Earlier quoted context omitted.
I assume the author isn't lying when they acknowledged that it had been.
I'm lost, what are you referring to? The author references the claim by the CEO, and then goes on to prove it was a lie. That's a very common linguistical pattern.
'Impossible-to-hack' security turns out to be no security
61–70 of 157 posts
Re: 'Impossible-to-hack' security turns out to be no security
#62Earlier quoted context omitted.
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…
[flagged]
Re: 'Impossible-to-hack' security turns out to be no security
#63Earlier quoted context omitted.
I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.
I think the data he discloses in the post is the one that he got before getting in contact with the company. He does this in order to prove that the database was accesible to anyone on the internet, instead of the "no breach at all" claimed on the response email.
Re: 'Impossible-to-hack' security turns out to be no security
#64Earlier quoted context omitted.
That's...not what blackmail is. Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly. If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.
Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.
Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?
Re: 'Impossible-to-hack' security turns out to be no security
#65I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…
Re: 'Impossible-to-hack' security turns out to be no security
#66Re: 'Impossible-to-hack' security turns out to be no security
#67The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.
I was also ready to chalk this up to "Yet another security researcher needs to learn how to play well with others..." but the moronic and indigent response from "Sean" makes it clear who's wrong here. Imagine an alternate universe where "Sean" wasn't so aggressively stupid, and instead replied: "Thanks, JayeLTee, we took the database down while we do an audit. We don't think there were any access, and we would rather…
The company did reach out and said something similar, I held my publication for months months waiting for a reply which they said they would send and ended up finding out their were filing breach notifications to multiple states and never said anything back to me.
Re: 'Impossible-to-hack' security turns out to be no security
#68Earlier quoted context omitted.
why does it sound like you're defending the argument of; I couldn't act ethically because I had to make money.
My paycheck depends on reconciling myself to it. Should I quit possibly my last job before retirement in a bleak job market to protest my manager's decision to protect her job and mine by putting revenue before protecting jane@doe.com's login from being stolen for the Nth time? Am I the bad guy?
I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing.
No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.
Re: 'Impossible-to-hack' security turns out to be no security
#69The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.
Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.
A+ - And thanks for trying to keep folks like this honest!
Re: 'Impossible-to-hack' security turns out to be no security
#70Earlier quoted context omitted.
[flagged]
> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…