Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

31–40 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#31
post #15

Not very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.

OP here, the one who found the exposed data. Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies. Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.

I don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.

Re: 'Impossible-to-hack' security turns out to be no security

#32

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

The tone doesn't have to be professional. Not everybody owes you professional courtesy, especially when you're giving away personal information on your customers.

Re: 'Impossible-to-hack' security turns out to be no security

#33

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Your comment is unprofessional, the CEO in question deserves a lot more vitriol frankly.

Re: 'Impossible-to-hack' security turns out to be no security

#34

[flagged]

That's...not what blackmail is.

Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly.

If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.

Re: 'Impossible-to-hack' security turns out to be no security

#35

Earlier quoted context omitted.

OP here, the one who found the exposed data. Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies. Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.

I don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.

I think the around 50 public disclosures I did in the last year where I asked 0 times for anything kinda show I'm not looking for any payments.

There is a huge issue regarding publicly exposed data that no one seems to want to acknowledge or talk about, what you see online? It's 100 times worse.

I'm someone who is trying to raise awareness through my finds, nothing else.

Also I was initially polite to the company, not once but twice, as I am to anyone who I reach out, why wouldn't I be? I want them to fix the issues, not ignore me.

Don't expect the politeness to be infinite though, specially when you start accusing me of harassment and lying about the severity of the exposure that affects thousands of people, the ones I DO care about, not the companies.

Re: 'Impossible-to-hack' security turns out to be no security

#36

Earlier quoted context omitted.

OP here, the one who found the exposed data. Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies. Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.

I don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.

Sure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards.

Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.

Re: 'Impossible-to-hack' security turns out to be no security

#37
I'm confused about the chronology here:

1. He discovers an unprotected database.

2. He mails the CEO of the company.

3. The database is fixed.

4. He mails the CEO again to say he's publishing.

5. The CEO replies and says there was no security breach.

6. He goes spelunking in the database tables to write a rebuttal?

How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access to it in step 3?

Re: 'Impossible-to-hack' security turns out to be no security

#38

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.

sure you're a journalist, but the best kind! Gonzo![0]

I found the tone highly entertaining; don't let the haters wear you down

0 https://en.wikipedia.org/wiki/Gonzo_journalism

Re: 'Impossible-to-hack' security turns out to be no security

#39
post #12

Earlier quoted context omitted.

Some powerful people subscribe to the idea that "if I (or the law) says don't touch it, it's secure". This attitude was on full display a little over three years ago in Missouri. https://missouriindependent.com/2021/10/14/missouri-governor...

Missouri

fixed, thank you.

Re: 'Impossible-to-hack' security turns out to be no security

#40
Unfortunately, there are people out there (with a seemingly large overlap with CEOs) that have incredibly fragile egos, and any perceived criticism (such as pointing out a dreadful security failure) can result in lies, excessive reactions, defensiveness, denial, insults, scapegoating or even retaliation. Or all of the above.

In situations like this, it feels to me like the reaction is “how dare you think that I would need your help?!”

Post reply on HN