Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

41–50 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#41

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

I was also ready to chalk this up to "Yet another security researcher needs to learn how to play well with others..." but the moronic and indigent response from "Sean" makes it clear who's wrong here.

Imagine an alternate universe where "Sean" wasn't so aggressively stupid, and instead replied: "Thanks, JayeLTee, we took the database down while we do an audit. We don't think there were any access, and we would rather you not go public about the findings, but it will take us time to check. Please hold off on your publication until [DATE] and we will be in touch."

There. That didn't take much effort! But, no, "Sean" chose belligerence and threats rather than professionalism. I don't know what is wrong with people who just seem to default to "bad attitude" in their communications.

Re: 'Impossible-to-hack' security turns out to be no security

#43

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

The author is not acting in a professional role here.

He, in his own time, discovered a pretty serious exposure of information and politely informed them. They decided to not be polite in return. He responded in the same tone as them.

There was never any professional obligation, nor any obligation for the author to inform them of their breach at all, nor was there any obligation to give them time to notify clients before publication. Those are all courtesies.

This man didn't choose team troll, he responded to team troll in kind.

Re: 'Impossible-to-hack' security turns out to be no security

#44
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful.

Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch.

You noticed that the email implies the security has been perfected. Did you also note that it would be unethical for a professional to blindly convey that false belief.

Re: 'Impossible-to-hack' security turns out to be no security

#45

[flagged]

That's...not what blackmail is. Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly. If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.

Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.

Re: 'Impossible-to-hack' security turns out to be no security

#46
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

Re: 'Impossible-to-hack' security turns out to be no security

#47
post #23

Earlier quoted context omitted.

> they're unavailable for the foreseeable future on higher priorities Need I respond to that?

If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.

why does it sound like you're defending the argument of;

I couldn't act ethically because I had to make money.

Re: 'Impossible-to-hack' security turns out to be no security

#48
post #46

Earlier quoted context omitted.

Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

Did you not consider the CEO would just lie about fixing something?

Re: 'Impossible-to-hack' security turns out to be no security

#49
post #46

Earlier quoted context omitted.

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

Did you not consider the CEO would just lie about fixing something?

I assume the author isn't lying when they acknowledged that it had been.

Re: 'Impossible-to-hack' security turns out to be no security

#50

[flagged]

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…

[flagged]
Post reply on HN