Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

61–70 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#61
post #49

Earlier quoted context omitted.

I assume the author isn't lying when they acknowledged that it had been.

I'm lost, what are you referring to? The author references the claim by the CEO, and then goes on to prove it was a lie. That's a very common linguistical pattern.

The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.

Re: 'Impossible-to-hack' security turns out to be no security

#62

Earlier quoted context omitted.

I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I ev…

[flagged]

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#63
post #46

Earlier quoted context omitted.

I'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.

I think the data he discloses in the post is the one that he got before getting in contact with the company. He does this in order to prove that the database was accesible to anyone on the internet, instead of the "no breach at all" claimed on the response email.

He writes as if he has access to large quantities of data after the CEO responded to him, which implies that it was after the exposed database was fixed, as the author acknowledges in the email he sent to the CEO.

Re: 'Impossible-to-hack' security turns out to be no security

#64

Earlier quoted context omitted.

That's...not what blackmail is. Blackmail is when someone says "do $thing or else". That didn't happen here, implicitly or explicitly. If you're saying the implicit blackmail was "don't be an asshole, or else I'll be unkind when I talk about you later to others", then all of us are always blackmailing one another with every conversation.

Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.

I see you read and understood the researcher's emails as well as the CEO did, then...I'm not assuming anything, I'm repeating what was said.

Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?

Re: 'Impossible-to-hack' security turns out to be no security

#65
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

TBH it sounds like he exfil'ed / downloaded the database before reporting.

Re: 'Impossible-to-hack' security turns out to be no security

#66
It looks like the CEO is both clueless and his reports are also probably misleading him. Whoever looked into the security problem probably saw the extent of it. This possibly got downplayed when reported back to the CEO. However rude, the CEO had little reason to lie about the extent of the problem towards the security researcher.

Re: 'Impossible-to-hack' security turns out to be no security

#67

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

I was also ready to chalk this up to "Yet another security researcher needs to learn how to play well with others..." but the moronic and indigent response from "Sean" makes it clear who's wrong here. Imagine an alternate universe where "Sean" wasn't so aggressively stupid, and instead replied: "Thanks, JayeLTee, we took the database down while we do an audit. We don't think there were any access, and we would rather…

The alternative universe can be seen on this post: https://jltee.substack.com/p/lcptrackercom-lcptracker-inc-se...

The company did reach out and said something similar, I held my publication for months months waiting for a reply which they said they would send and ended up finding out their were filing breach notifications to multiple states and never said anything back to me.

Re: 'Impossible-to-hack' security turns out to be no security

#68

Earlier quoted context omitted.

why does it sound like you're defending the argument of; I couldn't act ethically because I had to make money.

My paycheck depends on reconciling myself to it. Should I quit possibly my last job before retirement in a bleak job market to protest my manager's decision to protect her job and mine by putting revenue before protecting jane@doe.com's login from being stolen for the Nth time? Am I the bad guy?

It's not my place to define your ethics for you. I'm pointing out so any other readers can be innoculated from accidentally stumbling into this ethical minefield.

I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing.

No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.

Re: 'Impossible-to-hack' security turns out to be no security

#69

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.

I thoroughly enjoyed the post and thought your tone was appropriate, entertaining, and kind of kethartic. You didn't call them names, engage in ad hominem, or do anything click-batey. You were understandably irritated at how they talked to you and how they were clearly trying to hide a massive exposure from their users. And then you shredded them with data.

A+ - And thanks for trying to keep folks like this honest!

Re: 'Impossible-to-hack' security turns out to be no security

#70
post #57

Earlier quoted context omitted.

[flagged]

> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…

[flagged]
Post reply on HN