Live data from Hacker News

I found Prezi's source code

blog.shubh.am

231–240 of 266 posts

Re: I found Prezi's source code

#231

There should be some neutral third party non-profit that adjudicates bug bounties so that security researchers don't need to worry that their efforts will go to waste. Companies could sign on to using this third party and pay a fee and put up escrow for the service. This would motivate researchers to find bugs for those companies that utilize the service, knowing payment will be impartial.

A simple option is CrowdCurity - reward programs as a service. Private or public, dollars or bitcoin payments - everything setup and managed for the companies. https://www.crowdcurity.com/ Disclosure: I'm co-founder of CrowdCurity

You know, you are just harming yourself this way. If you must show your stuff on HN, why not post it as a ShowHN?? why do this dishonorable thing to gain attention? IMO it actually harms you.

Re: I found Prezi's source code

#232

Earlier quoted context omitted.

"Because they tried" doesn't get a B. You're not graded on effort. What you're graded on - when it comes to defense as opposed to recovery, though both are a part of this - is how likely a breach is. Unfortunately, you don't always learn your grade (and when you do, it's bad). "Gambling with security will always be a losing bet in the long run. Rather just make it secure. Going off some strange 'expected resources' i…

No. But if the site gets hacked, I failed. If I asked users for their credits cards and stored it in a publicly accessible plain text file or in a secure system that still gets hacked the end result is still the same. My users are having unauthorized payments coming off their credit cards. I've failed. Maybe I can sleep better at night if I didn't go storing them in plain text and I can make up excuses easier, but I…

> So skimping on security is always a terrible idea. If you know of a way to increase security, then you should increase it.

This is what all of the "security" vendors would like you to believe. It completely ignores the value of the assets you are securing.

How many rounds do you use with PBKDF2 if you want to slow down attackers? You can always add more rounds to slow down brute forcing, so how would you reconcile this with your statement of always increasing security. The same applies to bcrypt.

Re: I found Prezi's source code

#234
post #170

Why even have a limited scope on bounty programs? (This is not the only time I've seen that.) Is it only to limit payout? Are their legal reasons? For example, their client tablet applications are ineligible. I just don't get the reasoning. In their position, I'd pay him the $500 and remove the idea of scope. I'm just curious if there's some counter-argument I'm not thinking about.

I think it's ridiculous, I've reported similar "out of scope" bugs and got no bounty for them. Even worse are the companies that DON'T state any kind of bug bounty or instructions to report a security bug... I found a data leak issue in one of the web properties of an S&P 500 company last week and I'm not sure if I should report it, because I feel that if misunderstood it could have negative consequences for me; and…

Sorry, I have some problems with this attitude of expecting a reward for each and every action that benefits other human beings. Whatever happened to altruism?

Re: I found Prezi's source code

#235
This policy of limiting security assessments/bug bounties to only certain things is really stupid.

Do you really think that any extremely motivated hacker would just stick to the arbitrary terms you set.

He will do whatever it takes to get in and by limiting security research you're making yourself vulnerable in other areas not defined in that assessment request.

Re: I found Prezi's source code

#236
post #170

Earlier quoted context omitted.

I think it's ridiculous, I've reported similar "out of scope" bugs and got no bounty for them. Even worse are the companies that DON'T state any kind of bug bounty or instructions to report a security bug... I found a data leak issue in one of the web properties of an S&P 500 company last week and I'm not sure if I should report it, because I feel that if misunderstood it could have negative consequences for me; and…

Sorry, I have some problems with this attitude of expecting a reward for each and every action that benefits other human beings. Whatever happened to altruism?

I don't think you understand, it's not about a reward; it's about having a clearly defined process to report security bugs that is inclusive of every kind of bug.

If you don't have that, people don't know if they are breaking the law by sending you a bug report, and they might not report the issues.

Most of the time, the bounty is not going to pay for my time anyway; I just do it for the fun of it, but it definitely says "security issues are welcome"

Re: I found Prezi's source code

#237

Earlier quoted context omitted.

