Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

421–430 of 466 posts

Re: I found a vulnerability. they found a lawyer

#421
Almost makes one want to anonymously respond:

Oh, I see that you're cunts. Well that's your choice. My choice, in response, then, is to notify certain corners of the dark web how you approach security. I'm sure they'll find something else, and don't worry - they won't bother you with a disclosure.

Re: I found a vulnerability. they found a lawyer

#422

Earlier quoted context omitted.

I read that post as him talking about their company, in the sense of the company they were working for. If that was the case, then an exploit of an unfixed security issue could very much affect them either just as part of the company if the fallout is enough to massively harm business, or specifically if they had not properly documented their concerns so “we didn't know” could be the excuse from above and they could…

No i mean, 'a company you own'. At the end of the day you're just a worker getting paid to produce output. cross your I's and dot your T's and whatever else and then clock out.

Even keeping to the 9-to-5 you can make your displeasure at being insecure know. And if the security issues come to a head and it damages the company, you could be out on your arse if the company dies or needs to cut costs. In the current environment is a lot worse than it would have been five or ten years ago, and that same environment likely limits the “I don't like it so I'll just leave” options that are available.

I'm lucky, I have options¹ and it is looking like I don't need them²³, but many are not so lucky.

--------

[1] I made serious enquiries about a couple of them when the recent take-over was announced, just in case…

[2] the new corporate masters seem to be doing more than talking the talk, and on quality matters we were already doing things right and the new overlords don't appear to have any desire to change that

[3] well, at least not on these matters, there are a few cultural changes that I need to get used to or get away from, largely due to being a bigger organisation now, but they aren't wrong just a little further from my preference than things were before.

Re: I found a vulnerability. they found a lawyer

#423

Earlier quoted context omitted.

> You don't need to retrieve other people's data to demonstrate the vulnerability. If you’re reporting to a nontechnical team…which sometimes you are…sometimes you do?

Absolutely not. That's not your concern nor your problem. They're perfectly capable of hiring incident response experts, and companies commonly have cyber insurance that'll pay for it. "Demonstrating" is dumb and means you turn an ordinary disclosure into personal liability for you . Blabbing about it on the internet is just the idiot cherry on the stupid cake.

If your goal is to successfully report and resolve, it is your problem.

Agree otherwise.

In the stories I’ve carefully read, no proof means being ignored by frontline people who are all you can reach,

turning an ordinary disclosure into no disclosure at all.

Re: I found a vulnerability. they found a lawyer

#425
post #331

Earlier quoted context omitted.

If his goal was to keep the data he wouldn't have reported it?

That doesnt necessarily track. He could have stolen the data, then reported it to clear his own name. He did access more data than he needed to prove that there is a likely breach.

His name didn't need clearing.

Re: I found a vulnerability. they found a lawyer

#426
post #388

Earlier quoted context omitted.

I mentioned legal signatures for a reason.

No Software Engineer in title or in real skills will do such a thing.

Sign project contracts with Eng. and find out when liability comes into play.

Re: I found a vulnerability. they found a lawyer

#427
post #390

Earlier quoted context omitted.

That is the thing software can kill, or destroy lives in presence of bugs. Again, sign any legal documents as engineer, and a court visit might turn into reality.

If Oracle, IBM or Microsoft after 50 years, and employing thousands of Software Engineers ...include the standard disclaimers on their Software, I dont think those in title only should make much fuss of the Software Engineer badge...

Only because so far they haven't been called into court as much as they should.

Thankfully stuff like Crowdstrike and Cloudflare are making governments pay attention to industry losses caused by malpractice.

Re: I found a vulnerability. they found a lawyer

#428
post #392

Earlier quoted context omitted.

There are engineers, and there are brick layers. You mean Android's great quality, or Chrome CVEs by the way?

Just because you have an engineering degree doesn't mean your code is of better quality and security than someone without an engineering degree. Signed, someone with an CS engineering degree.

It surely means one has the responsibility to be one as such, having had the education that others have not.

Re: I found a vulnerability. they found a lawyer

#429
post #309

Earlier quoted context omitted.

Professional labour value isn't synonymous with late stage capitalism without ethics or morals. Now if you mean for own much one is willing to sell themselves to late stage capitalism, producing low quality products and entshtification, maybe that is the bang for buck right there.

>Now if you mean for own much one is willing to sell themselves to late stage capitalism The government is the one selling you out to late stage capitalism through rampant inflation, business and fiscal regulations and deregulation, offshoring, and various nefarious policies on housing and labor migration. People just adapt to survive by taking the best paying jobs, since voting clearly doesn't help them. Don't tell…

That is the difference between the US mentality of the winner takes it all that has given us late stage capitalism, entshitification and Trump, and most of the world.

Quality of life and health matters more than anything else.

After a certain point, more money doesn't bring any of that, one is not taking the money into the grave, other than build a mausoleum.

Re: I found a vulnerability. they found a lawyer

#430
post #260

Earlier quoted context omitted.

Interesting that perplexity takes a random Redditor comment as fact...

yeah, so many software engineers are not verify "ai search results". Hey people, llm generated search results aren't reliable, might well have hallucinations. You have to verify anything they say.

My favourite was a search result based ai digest suggesting that during storms large cargo ships could survive for days until eventually 'disappearing'; Perplexed (intended), I followed the citation, the source actually said that the storms themselves would persist for days until disappearing.
Post reply on HN