CFAA, you got them shaking dude (and vice versa when someone in the US hacks one of their sites). The particular problem here is we think of the crime on the web in a civil/criminal manner... "People should just follow the law or be punished for a crime". This is not the internet. Regardless of what you think about the internet, it is an interna…
None of this at all applies to this thread. It’s true, but also irrelevant to this discussion being had.
Do you cultivate vines with fruit, or do you cultivate brambles and eat thorns?
Remember white hats don't need to exist. Black hats will exist by the very nature they are parasitic and thrive where exploits exist. We can either have a community that warns you that "Hey, the stuff on your porch is going to get stolen" or we can have a community that calls their buddy when they see some stuff fresh for the taking.
A huge portion these discussions under this article are people arguing the minutia of a puddle in the lawn while a 10 meter high tsunami is rushing their way.
Re: Researcher finds flaw in a16z website that exposed some company data
#190Earlier quoted context omitted.
It only takes a single mistake. A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.
Perhaps some processes should be put into place to make exposing the entire company into a multi-step failure?