Earlier quoted context omitted.
> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…
[flagged]
'Impossible-to-hack' security turns out to be no security
71–80 of 157 posts
Re: 'Impossible-to-hack' security turns out to be no security
#72Earlier quoted context omitted.
> they're unavailable for the foreseeable future on higher priorities Need I respond to that?
If you know the secret to getting a company to prioritize potential security problems that haven't yet emerged in forty years over meeting payroll, please share.
Re: 'Impossible-to-hack' security turns out to be no security
#73Earlier quoted context omitted.
[flagged]
I hope you are not in a client-facing role, as you appear to lack the ability to understand another's perspective. Security researchers rely on publications and recognition from security platforms to build their CVs. That's what he wanted. Think about it that way if everyone was a n idiot like the CEO of this ordeal we would have way less white hats.
Re: 'Impossible-to-hack' security turns out to be no security
#74Re: 'Impossible-to-hack' security turns out to be no security
#75Earlier quoted context omitted.
I'm lost, what are you referring to? The author references the claim by the CEO, and then goes on to prove it was a lie. That's a very common linguistical pattern.
The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.
I read his email as a polite gesture, giving them a chance to request more time. I'm still confused as to what parts you're missing. Are you trying to imply something, or do you really not understand that people can lie and withhold information?
Re: 'Impossible-to-hack' security turns out to be no security
#76Earlier quoted context omitted.
My paycheck depends on reconciling myself to it. Should I quit possibly my last job before retirement in a bleak job market to protest my manager's decision to protect her job and mine by putting revenue before protecting jane@doe.com's login from being stolen for the Nth time? Am I the bad guy?
It's not my place to define your ethics for you. I'm pointing out so any other readers can be innoculated from accidentally stumbling into this ethical minefield. I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing. No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.
Re: 'Impossible-to-hack' security turns out to be no security
#77I'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access…
TBH it sounds like he exfil'ed / downloaded the database before reporting.
Re: 'Impossible-to-hack' security turns out to be no security
#78The tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.
The author is not acting in a professional role here. He, in his own time, discovered a pretty serious exposure of information and politely informed them. They decided to not be polite in return. He responded in the same tone as them. There was never any professional obligation, nor any obligation for the author to inform them of their breach at all, nor was there any obligation to give them time to notify clients be…
If someone who in theory is a professional (the company that left all of this in the open) responds in an unprofessional way from the start - you are done using professional tone. That tool isn't producing results. Stop using that tool.
The goal is not to model perfect manners - it is to bring attention to a breach so it can be remedied. The author understands this and has acted so to achieve this result.
Re: 'Impossible-to-hack' security turns out to be no security
#79Earlier quoted context omitted.
Yes, "it would be a shame if something were to happen" is also not extortion, because you aren't actually saying you will visit misery upon them, only implying it. The mistake you are making is assuming the researcher wants literally nothing, or that the CEO can know they want literally nothing. I still have no idea what they actually wanted, and whether there was going to be some sort of value extraction.
I see you read and understood the researcher's emails as well as the CEO did, then...I'm not assuming anything, I'm repeating what was said. Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?
Re: 'Impossible-to-hack' security turns out to be no security
#80Earlier quoted context omitted.
> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…
[flagged]