Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

211–220 of 466 posts

Re: I found a vulnerability. they found a lawyer

#211

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

I generally agree with you, but:

> If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper

To match this metaphor to TFA, the architect has to break in to someone else's apartment to prove there's a flaw. IANAL but I'm not positive that "I'm an architect and I noticed a crack in my apartment, so I immediately broke in to the apartments of three neighbours to see if they also had cracks" would be much of a defence against a trespass/B&E charge.

Re: I found a vulnerability. they found a lawyer

#212
post #42

Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.

There is precisely one large, internationally well known company that offers dive insurance and is based in Malta.

They left more than enough clues to figure out that this is DAN (Divers Alert Network) Europe.

Ironically, this will garner far more attention and focus on them than if they had disclosed this quietly without threats.

Re: I found a vulnerability. they found a lawyer

#213

Earlier quoted context omitted.

He didn't have to crack the site. He could have reported up to that point. We need a change in law but more to do with fining security breaches or requiring certification to run a site above X number of users.

Showing up without a PoC complicates things.

I understand why the author thought that way, but showing up with private data that the company is obligated to protect complicates things quite a lot more.

I've dealt with security issues a number of times over my career, and I'm genuinely unsure what my legal obligations would be in response to an email like this. He says the company has committed "multiple GDPR violations"; is there something I need to say in response to preserve any defenses the company may have or minimize the fines? What must I do to ensure that he does eventually delete the customer data? If I work with him before the data is deleted, or engage in joint debugging that gives him the opportunity to exfiltrate additional data, is there a risk that I could be liable for failing to protect the data from him?

There's really no option when getting an email like this other than immediately escalating to your lawyers and having them handle all further communication.

Re: I found a vulnerability. they found a lawyer

#214

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

I generally agree with you, but: > If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper To match this metaphor to TFA, the architect has to break in to someone else's apartment to prove there's a flaw. IANAL but I'm not positive that "I'm an architect and I noticed a crack in my apartment, so I immediately broke in to the apartments of three neighbours to see if they…

Nah, this is more like “I put a probe camera in the crack and I ended up seeing my neighbor’s living room for a second

Re: I found a vulnerability. they found a lawyer

#215

Earlier quoted context omitted.

You'd be surprised how many SE's would love for this to happen. The biggest reason, as you said, being able to push back. Having worked in low-level embedded systems that could be considered "system critical", it's a horrible feeling knowing what's in that code and having no actual recourse other than quitting (which I have done on few occasions because I did not want to be tied to that disaster waiting to happen). I…

> You'd be surprised how many SE's would love for this to happen I'm one of them, and for exactly the reason you say. I worked as a physical engineer previously and I think the existence of PEs changes the nature of the game. I felt much more empowered to "talk back" to my boss and question them. It was natural to do that and even encouraged. If something is wrong everyone wants to know. It is worth disruption and ev…

I also come from a more "traditional engineering" background, with PEs and a heavier sense of responsibility/ethics(?). I definitely think that's where it's going, although in my somewhat biased opinion, that's why the bar for traditional engineering in terms of students and expected skill and intuition was much higher than with CS/CE, which means the get rich quick scheme nature of it might go away.

Re: I found a vulnerability. they found a lawyer

#216

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

It's illegal in the US, too. This is an incredibly stupid thing to do. You never, ever test on other people's accounts. Once you know about the vulnerability, you stop and report it.

Knowing the front door is unlocked does not mean you can go inside.

Re: I found a vulnerability. they found a lawyer

#217
post #165

Earlier quoted context omitted.

You don't need to retrieve other people's data to demonstrate the vulnerability. It's readily evident that people have an account with a default password on the site for some amount of time, and some of them indefinitely. You know what data is in the account (as the person who creates the accounts) and you know the IDs are incremental. You can do the login request and never use the retrieved access/session token (or…

> You don't need to retrieve other people's data to demonstrate the vulnerability. If you’re reporting to a nontechnical team…which sometimes you are…sometimes you do?

Absolutely not. That's not your concern nor your problem.

They're perfectly capable of hiring incident response experts, and companies commonly have cyber insurance that'll pay for it.

"Demonstrating" is dumb and means you turn an ordinary disclosure into personal liability for you.

Blabbing about it on the internet is just the idiot cherry on the stupid cake.

Re: I found a vulnerability. they found a lawyer

#218
post #201
post #192

Earlier quoted context omitted.

The risk of lawsuits like the ones threatened to be filed against this researcher.

They can also sue the pope but I don't think the pope finds that a risk worth considering either when they didn't do any hacking, legal or otherwise. How would an organization get sued for hacking when they didn't do any hacking and are merely passing on a message?

They would call it abetting. It's not as if the site doesn't know what it's disclosing.

Re: I found a vulnerability. they found a lawyer

#219

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

Agree with the points. Cybersec audits are mandatory for insurance companies in most countries. This list need to be expanded.

Re: I found a vulnerability. they found a lawyer

#220

Earlier quoted context omitted.

I'm wary of centralizing the powers of the web like that.

Web is already mostly centralized, and corporations which should be scrutinized in way they handle security, PII and overall software issues are without oversight. It is also a matter of respect towards professionals. If civil engineer says that something is illegal/dangerous/unfeasible their word is taken into the account and not dismissed - unlike in, broadly speaking, IT.

The question is who defines security.

I, as a self-proclaimed dictator of my empire, require, in the name of national security, all chat applications developed or deployed in my empire to send copies of all chat messages to the National Archive for backup in a form encrypted to the well-known National Archive public key. I appoint Professional Software Engineers to inspect and certify apps to actually do that. Distribution of non-certified applications to the public or other forms of their deployment is prohibited and is punishable by jail time, as well as issuing a false certification.

Sounds familiar?

The difference from civil engineering is that governments do not (yet?) require a remotely triggerable bomb to be planted under every bridge, which would, arguably, help in a war, while they are very close to this in software. They do something similar routinely with manufacturing equipment - mandatory self-disabling upon detecting (via GPS) operation in countries under sanctions.

Post reply on HN