Earlier quoted context omitted.
> Before, one collaborator had them in a chat sneering about chattr "Wow this thing looks crappy" > checking their Javascript "I wonder if it is crappy" > then getting a GUI pwn tool for firebase. "Huh, it seems crappy. Let's just check to be sure" > with a disclosure policy of 'we emailed them once and they fixed ...' "Well, this thing is really crappy. we don't want to harm people. Let's tell them about how crappy…
Note I'm not claiming disclosure is bad , but rather, this is a copy of a copy of a copy of a copy of a copy of a copy of how professionals handle these situations, to the point there's nothing left except the "1) pick a target 2) email them 3) write a blog post when fixed" parts.
I pwned half of America's fast food chains simultaneously
441–450 of 513 posts
Re: I pwned half of America's fast food chains simultaneously
#442Re: I pwned half of America's fast food chains simultaneously
#443This is my problem with the whole architecture of FE -> DB. Without a middle server layer, things like token storage, authentication, and other things become really easy to screw up.
It's... way too successful internally, lol, because we have a lot of permissions and privileges to manage now. And now we have to figure out good ways to assign these permissions to people more efficiently.
But that's a better problem than a GDPR relevant data breach, to be honest.
Re: I pwned half of America's fast food chains simultaneously
#444Re: I pwned half of America's fast food chains simultaneously
#445Earlier quoted context omitted.
Weird, I don't feel nearly as touchy about some ones and zeros on a computer as I do my physical body's safety, without which I would not exist.
OK, make the comparison more direct, then. Say you have a filing cabinet with all of your important and \ or embarrassing documents in it. Are you OK with houseguests giving the handle a little wiggle when they come over to check if its locked? What about the neighborhood kids?
If i leave that filing cabinet in the middle of Times Square in Manhattan (which has an insane amount of foot traffic every day), then yes, I would expect plenty of people to give it a little wiggle to check if it’s locked. And I would be rightfully given a lot of questionable looks for complaining that passerbys stop to check it out or give it a wiggle.
Having your service on the internet is not the same as having a filing a cabinet in your house. I think that the Times Square analogy is even underplaying it, given that on the internet, your audience is many many magnitudes larger and more remote/anonymous.
On the other hand, if I had a private VLAN (that wasn’t exposed to the internet) on my home network, then I would be definitely annoyed if my houseguests would try and pentest it without asking.
Re: I pwned half of America's fast food chains simultaneously
#446Earlier quoted context omitted.
It’s an ineffective tool if your goal is change.
Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.
Shame is so effective when it actually lands that you can never fully deprogram it -- I will live with my Catholic guilt for the rest of my life.
Re: I pwned half of America's fast food chains simultaneously
#447From Eva’s post: > we didnt know much about firebase at the time so we simply tried to find a tool to see if it was vulnerable to something obvious and we found firepwn, which seemed nice for a GUI tool, so we simply entered the details of chattr's firebase Genuinely curious (I’ve no infosec experience), wouldn’t there be a risk that a tool like this could phone home and log everything you find while doing research?
Plus as part of the pentesting I watch the network stack in Firefox sometimes so I would tell if it was trying to exfiltrate date
Re: I pwned half of America's fast food chains simultaneously
#448Earlier quoted context omitted.
Note I'm not claiming disclosure is bad , but rather, this is a copy of a copy of a copy of a copy of a copy of a copy of how professionals handle these situations, to the point there's nothing left except the "1) pick a target 2) email them 3) write a blog post when fixed" parts.
What other steps have their ever been? Getting a CVE?
They did do the most significant signifiers to a layman: hack, write a blog post, wait until fix before talking about it.
I'd have a better explanation for picking a target, avoid having competing versions of the story out there, avoid having one version having you targeting a company while another claims it was a general sweep, get the collaborators together and at least credit them in all versions of you can't get people to agree to write one post, avoid exaggerating, avoid claiming you hacked other companies, and add a contact or two before releasing the vulnerability.
Comparing a Project Zero blog post to this is a good idea, I went off of memory.
As it stands it sure sounds like some people were hanging out in Discord, scrolled through some JS in dev tools and / or ran some automated script against a site, then got puzzled and downloaded a pwner GUI to do the hard part, saw a fix, then rushed to write blog posts and stepped on each other's toes, one wildly exaggerating who was hacked while covering up details, another being honest but had ~0 idea of what they were supposed to say
Re: I pwned half of America's fast food chains simultaneously
#449Earlier quoted context omitted.
> No rules or laws that require it It will just be FTC knocking on your door…
FTC will come knocking at your door even if you do pass an external audit and have Soc2/soc1/iso certification. Equifax is an example.
Re: I pwned half of America's fast food chains simultaneously
#450Earlier quoted context omitted.
Yes, the CTO hopefully has nothing to do with lower level operations like that. But if they get a public burn they're going to issue a decree that will be addressed.
No what I mean is that it won’t even be in their org. The public website will belong to the head of corporate communications or some similar chief bullshit officer