From the techcrunch article: > “On June 30th, a16z addressed a misconfiguration in a web app that is used for the specific use case of updating publicly available information on our website such as company logos and social media profiles. The issue was resolved quickly and no sensitive data was compromised,” What the fuck is this? They are blatantly lying here. There was a lot of sensitive data compromised. Anyone wh…
Researcher finds flaw in a16z website that exposed some company data
231–240 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#232I made a similar mistake actually. We used a nodejs cms called apostrophecms that had an admin panel called global settings. We used that for managing api keys to our auth server. We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it. Annoyingly we paid a reasonable amount of mon…
Hello, I'm really sorry you had this unexpected exposure using ApostropheCMS. As you've mentioned, this data sharing was noted in the documentation but can still prove surprising. A note for future researchers: the currently supported major version of Apostrophe no longer behaves in this way . Any data injection to the logged-out front-end would be a choice made at the developer level, specifically to avoid this sort…
Overall it's a great & in current headless craze a unique product. V3 looks very good, but we never got that in production.
Re: Researcher finds flaw in a16z website that exposed some company data
#233Earlier quoted context omitted.
> It’s obviously not safe to publicly announce the existence of a security vulnerability Publicly showing the vulnerability would have been unsafe, but I don't think there's much harm in asking to get in touch about an unspecified security issue (not even saying that it's a vulnerability in their website). Andreessen Horowitz is a massive firm, not some tiny website flying under the radar. > and there was no barrier…
> I feel we're going over the actions of an individual researcher with a fine-comb, searching for any hint that there was an arguably better course of action, when there are multiple huge obvious mistakes from a16z. You're going over things "with a fine-comb". I just wrote two sentences that made a single point.
Re: Researcher finds flaw in a16z website that exposed some company data
#234Earlier quoted context omitted.
Doing free work for A16Z or any of the awful companies ruining our world is not helping make anything better.
I think A16Z and the companies they’ve funded have done a great deal of good for the world. The very web browser you’re typed your angry comment into is a technology pioneered by one of its two founders. Being anti-VC is essential being against technological and economic progress.
Not everything that happens is progress, the world can often do without 'disruption'
Re: Researcher finds flaw in a16z website that exposed some company data
#235From the techcrunch article: > “On June 30th, a16z addressed a misconfiguration in a web app that is used for the specific use case of updating publicly available information on our website such as company logos and social media profiles. The issue was resolved quickly and no sensitive data was compromised,” What the fuck is this? They are blatantly lying here. There was a lot of sensitive data compromised. Anyone wh…
How do you know that? Both quotes seem to explain why what you're saying isn't true.
Re: Researcher finds flaw in a16z website that exposed some company data
#236> a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because there was no available contact on their main site and the email i could find engineering@a16z.com bounced my emails That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties wi…
Re: Researcher finds flaw in a16z website that exposed some company data
#237What is best practice here? Do you first tell the company that they have a security issue, ask for bounty and then help? Is that unethical? Blackmail?
Re: Researcher finds flaw in a16z website that exposed some company data
#238When I create a new service and add LetsEncrypt cert to server via ACME. I immediately see logs filled with junk, obviously bots searching for shitty defaults that devs might leave open. I have even seen requests for the process env file lol. How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker m…
Re: Researcher finds flaw in a16z website that exposed some company data
#239Earlier quoted context omitted.
Let's imagine your backpack is open. It's polite to say thanks if someone informs you that you accidentally left your backpack open. But in no way you are supposed to give them anything. Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.
... Did they actually steal anything or take advantage, or just touch the bag to make sure it wasn't fake? Seems more of the latter, and your analogy falls flat when the bag carrier contains other people's pii.
Re: Researcher finds flaw in a16z website that exposed some company data
#240Hopefully Martin Casado or one of the other awesome open source folks from a16z will take a look at this and make the person whole!