Live data from Hacker News

Researcher finds flaw in a16z website that exposed some company data

kibty.town

241–246 of 246 posts

Re: Researcher finds flaw in a16z website that exposed some company data

#241
post #163
post #27

[flagged]

Having a curious look is alright but it's the "beg bounty" attitude that these researchers need to rein in. It's like the sponge-and-bucket guy washing your grimy windscreen without you asking while you wait at the lights, then demanding cash for it. Thanks but no thanks.

Agreed, and all the "shame if next time someone would sell it on the black market" comments don't exactly make those "researchers" look like the good guys.

Re: Researcher finds flaw in a16z website that exposed some company data

#242
post #27

[flagged]

And so you're just going to dismiss the modern reality of cybersecurity threats? "What happened to the good old days when we could all leave our cars and homes unlocked.." Yeah no.

> What happened to the good old days when we could all leave our cars and homes unlocked..

That is actually a really good question you should be asking. Also when it comes to computers.

Re: Researcher finds flaw in a16z website that exposed some company data

#244

Earlier quoted context omitted.

How do you know that? Both quotes seem to explain why what you're saying isn't true.

If anyone could view any of those secrets and access emails, then sensitive data was exposed. They can't just decide it wasn't exposed because no one else told them about this.

Couldn't it be the case that the secrets were not useful for accessing sensitive emails? Their response made it sound like the secrets were limited to a specific, limit-used app.

Re: Researcher finds flaw in a16z website that exposed some company data

#245

Earlier quoted context omitted.

If anyone could view any of those secrets and access emails, then sensitive data was exposed. They can't just decide it wasn't exposed because no one else told them about this.

Couldn't it be the case that the secrets were not useful for accessing sensitive emails? Their response made it sound like the secrets were limited to a specific, limit-used app.

I'm just going off what the hacker said.

> the compromised list of services:

> their database (containing PII)

> their AWS

> their salesforce (never checked, account may be limited)

> mailgun (arbitrary emails from a16z domains, and also could read older emails)

> ... and probably more

Re: Researcher finds flaw in a16z website that exposed some company data

#246
post #205
post #180

Earlier quoted context omitted.

I think I'd be looking for at least a refund on that pen test. I've never come across one that was anymore than a box ticking exercise.

Security is just box checking. Most IT work is. The deployed stack has limited set of parameters to learn and test for. Leetcode is popular hiring criteria for a reason; that kind of code checks the “KISS/don’t be clever” and DRY rediscovering known algorithms boxes Except in a few fields, most startups are pretty vanilla config ops and secops tasks. Recent popularity among the working class has inflated the egos of…

This actually sounds like a great idea for a show and one I'd watch with great interest.
Post reply on HN