Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

361–370 of 466 posts

Re: I found a vulnerability. they found a lawyer

#361

I am a lawyer and my field do cross this area which the events have transpired. First, yes, everyone should acknowledge that this matter has been handled poorly by their corporate in-house and external lawyers. These should not have happened. The company should face consequences. I advise my data controller corporate clients to reach out to the reporter/whistleblower immediately and have the IT team collaborate, at t…

> You cannot disclose this to public. Even with good intentions.

Bullshit, NIS 2 article 12 specifically says CSIRTs must coordinate the negotiation of a disclosure timeline between reporter and provider. I'd say offering a 30 day embargo while CC'ing the relevant CSIRT is the start of such negotiation from the reporter.

My biggest doubt about this story, LLM writing aside, is the lack of mention of a CSIRT follow up.

Re: I found a vulnerability. they found a lawyer

#362

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

Good guideline advice but it seems you didn't read the article. Their personal data was at risk here. Leaving them alone would very likely result in a breach of this person's data. Both he and you have an ethical responsibility to at minimum notify the business of this problem and follow up with it.

Re: I found a vulnerability. they found a lawyer

#363

Earlier quoted context omitted.

In other industries there are professional engineers. People who have a legal accountability. I wonder if the CS world will move that way, especially with AI. Since those engineers are the ones who sign things off. For people unfamiliar, most engineers aren't professional engineers. There are more legal standards for your average engineer and they are legally obligated to push back against management when they think…

You'd be surprised how many SE's would love for this to happen. The biggest reason, as you said, being able to push back. Having worked in low-level embedded systems that could be considered "system critical", it's a horrible feeling knowing what's in that code and having no actual recourse other than quitting (which I have done on few occasions because I did not want to be tied to that disaster waiting to happen). I…

I work in manufacturing, though this comment is a generalization, and depends on what industry you’re in. What happens in practice is that products are certified by a third party regulatory agency, probably Intertek. They’re the ones who hire the professional engineers. The pushback comes from the design engineers being aware of the regulations, and saying: “This won’t get past Intertek.”

The downside is, bring money. Also, don’t expect to have an agile development process, because Intertek is a de facto phase gate. The upside is that maintaining your own regulatory lab is probably more expensive, and it’s hard to keep up with the myriad of international standards.

As for mom-n-pops, why do you want competition from them? Regulatory capture always favors consolidation of an industry. What happens in practice for consumers is that stuff comes from countries where the regulatory process can be bypassed by just putting the approval markings on everything.

Okay, that was sarcastic, but it’s possible that the vitality of software owes a lot to the fact that it’s relatively unregulated.

On the other hand, I wouldn’t mind some regulatory oversight, such as companies having to prove that they don’t store my personal data.

Note that I’m naming Intertek, not to point a finger at them, but because I don’t know if they have any competitors.

Re: I found a vulnerability. they found a lawyer

#364

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

Good guideline advice but it seems you didn't read the article. Their personal data was at risk here. Leaving them alone would very likely result in a breach of this person's data. Both he and you have an ethical responsibility to at minimum notify the business of this problem and follow up with it.

That’s not how it works. You are not ethically responsible to hack every company you interact with.

Re: I found a vulnerability. they found a lawyer

#365

AFAIK, what this dude did - running a script which tries every password and actually accessing personal data of other people – is illegal in Germany. The reasoning is, just because a door of a car which is not yours is open you have no right to sit inside and start the motor. Even if you just want to honk the horn to inform the guy that he has left the door open. https://www.nilsbecker.de/rechtliche-grauzonen-fuer-et…

This is exactly what I thought. The person did something illegal by accessing random accounts and no explanation makes this better. Could have asked his diving students for their consent, could have asked past students for their consent to access their accounts - but random accounts you cannot access. Since this is a Maltese company I would assume different rules apply, but no clue how this is dealt with in Malta. Ho…

[deleted]

Re: I found a vulnerability. they found a lawyer

#366

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

NIS 2 article 12 specifically says the CSIRT must help reporter and provider negotiate a disclosure timeline. He set a timeline because there's supposed to be a timeline.

