Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

211–220 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#211
post #166

Earlier quoted context omitted.

Yes, the answer must be additional processes and procedures. That way, you’ll never make a mistake! /s Also bizarre to frame this as “unacceptable behavior”, as if whoever is involved was in some way aware of their mistake and/or would say “this is acceptable behavior!” when confronted with it or something.

GP framed leaking all your keys at something that happens when you are tired or distracted. This is unacceptable behaviour for a professional in my eyes.

Humans are gonna human, if you have an environment where you fail to account for this, this will happen. Reminds me of a dev dropping a production database, or the aws engineer who incorrectly entered a command and brought down s3: many things have gone wrong to even be at this point, blaming a human for behaving like a human in an inhospitable environment is silly. Effort is almost always better spent building a system which is safer to operate for the people involved.

Re: Researcher finds flaw in a16z website that exposed some company data

#212
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

Do it enough times and you’ll be known for not paying any bounties, which makes people less likely to report issues they find.

Re: Researcher finds flaw in a16z website that exposed some company data

#214

Earlier quoted context omitted.

>Implying the Eu will actually do anything at all whatsoever upon reporting a gdpr issue >Money is something VCs “print” and manipulate. You wot m8

It is the member state authority, although EU GDPR is a Directive, is up to the member state. It doesn’t just apply to the EU, it can be UK ICO.

I have literally seen EU institutions fragrantly break GDPR

Re: Researcher finds flaw in a16z website that exposed some company data

#215
post #64

The fact that this VC firm didn't provide bug bounty for such a gaping hole does not instill trust.

Unsurprising given that the founders are Trumpists now: https://siliconangle.com/2024/07/17/co-founders-andreessen-h...

Billionaires like tax cuts for billionaires; go figure.

Re: Researcher finds flaw in a16z website that exposed some company data

#216
> i publicly reached out

Means what exactly? What information did your public reach-out include?

EDIT:

Ah, I think it's a tweet that said:

> someone from @a16z get in touch, now. its bad. security related.

Lol, ok. I guess they don't want anyone to know they had a security vuln. I wonder if they make you sign an NDA too when you get the bounty.

Re: Researcher finds flaw in a16z website that exposed some company data

#217
post #215

Earlier quoted context omitted.

Unsurprising given that the founders are Trumpists now: https://siliconangle.com/2024/07/17/co-founders-andreessen-h...

Billionaires like tax cuts for billionaires; go figure.

According to the article, the decision to back him was due to the 2025 tax plan to tax unrealized gains, which I hadn't heard of, but I'm not surprised that he wouldn't be a fan of that, given that his entire business is built on investing in companies, and that these investments on the part of founders and investors are unrealized. It does seem like it would de-incentivize much of the startup and venture capital economy.

Re: Researcher finds flaw in a16z website that exposed some company data

#218

Earlier quoted context omitted.

GP framed leaking all your keys at something that happens when you are tired or distracted. This is unacceptable behaviour for a professional in my eyes.

Humans are gonna human, if you have an environment where you fail to account for this, this will happen. Reminds me of a dev dropping a production database, or the aws engineer who incorrectly entered a command and brought down s3: many things have gone wrong to even be at this point, blaming a human for behaving like a human in an inhospitable environment is silly. Effort is almost always better spent building a sys…

That’s why I recommend in my original comment as well: get a better process.

The person I replied to understood it as “piling on more and more agile bs” but IMO that was just bad faith so I ignored it.

You need both - processes that are lightweight but solid where it matters - operators who give a shit

Re: Researcher finds flaw in a16z website that exposed some company data

#219
post #130

Earlier quoted context omitted.

The places you're most likely to get your wallet back in the world are the places you're also less likely to get a reward. The reward for returning a wallet is knowing you're doing your part to make the place you live in a nice place to live.

Doing free work for A16Z or any of the awful companies ruining our world is not helping make anything better.

I think A16Z and the companies they’ve funded have done a great deal of good for the world. The very web browser you’re typed your angry comment into is a technology pioneered by one of its two founders.

Being anti-VC is essential being against technological and economic progress.

Re: Researcher finds flaw in a16z website that exposed some company data

#220
post #135
post #31

Earlier quoted context omitted.

Counterpoint: OP is a security researcher and couldn’t find a single human email address at one of the most well-known VC firms on the planet? LinkedIn? Twitter? Facebook friends? Come on. They’re not hard to reach if one really wants to. (Note: I still think A16Z should have paid them.)

They said they got in contact via Twitter, but a16z didn’t like that.

The issue wasn’t using Twitter. It was publicly broadcasting the existence of a security vulnerability.

This is especially egregious given that A16Z’s DMs are open.

Post reply on HN