A simple option is CrowdCurity - reward programs as a service. Private or public, dollars or bitcoin payments - everything setup and managed for the companies. https://www.crowdcurity.com/ Disclosure: I'm co-founder of CrowdCurity

You know, you are just harming yourself this way. If you must show your stuff on HN, why not post it as a ShowHN?? why do this dishonorable thing to gain attention? IMO it actually harms you.

a down vote? :O but why? i thought we were unanimously against plugs?

Re: I found Prezi's source code

#238

There should be some neutral third party non-profit that adjudicates bug bounties so that security researchers don't need to worry that their efforts will go to waste. Companies could sign on to using this third party and pay a fee and put up escrow for the service. This would motivate researchers to find bugs for those companies that utilize the service, knowing payment will be impartial.

A simple option is CrowdCurity - reward programs as a service. Private or public, dollars or bitcoin payments - everything setup and managed for the companies. https://www.crowdcurity.com/ Disclosure: I'm co-founder of CrowdCurity

Fine fine, i'll play nice...

Ps: the idea is pretty cool. So is the implementation =) though how would you guys have handled if an issue like this occurs on your platform? A submitter submits a bug but the company refuses to pay for it citing "out of scope" ??

Re: I found Prezi's source code

#239

Earlier quoted context omitted.

'Just want to add that this shows a very large misconception in the corporate security world. Security is not something you can get a "B - good effort" for. Security is all encompassing. You either get an A+ and the hacker does not get in, or you get an F and your data is gone. There is no middle ground.' That's not true. There are substantially different levels of security required depending on the expected resource…

I disagree here - you've either lost the data or you haven't. You can make guesses as to the expected resources of the attacker, but if you're wrong and the attacker has more resources, then you might as well have not even bothered. As an example, you have some fairly non-sensitive private health records. Here are three approaches: (1) No security at all. You hope nobody is going to bother taking them and using them…

> I disagree here - you've either lost the data or you haven't.

You seem to be implying that the fact there are two possible outcomes implies there are only two possible initial states - vulnerable and not vulnerable. If the attacker steals data, the initial state was vulnerable, and if the attacker fails, the initial state was not vulnerable.

This is what poker players call "results-orientated thinking". The initial state is much more like a range of continuous values, where 0 is "having literally no security whatsoever" and 1 is "having security no earthly force can overcome in any scenario".

No private company has perfect security, and perfect security is not desirable, because incremental security has non-zero cost. Does it make sense for a typical firm to spend millions of dollars hardening their office building against the threat of attack by a heavily armed private militia? No, because for most firms the cost of preparing against such an attack outweighs the risk-weighted value of preventing such an attack.

Incrementally improving security narrows the range of successful attacks. Incrementally improving security means fewer attackers will be skilled enough able to successfully infiltrate, and fewer attackers with enough skill will go to the effort to successfully infiltrate. The goal is not to guard against every conceivable attacker, but, in a simplified model, to incrementally improve security until the marginal cost of the last improvement is equal to the marginal value of the reduction of attack scenarios.

> If (2) had guessed correctly and nobody had actually devoted those resources then (2) gets a flying colors because the data is safe - but it's just pure gambling

"Gambling" has no particular meaning in this context, because every decision about security precautions involves weighing known costs against potential risks. The division of security plans is not between "gambling" and "not gambling" but rather between "positive expected value" and "negative expected value".

Re: I found Prezi's source code

#240
post #170

Earlier quoted context omitted.

I think it's ridiculous, I've reported similar "out of scope" bugs and got no bounty for them. Even worse are the companies that DON'T state any kind of bug bounty or instructions to report a security bug... I found a data leak issue in one of the web properties of an S&P 500 company last week and I'm not sure if I should report it, because I feel that if misunderstood it could have negative consequences for me; and…

Sorry, I have some problems with this attitude of expecting a reward for each and every action that benefits other human beings. Whatever happened to altruism?

Since when the word "altruism" applies to corporations? I believe that word is intended to relate to people, not businesses.
Post reply on HN