Live data from Hacker News

Hacking into an insurance company by exploiting their premium calculator

eaton-works.com

81–90 of 113 posts

Re: Hacking into an insurance company by exploiting their premium calculator

#81

It's a bit hard to imagine this specific problem existing outside of the Microsoft ecosystem. I can very well imagine that there are loads of corporate resources provided through a valid O365 account that are useful for targeted hacks -- heck, the metadata in the corporate directory alone is going to be useful to a ne'er-do-well. I really can't believe they haven't changed the password. I wonder what part of their wo…

> I really can't believe they haven't changed the password. I wonder what part of their workflow that breaks?

Probably their single sign-on. They probably only have the one company password, shared. That's the single sign-on!

Re: Hacking into an insurance company by exploiting their premium calculator

#82

I am not Indian but I work for a large Tata like IT firm. This hit way too close to home. There a lot of cultural issues here that comes down to management being rewarded if things are done cheaply and discouraging any agency or self-realization by the developers. If I saw this in the US, I’d walk out. They literally don’t have that option as there’s a 90 day salary clawback if they do. Some general thoughts: - Most…

> a 90 day salary clawback if they ‘leave their job’

This is what you get, ladies and gentlemen, without unions and labour right.

Coming soon, to us too.

Re: Hacking into an insurance company by exploiting their premium calculator

#83

Wild-assed guess before I read this: in their greed for personal information, they took what should be a purely client-side scripted job into something that connects to the back end. Edit: Yup! Instead of just doing calculations, it involved some e-mail workflow. > The password could be used to log into the “noreplyeicher@ttibi.co.in” Microsoft email account. I'm surprised this is literally true as described. The act…

> The actual browser itself makes the actual SMTP connection to the Microsoft e-mail host! This is not generally possible, browsers cannot make arbitrary socket connections in the way that would be required to reliably communicate with an SMTP server. The article makes clear that the frontend is calling a poorly-coded email-sending API implemented as an HTTP endpoint.

I see. That's what I would have thought so I was scratching my head; that lack of sandboxing would turn all browsers into horrible attack vehicles, rendering botnets obsolete.

Re: Hacking into an insurance company by exploiting their premium calculator

#84
post #64

Earlier quoted context omitted.

Yes and no. AFAIK it provides controls to ensure a certain level of privacy (with serious flaws IMO). AFAIK it does not do much, if anything to punish breaches caused by incompetence. I have not heard of of any cases where companies were fined for breaches. Not the whole of Europe. The EEA and the UK has legislation based on it what has not yet diverged significantly.

https://www.enforcementtracker.com/ Here's a long list of them

Not really. That links to a list of all enforcement actions.

If you search for "technical" you get "organisational and technical measures", and most are organisational rather than technical.

If you search by the word "hack" which seems to be the seems to be the usual terminology used there for vulnerabilities being exploited. There are 18 of these of 2182 entries. Not even one per EU country since 2018. Given how common data breaches are it is a tiny number.

Most of them do not give details, but those that do suggest the fines are levied only in extreme cases (for example allowing unauthenticated internet access to medical data: https://www.enforcementtracker.com/ETid-1015 ) or for certain types of failure (e.g. not having MFA). Most do not give details.

its better than I thought, but still far too little, and all the cases where any details are given it is for only a very narrow range of failures.

Re: Hacking into an insurance company by exploiting their premium calculator

#85

So crazy that things like this still happen in production. I mean, maybe I have survivorship bias (we never hear about the companies that don't have security flaws, or the hundreds of APIs that are completely secure), but it should be super easy to make a site that is secure. Even I know how to do it. It shouldn't be that hard to find people who know how to make secure sites.

You are either young or don't know any better. All major companies have bug bounties program and consistently, every few weeks, payout CRITICAL level bounties, as in attacker managed to get full server/access to any account etc. Security breaches are just a matter of time. Who is to blame is debatable, since being a criminal and breaking and stealing (into digital or physical business) is against the law.

> Who is to blame is debatable, since being a criminal and breaking and stealing

Not debatable at all - if you get mugged, it’s the criminals fault.

But if you trust your money to a bank, they leave the safe unlocked, and your money is gone, it’s their fault. That literally the whole point of a bank.

Same with your data - when it stolen, it usually the company’s fault - after all if there is no security, sooner or later it will happen.

Re: Hacking into an insurance company by exploiting their premium calculator

#86

I am not Indian but I work for a large Tata like IT firm. This hit way too close to home. There a lot of cultural issues here that comes down to management being rewarded if things are done cheaply and discouraging any agency or self-realization by the developers. If I saw this in the US, I’d walk out. They literally don’t have that option as there’s a 90 day salary clawback if they do. Some general thoughts: - Most…

> a 90 day salary clawback if they ‘leave their job’ This is what you get, ladies and gentlemen, without unions and labour right. Coming soon, to us too.

> This is what you get, ladies and gentlemen, without unions and labour right.

Are you speaking of the EU? The US has at-will employment and most software developers are not unionized.

Re: Hacking into an insurance company by exploiting their premium calculator

#87
What if developers in other countries make more by putting obvious back doors in and selling to their respective government ?

Maybe applications that take personal and sensitive data should require a clearance. Companies that perform pen tests should also require clearances.

Re: Hacking into an insurance company by exploiting their premium calculator

#88

I am not Indian but I work for a large Tata like IT firm. This hit way too close to home. There a lot of cultural issues here that comes down to management being rewarded if things are done cheaply and discouraging any agency or self-realization by the developers. If I saw this in the US, I’d walk out. They literally don’t have that option as there’s a 90 day salary clawback if they do. Some general thoughts: - Most…

You've explained my work to close to home, not Indian, not large TataMSP but just general large enterprise.

To a T.

Re: Hacking into an insurance company by exploiting their premium calculator

#89
post #65

There was a car dealer (Honda affiliate) I had the unfortunate "pleasure" of dealing with back in the mid-late 2000s that stored finance applications by numeric incrementing ids. I never did report it, but I was able to pull up a bunch of sensitive info (SSN, DOB, names, addresses) on folks living in NJ. (I didn't report it because bug bounties weren't really a thing back then and the CFAA was). I managed to get my a…

There is a huge missing niche for trusted intermediaries of identity information. We’ve been working on this at https://cerebrum.com in a different niche (background checks), but this comment just triggered a slew of ideas…

Lol 0/10 marketing push.

Btw, schedule is spelt with a c after the s.

Re: Hacking into an insurance company by exploiting their premium calculator

#90

Earlier quoted context omitted.

> a 90 day salary clawback if they ‘leave their job’ This is what you get, ladies and gentlemen, without unions and labour right. Coming soon, to us too.

> This is what you get, ladies and gentlemen, without unions and labour right. Are you speaking of the EU? The US has at-will employment and most software developers are not unionized.

Is it legal to have a 90 day salary clawback (not a signing bonus clawback, just salary clawback for quitting) in the US?
Post reply on HN