Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

71–80 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#71
post #57

Earlier quoted context omitted.

> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…

[flagged]

Does the CEO know what?

Re: 'Impossible-to-hack' security turns out to be no security

#72
post #23

Earlier quoted context omitted.

> they're unavailable for the foreseeable future on higher priorities Need I respond to that?

If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#73

Earlier quoted context omitted.

[flagged]

I hope you are not in a client-facing role, as you appear to lack the ability to understand another's perspective. Security researchers rely on publications and recognition from security platforms to build their CVs. That's what he wanted. Think about it that way if everyone was a n idiot like the CEO of this ordeal we would have way less white hats.

I am in a very client facing role, and my clients quite like me. You know nothing about me, and you are completely misunderstanding this situation. I am holding the researcher accountable to how they comported themselves in this interaction instead of dick-riding a fellow hacker I actually do understand what security researchers usually want out of such an interaction. Where things fall apart is that the CEO does _not_ know, then the researcher punished them for their behavior and accessed their data, likely illegally. I am trying to communicate why they got a bad response, and why their response to the bad response was bad. I probably shouldn't have mentioned blackmail because people are focusing on that. I'm mainly trying to say "it reads like it could be blackmail" and they'd have a friendlier interaction with just a little more info upfront.

Re: 'Impossible-to-hack' security turns out to be no security

#75
post #61

Earlier quoted context omitted.

I'm lost, what are you referring to? The author references the claim by the CEO, and then goes on to prove it was a lie. That's a very common linguistical pattern.

The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.

To which the CEO was rude and dismissive and threatening. Which is often a sign of having something to hide. I assume the author decided to then verify if the threats were made from a position of strength or weakness.

I read his email as a polite gesture, giving them a chance to request more time. I'm still confused as to what parts you're missing. Are you trying to imply something, or do you really not understand that people can lie and withhold information?

Re: 'Impossible-to-hack' security turns out to be no security

#76

Earlier quoted context omitted.

My paycheck depends on reconciling myself to it. Should I quit possibly my last job before retirement in a bleak job market to protest my manager's decision to protect her job and mine by putting revenue before protecting jane@doe.com's login from being stolen for the Nth time? Am I the bad guy?

It's not my place to define your ethics for you. I'm pointing out so any other readers can be innoculated from accidentally stumbling into this ethical minefield. I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing. No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.

I'm a participant in sub-criminal negligence rather than stealing. I'd call that a lesser offense. And it's a failure I have mitigated by working to protect the data. I can't claim innocence, but I sleep OK.

Re: 'Impossible-to-hack' security turns out to be no security

#77
post #65
post #37

I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…

TBH it sounds like he exfil'ed / downloaded the database before reporting.

Isn't this a jurisdictional crime that a well connected CEO could get him in a lot of trouble for?

Re: 'Impossible-to-hack' security turns out to be no security

#78

The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.

The author is not acting in a professional role here. He, in his own time, discovered a pretty serious exposure of information and politely informed them. They decided to not be polite in return. He responded in the same tone as them. There was never any professional obligation, nor any obligation for the author to inform them of their breach at all, nor was there any obligation to give them time to notify clients be…

To double down here, the author did the correct thing by using their snarkiness.

If someone who in theory is a professional (the company that left all of this in the open) responds in an unprofessional way from the start - you are done using professional tone. That tool isn't producing results. Stop using that tool.

The goal is not to model perfect manners - it is to bring attention to a breach so it can be remedied. The author understands this and has acted so to achieve this result.

Re: 'Impossible-to-hack' security turns out to be no security

#79

Earlier quoted context omitted.

Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.

I see you read and understood the researcher's emails as well as the CEO did, then...I'm not assuming anything, I'm repeating what was said. Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?

No, I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have responded that way. I am also not letting the researcher off the hook for responding to the CEOs response the way they did.

Re: 'Impossible-to-hack' security turns out to be no security

#80
post #57

Earlier quoted context omitted.

> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…

[flagged]

While it's hard to convey "this is 100% not a scam" without sounding suspicious, in the example of this article they tried to get it across at the very start. It's on the CEO for becoming hostile to someone who asked for nothing in return and wasn't making any threat.
Post reply on HN