Live data from Hacker News

I found Prezi's source code

blog.shubh.am

241–250 of 266 posts

Re: I found Prezi's source code

#241

Earlier quoted context omitted.

This is a fascinating discussion because it betrays two fundamental attitudes of society to risk. RyanZAG is "correct". If someone breaks into my house and steals my TV, then my security was a failure. This leads to the next problem - its not a catastrophic failure in today's (western) society . I am probably out at work, and I am insured, and the burglar is unlikely to be waiting when I get home to murder me. Howeve…

Great perspective! "So its not a judgement on the resources of the attacker that matters, it is the expected consequences of the breach - the expected value of damage." I nodded at this when I mentioned resiliency and recovery, but I still think resources of the attacker matters. A determined attacker could doubtless breach your front door with a battering ram or axe and enough time. Part of the reason you don't worr…

That is a good point - I factor in the security of a effective police force, a legal system that will not tolerate using threats to sign over a business for $1 - all of these are part of our security.

Curiously I am not convinced of the total damage done by these various break-ins. Stealing credit card numbers is not the same as getting the loot into a laundered bank account. Grabbing bitcoin wallets is closer, but the liquidity does not exist to extract much.

The damage is seemingly more reputational, or other internal costs to the hacked company (like paying security consultants). The actual "money the thieves ran off with and could convert into real cash" is pretty thin - would value some pointers at studies here.

Re: I found Prezi's source code

#242

Earlier quoted context omitted.

You know, you are just harming yourself this way. If you must show your stuff on HN, why not post it as a ShowHN?? why do this dishonorable thing to gain attention? IMO it actually harms you.

a down vote? :O but why? i thought we were unanimously against plugs?

You didn't get the memo ? There's no such thing as a single we anymore.

Re: I found Prezi's source code

#243
post #225
post #209

Earlier quoted context omitted.

Can you expand?

I think he means that if we're not holding Prezi ethically responsible to pay the bounty, then we can't then start saying the researcher is ethically bound not to sell the exploit.

But Prezi aren't ethically responsible for paying the bounty. They stated the conditions pretty clearly and what he found wasn't within their scope.

Re: I found Prezi's source code

#244
post #229
post #225

Earlier quoted context omitted.

I think he means that if we're not holding Prezi ethically responsible to pay the bounty, then we can't then start saying the researcher is ethically bound not to sell the exploit.

Exactly, it's just a URL. Why not sell it? People sell URLs all the time, and bitbucket is clear written intent from the company that they wanted their source control systems accessible to the public else they would not have provided written notice to the world of their passwords. Surely the creators of the software are competent software experts who fully understood the implications of making their repository public…

Selling the login credentials would probably be illegal. It's a grey area, at least.

Re: I found Prezi's source code

#245
post #55

What this guy describes doing (using accidentally exposed credentials to log in to somewhere) is quite a bit more than what other people have been successfully prosecuted for violations of the CFAA for. I'd be careful.

You mean that Prezi, a Hungarian company, would prosecute the author, an Australian, under an American law? The Internet isn't just something happening in the United States.

It's a fair point, but a lot of other countries have similarly strict laws.

Re: I found Prezi's source code

#246
post #80

Earlier quoted context omitted.

If you leave your door open and someone enters without your knowledge, would you call the police?

It is closer to find someones home key in a public place and deciding to see if it opens their door or not before giving it back. You did not enter the house you did not explore. You turned the key, the knob, and made sure the door would open a little. Not something I would recommend, especially since the key had the address and the owner name and address attached to it. But not as bad as someone entering the home an…

The analogies are beside the point. Logging in to a system which you don't have permission to access just is illegal in many countries, whether you think that it ought to be or not.

Re: I found Prezi's source code

#247

Simply by logging in he could be thrown in jail. I hope some prosecutor doesn't get wind and decides to bring charges.

Which laws would apply?

In the US, the CFAA:

https://ilt.eff.org/index.php/Computer_Fraud_and_Abuse_Act_(...

Apparently neither Prezi nor the guy who found the login are American, so this particular law might not apply, but many other countries have similar laws.

Re: I found Prezi's source code

#249

Earlier quoted context omitted.

How is that dishonest? It sounds like a great way to improve security and get bounties.

I'm sure (paying) customers will be totally fine with Prezi's source code being available to anyone that want to try to hack the site.

I fail to see how that has anything to do with honesty. The source was leaked accidentally.
Post reply on HN