Re: I found a vulnerability. they found a lawyer

#367

Vulnerability Researcher here… Unless your target has a security bounty process or reward; leave them alone. You don’t pentest a company without a contract that specified what you can and can’t test. Although I would personally appreciate and thank a well meaning security researchers efforts most companies don’t. I have reported 0days for companies that HAVE bounties and they still tried to put me in hot water over d…

Good guideline advice but it seems you didn't read the article. Their personal data was at risk here. Leaving them alone would very likely result in a breach of this person's data. Both he and you have an ethical responsibility to at minimum notify the business of this problem and follow up with it.

I also guess you haven't read the article too:

> And the real irony? The legal threats are the reputation damage. Not the vulnerability itself - vulnerabilities happen to everyone. It's the response that tells you everything about an organization's security culture.

See. The moral of the story is that the entity care more about their face than the responsibility to fix the bug, that's the biggest issue.

He also pointed out bugs do happens and those are reasonable, and he agreed to expose them in an ethical manner -- but the goodwill, no matter well or ill intentioned, those responses may not come with the same good tolerations, especially when it comes to "national" level stuff where those bureaucrats knows nothing about tech but they knew it has political consequences, a "deface" if it was exposed.

Also, I happened to work with them before and know exactly why they have a lot of legal documents and proceedings, and that's because of bureaucracy, the bad kind, the corrupt kind of bureaucracy such that every wrong move you inflicted will give you huge, if not capitcal punishment, so in order to protect their interest, they rather do nothing as it is unfortunately the best thing. The risk associated of fixing that bug is so high so they rather not take it, and let it rot.

There's a lot of system in Hong Kong that is exactly like that, and the code just stay rotten until the next batch of money comes in and open up new theatre of corruption. Rinse and repeat

Re: I found a vulnerability. they found a lawyer

#368
post #225

Earlier quoted context omitted.

In many countries you are only allowed to call yourself a Software Engineer if you actually have a professional title. It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. I have been on the liability side ever since, people don't keep broken cars unless they cannot afford anything else, software is nothing special, other than lack of accountability.

Exactly this - I had a role in a multinational, US-founded company, however - I was based in Canada - our title had the name "engineer" contained within it. We were NOT by any means certified professional engineers according to any regulatory body - we were great at our jobs, but that was the reality. We were NOT allowed to refer to our job title when deployed to the province of Quebec, which has strong regulations a…

And the people of Quebec are much safer for it. /s

This divide between Canada and the US has existed since the birth of software engineering as a thing. Where is the evidence the protected name has done anything useful for either Canadian software engineers or its citizens?

Re: I found a vulnerability. they found a lawyer

#369
post #300

Earlier quoted context omitted.

This is standard practice. Typical HN behaviour to drive by with quite evidently zero relevant background and self-righteously preach for three paragraphs about something that you don’t understand. This industry sucks.

Maybe the standard practice sucks. No matter how you turn it around, it does sound like blackmail. Just because you disclose a vulnerability to an org doesn’t mean you have any right or legitimacy to impose a deadline on them, you’re not their boss. This is some vigilante shit and it has not justification whatsoever. Report to the org, report to the authorities as needed and move on.

Blackmail to gain what? Speedy update to the site? The OP is going to disclose the vulnerability. The only matter up for debate is the timing.

Re: I found a vulnerability. they found a lawyer

#370
post #309

Earlier quoted context omitted.

>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?

Professional labour value isn't synonymous with late stage capitalism without ethics or morals. Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.

How do you explain the low quality of software coming out of all of the other countries you have mentioned with protected titles?

The software is happening regardless of title and you haven’t given any examples of the value of where kissing the ring to get the certification has been critical to Canada/Germany/Switzerland producing better software.

Post reply on HN