Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

451–460 of 466 posts

Re: I found a vulnerability. they found a lawyer

#451
post #274

Earlier quoted context omitted.

How do you generate the email addresses? Do you run your own e-mail server or do you use a third-party service?

If you’re on Gmail, there’s “plus addressing” - this allows you to append any term after your email - and then sort accordingly. So if your Gmail is foo.bar@gmail.com you can use foo.bar+servicename@gmail.com and the mail will still end up in your mailbox. Then you can create a rule that sorts incoming mails accordingly.

I find plus addressing unreliable. Not all websites allow you to have the +.

Re: I found a vulnerability. they found a lawyer

#453

I truly don’t understand why you decided to take the stance of setting them deadlines and disclosing the vulnerability if they miss them. I understand you had good intentions, but I also can see how this can look like unnecessary escalation and even like blackmail to someone outside the industry, like an insurance manager or a lawyer. I agree that disclosing a vulnerability in a major web browser or in a protocol mak…

It's not only about pressure, but also telling all the people whose data can be read AKA the public.

And still it's also about the pressure. I was found a pretty bad injections/XSS in an online banking website. Told them, got no response. After waiting blogged about it (without specifying what he actual issue is). Then someone contacted me and said I need to take down the wrong information. Send back a PoC and only then they started fixing it. In the meanwhile every customer could have gotten emails stealing their login data.

Re: I found a vulnerability. they found a lawyer

#454
post #125

Earlier quoted context omitted.

That could be a hack or something the company sold to a third party.

During a property search for rentals in the UK I created a throwaway alias email (to my regular account) as I did not really trust them with my data. This was not for those requiring me to provide credit check papers and name of children (!! yes, you read it right, name of children!) at the very first contact in their web form just to start conversation about if there is viewing ability or not, and then perhaps sched…

The absolute hell that is looking for a place to live in the UK. I remember having to submit a copy of my passport to one of those letting agencies. I don't even know how they process it and how it is stored, but I am convinced it's just stored on some random personal OneDrive at this point.

Re: I found a vulnerability. they found a lawyer

#455

Earlier quoted context omitted.

>It is countries like US where anyone can call themselves whatever they feel like that have devalued our profession. How have they devalued the profession when the labor of that professions is worth the most in the US?

If I start calling "bananas" "apples" then I devalue the meaning of the word "apple". You can't differentiate which I'm referring to. If I start calling "bananas" "apples" the price at the store doesn't change. I think you don't understand what the word "value" means. You understand one meaning, but it has more than one.

> If I start calling "bananas" "apples" then I devalue the meaning of the word "apple". You can't differentiate which I'm referring to.

In French, potatoes are called what translates to English as "apple of the earth". Nobody confuses a pomme de terre with an apple, because nobody calls a potato an apple without the adjective attached.

That's what the additional adjective as part of the title is for; like how apples and potatoes are vaguely related in that they're both plant-based food but are otherwise entirely different; turning "software engineer" into a compound term that has the extra word is specifically to differentiate it from expectations of it not having the extra word.

Software engineering is legitimately engineering going by the etymological meaning of engineering; but it's not really one going by some of the other (mostly orthogonal) things we've layered onto the term in many contexts over the years. It's creation through ingenuity. It has as much claim to the word as part of its title as any other usage of the word does.

Re: I found a vulnerability. they found a lawyer

#456

Earlier quoted context omitted.

It's kinda wild that you don't need to be a professional engineer to store PII. The GDPR and other frameworks for PII usually do have a minimum size (in # of users) before they apply, which would help hobbyists. The same could apply for the licensure requirement. But also maybe hobbyists don't have any business storing PII at scale just like they have no business building public bridges or commercial aircraft.

GDPR doesn't have any minimum size before applying. There's a household exemption for personal use, but if you have one external user, you're regulated.

Thanks for clarifying. I was thinking of the CCPA which does have some revenue or user count minimums.

Re: I found a vulnerability. they found a lawyer

#457
post #2

I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…

Corporate security is best understood as a marketing function; compliance enables sales even if (especially if) it undermines genuine security.

Re: I found a vulnerability. they found a lawyer

#458
post #158

> No exploits, no buffer overflows, no zero-days. Just a login form, a number, and a default password that was set for each student on creation. ai;dr This is AI slop. Use your own words! I would rather read the original prompt!

This garbage actually got over 900 upvotes. Crazy.

I already suspected it was AI written based in the super-cringe title, and a cursory look at the content confirmed my suspicion. Cookie-cutter basic ai writing as it gets.

Re: I found a vulnerability. they found a lawyer

#459

Earlier quoted context omitted.

He downloaded data of multiple users

Yes, that’s the PoC. Seemingly it could have been scoped tighter. But complaining about the methodology your (successful, free, overdue ) penetration test is wild.

Well done, defender of hill, protector of the mound.

Re: I found a vulnerability. they found a lawyer

#460

Earlier quoted context omitted.

I understand why the author thought that way, but showing up with private data that the company is obligated to protect complicates things quite a lot more. I've dealt with security issues a number of times over my career, and I'm genuinely unsure what my legal obligations would be in response to an email like this. He says the company has committed "multiple GDPR violations"; is there something I need to say in resp…

> is there something I need to say in response to preserve any defenses the company may have or minimize the fines? Company should have SOPs for this.

It should, and that SOP is essentially always going to say something like "file a tracking ticket and immediately forward to legal for all further conversation". It sounds like the author really was just trying to be a helpful guy, but the typical person who emails a company about "multiple GDPR violations" is absolutely trying to get them in trouble, and a random developer with no comms training risks putting their foot in their mouth in legally consequential ways.
Post reply on HN