> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.
I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…
Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
21–30 of 112 posts
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#22Finally the AI security startup hustlers will keep the other tech startup hustlers in line. Maybe the era of devastating leaks and total disregard for user privacy will come to an end (doubtful).
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#23Earlier quoted context omitted.
They could sell the next one to an adversary for a lot more money if they're going to act like that.
Yes, there are also many other lucrative illegal activities.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#24Let me guess though. They are SOC2 and ISO compliant right ?
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#25Would it be possible to stop using aXXb nomenclature within the titles? Some of us aren't hip enough to know what all of them mean.
Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.
Yes. I know Andreessen-Horowitz and I don’t know a16z. Reading the title i thought it will be about the cryptography serialisation specification. Turns out i was mixing it up with ASN.1.
> Their website is literally a16z.com
I hear now. Before this if pressed i would have guessed that they probably have a website indeed. If you would have twisted my arm my guess would have been andersenhorovitz.com (yup, with the typos. I learned the correct spelling today from your comment.)
> exceedingly relevant for the HN audience
We contain multitudes.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#26Earlier quoted context omitted.
Andreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.
> you'd rather say Andreessen-Horowitz, which is just as arbitrary as a16z Yes. I know Andreessen-Horowitz and I don’t know a16z. Reading the title i thought it will be about the cryptography serialisation specification. Turns out i was mixing it up with ASN.1. > Their website is literally a16z.com I hear now. Before this if pressed i would have guessed that they probably have a website indeed. If you would have twis…
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#27How do people find these vulnerabilities within the immense scope of the whole internet? Are they going around with some kind of generic API scanner that discovers APIs?
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#28Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#29The vulnerability itself appears to be something anyone with mitmproxy would have spotted within minutes of looking at the platform; apparently, rotating object IDs worked everywhere in the app, and there was no meaningful authz.
It's interesting if AI systems can "spot" these, in the sense of autonomously exercising the application and "understanding" obvious failed authz check patterns. But it's a "hm, ok, sure" kind of interesting.
Re: Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
#30Earlier quoted context omitted.
I keep getting emails with the content like: "I found a critical bypass vulnerability in your app what is the appropriate channel to disclose it, and do you have a bounty program?" I tried engaging and replying to them, and it inevitably turns into: "Yeah, we don't actually have the vulnerability, but you are totally vulnerable, just let us do a security audit for you". I have a pre-written reply for these kinds of m…
From the looks of it, they actually asked for a way to report.