Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

21–30 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#21

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#23
post #11

Earlier quoted context omitted.

> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?

It requires programming in a language specific to one little known db product, in an extremely brittle and spaghettified code base . There's exactly one person in the company who kinda knows how to do it, and they're unavailable for the foreseeable future on higher priorities. We don't have the money to throw at new hires or huge porting projects. Imagine software that has been in production since the 80's, was writt…

> they're unavailable for the foreseeable future on higher priorities

Need I respond to that?

Re: 'Impossible-to-hack' security turns out to be no security

#24

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.

Re: 'Impossible-to-hack' security turns out to be no security

#25

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

why is the author obligated to use a professional tone?

Re: 'Impossible-to-hack' security turns out to be no security

#26

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Personally, I find the tone of the article appropriate for the response received. The first email clearly set the tone as cordial and friendly while still being urgent. The response was in a clearly adversarial tone. So the prompter adjusted their tone accordingly.

It wasn't necessary to match tones with the person whom wanted to be uncharitable, but it definitely feels more human to me, which is who the writing is for: humans. I would have been fine with an info dump, but I enjoy turnabout as much as any other fan of fair play.

Re: 'Impossible-to-hack' security turns out to be no security

#27
post #23

Earlier quoted context omitted.

It requires programming in a language specific to one little known db product, in an extremely brittle and spaghettified code base . There's exactly one person in the company who kinda knows how to do it, and they're unavailable for the foreseeable future on higher priorities. We don't have the money to throw at new hires or huge porting projects. Imagine software that has been in production since the 80's, was writt…

> they're unavailable for the foreseeable future on higher priorities Need I respond to that?

If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.

Re: 'Impossible-to-hack' security turns out to be no security

#28
post #15

Not very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.

Agree. "You're not wrong, Walter, you're just an asshole!" Best case scenario, CEO just got an annoying distraction that was a credible enough threat they had to waste time investigating. Worst case they had a breach and someone is extorting or hacking them. Some grace on the part of the researcher is warranted IMO, despite the amateur handling by the CEO. No one looks good here.

Re: 'Impossible-to-hack' security turns out to be no security

#29

[flagged]

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables.

Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims.

Again, I never asked for anything, I even offered to delay my publication so they could notify people if that was their intent, where is the blackmail here?

Re: 'Impossible-to-hack' security turns out to be no security

#30

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

The author is more professional than the sean was, and conveys the correct amount of disgust we should all hold for this company and it's leadership.

The point of the essay was to be disrespectful of the CEO. Slightly less disrespectful than the CEO was, so IMO he still holds onto the high ground of ethics.

Please do choose team troll. The correct response to someone being a shitter, is not always to kill them with kindness. A lot of the time it is, but this time, I'm clearly on the authors side. He tried twice to be kind, was ignored and then insulted. When really he was owed a thank you, not to be disrespected.

Post reply on HN