Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

291–300 of 466 posts

Re: I found a vulnerability. they found a lawyer

#291

Earlier quoted context omitted.

Regarding your 2), in other industries and engineering professions, the architect (or civil engineer, or electrical engineer) who signed off carries insurance, and often is licensed by the state. I absolutely do not want to gatekeep beginners from being able to publish their work on the open internet, but I often wonder if we should require some sort of certification and insurance for large businesses sites that hand…

It's kinda wild that you don't need to be a professional engineer to store PII. The GDPR and other frameworks for PII usually do have a minimum size (in # of users) before they apply, which would help hobbyists. The same could apply for the licensure requirement. But also maybe hobbyists don't have any business storing PII at scale just like they have no business building public bridges or commercial aircraft.

Worth noting that “PII” is not a concept under the GDPR and that it’s definition of Personal Data is much broader than identifiable information.

Re: I found a vulnerability. they found a lawyer

#292

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

I find it interesting how American-accented people publish on social media how to access non-linked FBI files related to the Epstein leak, by updating a URL.

Re: I found a vulnerability. they found a lawyer

#293
post #280

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

What is CFAA? I couldn't find anything about it in EU or Malta. Is it something in India or China? Or Japan? Hmm, maybe I'm missing another country.. Australia?

Computer Fraud and Abuse Act

Re: I found a vulnerability. they found a lawyer

#294

Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vul…

> Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution

That logic is garbage and assumes there is some arbitrary point at which a user should magically know the difference between a few IDs happening to be near each other versus a system wide problem. The law would use the interpretations of "knowingly", "intent" and in this case "reasonable".

Re: I found a vulnerability. they found a lawyer

#296

Three thoughts from someone with no expertise. 1) If you make legal disclosure too hard, the only way you will find out is via criminals. 2) If other industries worked like this, you could sue an architect who discovered a flaw in a skyscraper. The difference is that knowledge of a bad foundation doesn’t inherently make a building more likely to collapse, while knowledge of a cyber vulnerability is an inherent risk.…

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

I wish I would have a rubber stamp like professional engineers do.

Re: I found a vulnerability. they found a lawyer

#297
post #278

I disclosed a vulnerability much like this one. .gov website. Incrementing IDs. No password to crack, just a url parameter with a Boolean value. Pretty much example.com/clients/fullz?id=123&butDoIReallyHaveToAuth=false Changed param key but yeah. Just that. You did need to have an authenticated session, but any valid session token would do. They hit me with same kind of response. I got a lawyer. Worked out in the end…

Proxies are cheaper than lawyers.

Re: I found a vulnerability. they found a lawyer

#298

You typically disclose the vulnerability for one of these reasons: you want money, you want fame, you want to make a better world. There are others such as blackmail but let's settle for the typical ones. If you do it for money or fame, you step cautiously not to annoy the company. You ask, you beg, etc. Not something to be proud of but this is life. If you do this to make the world a better place, you get annoying.…

Full disclosure is responsible disclosure.

Companies can't hide when there is a website or bot spewing out the information with their logo next to it.

Proxies are cheaper than lawyers.

Re: I found a vulnerability. they found a lawyer

#300

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t mean you have any right or legitimacy to impose a deadline on them, you’re not their boss. This is some vigilante shit and it has not justification whatsoever. Report to the org, report to the authorities as needed and move on.
Post reply on HN