So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?
After getting ignored even when the FBI got involved? What would be the right way then?
Security Researcher Assaulted Following Vulnerability Disclosure
41–50 of 118 posts
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#42Re: Security Researcher Assaulted Following Vulnerability Disclosure
#43I was once fired from a state job (USA) for bringing a vulnerability forward in the online ethics training. You can run "setScore(100, 0, 100)" in the developer console and pass the exam without actually taking it. (The state used a third party online exam provider who I contacted). I was fired by the end of the week
Though you probably would have done better to report the problem through the state authorities overseeing the contractor (or the general government oversight agency, like th Bureau of State Audits in California) rather than the contractor, to whom your report was a threat of revealing their poor performance.
If nothing else, a report to responsible state authorities would be less likely to meet with someone with an incentive to sweep it under the rug (especially a general oversight body) and would be more likely protected by whistleblower protections, which most states have in some form.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#44Re: Security Researcher Assaulted Following Vulnerability Disclosure
#45Re: Security Researcher Assaulted Following Vulnerability Disclosure
#46With articles like this, I often to take out the horrible thing that the company is doing and post the quote to Hacker News, to give a sense of the scale of the issue; in this case me trying to do so would require including the majority of the article. It’s that bad. And yes, apparently the company thought it was ok for the COO to physically assault security researchers at a conference.
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#47Now that this is out in the open, I wonder how much longer Atrient will stay in business. These people sell these systems to casinos. Their customers are not going to like this at all. Atrient mostly handles affinity cards and such. So they have lots of info about customers, including drivers license scans[1], but not much of a connection into the casino's main systems. A basic break-in might get you a suite upgrade…
"...and that you could enter casino cash prize draws with as many entries as you wanted in order to win them, ..."
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#48So they agreed with them about the 60,000 bounty, were waiting for a NDA agreement with the lawyers, but this didn't happen fast enough for them and so they showed up unannounced to an important conference where the company was announcing a new product to question them about it. Obviously assault is not right at all. But was this really the right way to check on the status of a security fix?
After getting ignored even when the FBI got involved? What would be the right way then?
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#49Disclosing security vulnerabilities that aren't part of a bug bounty program takes a large amount of either courage or ignorance. Until there are protections in place for a given jurisdiction, far safer to leak it anonymously or just stay quiet. I was surprised that GDPR didn't contain any sort of protections for security researchers. The fines collected are hefty enough they could easily run a very successful bug bo…
Re: Security Researcher Assaulted Following Vulnerability Disclosure
#50Disclosing security vulnerabilities that aren't part of a bug bounty program takes a large amount of either courage or ignorance. Until there are protections in place for a given jurisdiction, far safer to leak it anonymously or just stay quiet. I was surprised that GDPR didn't contain any sort of protections for security researchers. The fines collected are hefty enough they could easily run a very successful bug bo…
I agree with you, but it isn't a clear cut issue. Attacking a server right now comes with some legal risk, which is a deterrent to some. It's impossible to tell white hats from black. If it were paired with a law that made it a felony to resell vulns to third parties then it would be much more robust.