Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

231–240 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#231

From the techcrunch article: > “On June 30th, a16z addressed a misconfiguration in a web app that is used for the specific use case of updating publicly available information on our website such as company logos and social media profiles. The issue was resolved quickly and no sensitive data was compromised,” What the fuck is this? They are blatantly lying here. There was a lot of sensitive data compromised. Anyone wh…

How do you know that? Both quotes seem to explain why what you're saying isn't true.

Re: Researcher finds flaw in a16z website that exposed some company data

#232

I made a similar mistake actually. We used a nodejs cms called apostrophecms that had an admin panel called global settings. We used that for managing api keys to our auth server. We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it. Annoyingly we paid a reasonable amount of mon…

Hello, I'm really sorry you had this unexpected exposure using ApostropheCMS. As you've mentioned, this data sharing was noted in the documentation but can still prove surprising. A note for future researchers: the currently supported major version of Apostrophe no longer behaves in this way . Any data injection to the logged-out front-end would be a choice made at the developer level, specifically to avoid this sort…

Yeah, I didn't want to dunk on ApostropheCMS, this was our responsibility for not understanding the tech. I made another comment hoping to make that clear.

Overall it's a great & in current headless craze a unique product. V3 looks very good, but we never got that in production.

Re: Researcher finds flaw in a16z website that exposed some company data

#233
post #226

Earlier quoted context omitted.

> It’s obviously not safe to publicly announce the existence of a security vulnerability Publicly showing the vulnerability would have been unsafe, but I don't think there's much harm in asking to get in touch about an unspecified security issue (not even saying that it's a vulnerability in their website). Andreessen Horowitz is a massive firm, not some tiny website flying under the radar. > and there was no barrier…

> I feel we're going over the actions of an individual researcher with a fine-comb, searching for any hint that there was an arguably better course of action, when there are multiple huge obvious mistakes from a16z. You're going over things "with a fine-comb". I just wrote two sentences that made a single point.

The extent to which attempted fault-finding of someone's behavior is unwarranted is not determined by the number of words. I could complain "Why break my door when the window was open!?" to the firefighter carrying me out of a burning building in nine words.

Re: Researcher finds flaw in a16z website that exposed some company data

#234

Earlier quoted context omitted.

Doing free work for A16Z or any of the awful companies ruining our world is not helping make anything better.

I think A16Z and the companies they’ve funded have done a great deal of good for the world. The very web browser you’re typed your angry comment into is a technology pioneered by one of its two founders. Being anti-VC is essential being against technological and economic progress.

I like netscape & its decedents.

Not everything that happens is progress, the world can often do without 'disruption'

Re: Researcher finds flaw in a16z website that exposed some company data

#235

From the techcrunch article: > “On June 30th, a16z addressed a misconfiguration in a web app that is used for the specific use case of updating publicly available information on our website such as company logos and social media profiles. The issue was resolved quickly and no sensitive data was compromised,” What the fuck is this? They are blatantly lying here. There was a lot of sensitive data compromised. Anyone wh…

How do you know that? Both quotes seem to explain why what you're saying isn't true.

If anyone could view any of those secrets and access emails, then sensitive data was exposed. They can't just decide it wasn't exposed because no one else told them about this.

Re: Researcher finds flaw in a16z website that exposed some company data

#236
post #2

> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…

A post to HN with a query for how to get in touch with a16z engineering probably would have been fruitful.

Re: Researcher finds flaw in a16z website that exposed some company data

#237
Question to the community. I managed to expose all customer data of a well-funded D2C brand and when I reached out to them I did not ask for bounty before I shared the fix/the security hole. I only got a 200 USD gift card for their shop :D

What is best practice here? Do you first tell the company that they have a security issue, ask for bounty and then help? Is that unethical? Blackmail?

Re: Researcher finds flaw in a16z website that exposed some company data

#238
post #22

When I create a new service and add LetsEncrypt cert to server via ACME. I immediately see logs filled with junk, obviously bots searching for shitty defaults that devs might leave open. I have even seen requests for the process env file lol. How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker m…

To be fair, their main site doesn't seem super interesting. Couple of those credentials, such as OKTA seem bad though.

Re: Researcher finds flaw in a16z website that exposed some company data

#239
post #78
post #68

Earlier quoted context omitted.

Let's imagine your backpack is open. It's polite to say thanks if someone informs you that you accidentally left your backpack open. But in no way you are supposed to give them anything. Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.

... Did they actually steal anything or take advantage, or just touch the bag to make sure it wasn't fake? Seems more of the latter, and your analogy falls flat when the bag carrier contains other people's pii.

There are pleny of people here saying the equivalent that "not paying will only encourage people to take things from your backpack instead".

Re: Researcher finds flaw in a16z website that exposed some company data

#240
post #43

Hopefully Martin Casado or one of the other awesome open source folks from a16z will take a look at this and make the person whole!

The person is whole as nothing was taken from them. If you choose to do free work you are not owed anything.
Post reply on HN