Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

51–60 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#51
post #49

Earlier quoted context omitted.

Did you not consider the CEO would just lie about fixing something?

I assume the author isn't lying when they acknowledged that it had been.

I'm lost, what are you referring to? The author references the claim by the CEO, and then goes on to prove it was a lie.

That's a very common linguistical pattern.

Re: 'Impossible-to-hack' security turns out to be no security

#52

Earlier quoted context omitted.

I don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.

Sure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards. Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.

I can call myself a bicycle but I don't have any wheels.

Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.

Re: 'Impossible-to-hack' security turns out to be no security

#54
post #46

Earlier quoted context omitted.

Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#55

Earlier quoted context omitted.

That's...not what blackmail is. Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly. If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.

Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#56

Earlier quoted context omitted.

If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.

why does it sound like you're defending the argument of; I couldn't act ethically because I had to make money.

My paycheck depends on reconciling myself to it. Should I quit possibly my last job before retirement in a bleak job market to protest my manager's decision to protect her job and mine by putting revenue before protecting jane@doe.com's login from being stolen for the Nth time? Am I the bad guy?

Re: 'Impossible-to-hack' security turns out to be no security

#57

Earlier quoted context omitted.

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…

[flagged]

>If you don't want money and it's not a scam, why are you emailing them?

It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple.

When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in return. My hobby is security, my payment is knowing that I helped thousands of people out.

>I would NOT be happy to receive such an email.

You would rather just continue to expose your customer's information? Interesting... I don't think you have the ethical high ground here, if that is your position.

Re: 'Impossible-to-hack' security turns out to be no security

#58

Earlier quoted context omitted.

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…

[flagged]

As I read it, he wants them to secure their systems and fulfill their legal and ethical obligations to their customers and regulators by notifying them of the breach.

I'm not sure what you find ambiguous or confusing.

Re: 'Impossible-to-hack' security turns out to be no security

#59
post #46

Earlier quoted context omitted.

Step 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You no…

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

I think the data he discloses in the post is the one that he got before getting in contact with the company. He does this in order to prove that the database was accesible to anyone on the internet, instead of the "no breach at all" claimed on the response email.

Re: 'Impossible-to-hack' security turns out to be no security

#60

Earlier quoted context omitted.

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…

[flagged]

I hope you are not in a client-facing role, as you appear to lack the ability to understand another's perspective. Security researchers rely on publications and recognition from security platforms to build their CVs. That's what he wanted. Think about it that way if everyone was a n idiot like the CEO of this ordeal we would have way less white hats.
Post reply on HN