[flagged]
Having a curious look is alright but it's the "beg bounty" attitude that these researchers need to rein in. It's like the sponge-and-bucket guy washing your grimy windscreen without you asking while you wait at the lights, then demanding cash for it. Thanks but no thanks.
Researcher finds flaw in a16z website that exposed some company data
241–246 of 246 posts
Re: Researcher finds flaw in a16z website that exposed some company data
#242[flagged]
And so you're just going to dismiss the modern reality of cybersecurity threats? "What happened to the good old days when we could all leave our cars and homes unlocked.." Yeah no.
That is actually a really good question you should be asking. Also when it comes to computers.
Re: Researcher finds flaw in a16z website that exposed some company data
#243Re: Researcher finds flaw in a16z website that exposed some company data
#244Earlier quoted context omitted.
How do you know that? Both quotes seem to explain why what you're saying isn't true.
If anyone could view any of those secrets and access emails, then sensitive data was exposed. They can't just decide it wasn't exposed because no one else told them about this.
Re: Researcher finds flaw in a16z website that exposed some company data
#245Earlier quoted context omitted.
If anyone could view any of those secrets and access emails, then sensitive data was exposed. They can't just decide it wasn't exposed because no one else told them about this.
Couldn't it be the case that the secrets were not useful for accessing sensitive emails? Their response made it sound like the secrets were limited to a specific, limit-used app.
> the compromised list of services:
> their database (containing PII)
> their AWS
> their salesforce (never checked, account may be limited)
> mailgun (arbitrary emails from a16z domains, and also could read older emails)
> ... and probably more
Re: Researcher finds flaw in a16z website that exposed some company data
#246Earlier quoted context omitted.
I think I'd be looking for at least a refund on that pen test. I've never come across one that was anymore than a box ticking exercise.
Security is just box checking. Most IT work is. The deployed stack has limited set of parameters to learn and test for. Leetcode is popular hiring criteria for a reason; that kind of code checks the “KISS/don’t be clever” and DRY rediscovering known algorithms boxes Except in a few fields, most startups are pretty vanilla config ops and secops tasks. Recent popularity among the working class has inflated the egos of…