Earlier quoted context omitted.
How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?
If you’re on Gmail, there’s “plus addressing” - this allows you to append any term after your email - and then sort accordingly. So if your Gmail is foo.bar@gmail.com you can use foo.bar+servicename@gmail.com and the mail will still end up in your mailbox. Then you can create a rule that sorts incoming mails accordingly.
I found a vulnerability. they found a lawyer
451–460 of 466 posts
Re: I found a vulnerability. they found a lawyer
#452"Don't shoot the messenger. The person reporting the bug is not your enemy. The bug is."
Re: I found a vulnerability. they found a lawyer
#453I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…
And still it's also about the pressure. I was found a pretty bad injections/XSS in an online banking website. Told them, got no response. After waiting blogged about it (without specifying what he actual issue is). Then someone contacted me and said I need to take down the wrong information. Send back a PoC and only then they started fixing it. In the meanwhile every customer could have gotten emails stealing their login data.
Re: I found a vulnerability. they found a lawyer
#454Earlier quoted context omitted.
That could be a hack or something the company sold to a third party.
During a property search for rentals in the UK I created a throwaway alias email (to my regular account) as I did not really trust them with my data. This was not for those requiring me to provide credit check papers and name of children (!! yes, you read it right, name of children!) at the very first contact in their web form just to start conversation about if there is viewing ability or not, and then perhaps sched…
Re: I found a vulnerability. they found a lawyer
#455Earlier quoted context omitted.
>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?
If I start calling "bananas" "apples" then I devalue the meaning of the word "apple". You can't differentiate which I'm referring to. If I start calling "bananas" "apples" the price at the store doesn't change. I think you don't understand what the word "value" means. You understand one meaning, but it has more than one.
In French, potatoes are called what translates to English as "apple of the earth". Nobody confuses a pomme de terre with an apple, because nobody calls a potato an apple without the adjective attached.
That's what the additional adjective as part of the title is for; like how apples and potatoes are vaguely related in that they're both plant-based food but are otherwise entirely different; turning "software engineer" into a compound term that has the extra word is specifically to differentiate it from expectations of it not having the extra word.
Software engineering is legitimately engineering going by the etymological meaning of engineering; but it's not really one going by some of the other (mostly orthogonal) things we've layered onto the term in many contexts over the years. It's creation through ingenuity. It has as much claim to the word as part of its title as any other usage of the word does.
Re: I found a vulnerability. they found a lawyer
#456Earlier quoted context omitted.
It's kinda wild that you don't need to be a professional engineer to store PII. The GDPR and other frameworks for PII usually do have a minimum size (in # of users) before they apply, which would help hobbyists. The same could apply for the licensure requirement. But also maybe hobbyists don't have any business storing PII at scale just like they have no business building public bridges or commercial aircraft.
GDPR doesn't have any minimum size before applying. There's a household exemption for personal use, but if you have one external user, you're regulated.
Re: I found a vulnerability. they found a lawyer
#457I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…
Re: I found a vulnerability. they found a lawyer
#458> No exploits, no buffer overflows, no zero-days. Just a login form, a number, and a default password that was set for each student on creation. ai;dr This is AI slop. Use your own words! I would rather read the original prompt!
I already suspected it was AI written based in the super-cringe title, and a cursory look at the content confirmed my suspicion. Cookie-cutter basic ai writing as it gets.
Re: I found a vulnerability. they found a lawyer
#459Earlier quoted context omitted.
He downloaded data of multiple users
Yes, that’s the PoC. Seemingly it could have been scoped tighter. But complaining about the methodology your (successful, free, overdue ) penetration test is wild.
Re: I found a vulnerability. they found a lawyer
#460Earlier quoted context omitted.
I understand why the author thought that way, but showing up with private data that the company is obligated to protect complicates things quite a lot more. I've dealt with security issues a number of times over my career, and I'm genuinely unsure what my legal obligations would be in response to an email like this. He says the company has committed "multiple GDPR violations"; is there something I need to say in resp…
> is there something I need to say in response to preserve any defenses the company may have or minimize the fines? Company should have SOPs for this.