Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

81–90 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#81

Earlier quoted context omitted.

[flagged]

As I read it, he wants them to secure their systems and fulfill their legal and ethical obligations to their customers and regulators by notifying them of the breach. I'm not sure what you find ambiguous or confusing.

There are 2 sides to every story, with the other side being a potential business opportunity. /s

Re: 'Impossible-to-hack' security turns out to be no security

#82
post #57

Earlier quoted context omitted.

> If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in…

[flagged]

> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […]

This seems like a good hint.

Re: 'Impossible-to-hack' security turns out to be no security

#83
post #63

Earlier quoted context omitted.

I think the data he discloses in the post is the one that he got before getting in contact with the company. He does this in order to prove that the database was accesible to anyone on the internet, instead of the "no breach at all" claimed on the response email.

He writes as if he has access to large quantities of data after the CEO responded to him, which implies that it was after the exposed database was fixed, as the author acknowledges in the email he sent to the CEO.

No I did not query the database after it was exposed.

The information I had was from when the database was publicly exposed.

I don't want to be too specific about the links for the files as I don't know if others accessed this information and could exploit it but they had the website path to download the files exposed on the database, you just needed to know what to add to it, I tried a few things from the information I had and found out they worked.

I would of probably skipped over this, but after their response I wondered if there was more to it.

The files were not stored on the database, they were on a cloud storage but that link made it so no authentication was required to access them (not an expert but would say some hard coded access keys or something similar).

Re: 'Impossible-to-hack' security turns out to be no security

#84

Earlier quoted context omitted.

It's not my place to define your ethics for you. I'm pointing out so any other readers can be innoculated from accidentally stumbling into this ethical minefield. I'm not telling you stealing bread so your family doesn't starve is unethical, I'm pointing out it's stealing. No idea if you're the bad guy, but you're not the ~~good guy~~ hero, no.

I'm a participant in sub-criminal negligence rather than stealing. I'd call that a lesser offense. And it's a failure I have mitigated by working to protect the data. I can't claim innocence, but I sleep OK.

It's also not about bread, because that was just an analogy.

I would sleep ok too, until something bad happened and people I had a responsibility to protect got hurt. Then I wouldn't sleep so well... Turns out humans are really bad at risk calculations.

Re: 'Impossible-to-hack' security turns out to be no security

#85

It looks like the CEO is both clueless and his reports are also probably misleading him. Whoever looked into the security problem probably saw the extent of it. This possibly got downplayed when reported back to the CEO. However rude, the CEO had little reason to lie about the extent of the problem towards the security researcher.

I imagine the conversation between the CEO and his reports included something about "it's no biggie, the passwords were hashed using bcrypt, that's like irreversible encryption" without contextualizing that and mentioning that plaintext auth tokens were also exposed.

Re: 'Impossible-to-hack' security turns out to be no security

#86
post #61

Earlier quoted context omitted.

The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.

To which the CEO was rude and dismissive and threatening. Which is often a sign of having something to hide. I assume the author decided to then verify if the threats were made from a position of strength or weakness. I read his email as a polite gesture, giving them a chance to request more time. I'm still confused as to what parts you're missing. Are you trying to imply something, or do you really not understand th…

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#87

Earlier quoted context omitted.

I hope you are not in a client-facing role, as you appear to lack the ability to understand another's perspective. Security researchers rely on publications and recognition from security platforms to build their CVs. That's what he wanted. Think about it that way if everyone was a n idiot like the CEO of this ordeal we would have way less white hats.

I am in a very client facing role, and my clients quite like me. You know nothing about me, and you are completely misunderstanding this situation. I am holding the researcher accountable to how they comported themselves in this interaction instead of dick-riding a fellow hacker I actually do understand what security researchers usually want out of such an interaction. Where things fall apart is that the CEO does _no…

He is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.

Re: 'Impossible-to-hack' security turns out to be no security

#88

Earlier quoted context omitted.

[flagged]

> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […] This seems like a good hint.

I can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at.

A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling something or scamming me doesn't actually tell me what they want, and it does not provide me with enough information to know that they are not, in fact, scamming me. It just lets me know they don't want me to think I am being scammed.

Re: 'Impossible-to-hack' security turns out to be no security

#89
post #63

Earlier quoted context omitted.

I think the data he discloses in the post is the one that he got before getting in contact with the company. He does this in order to prove that the database was accesible to anyone on the internet, instead of the "no breach at all" claimed on the response email.

He writes as if he has access to large quantities of data after the CEO responded to him, which implies that it was after the exposed database was fixed, as the author acknowledges in the email he sent to the CEO.

[deleted]

Re: 'Impossible-to-hack' security turns out to be no security

#90
post #15

Not very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.

Agree. "You're not wrong, Walter, you're just an asshole!" Best case scenario, CEO just got an annoying distraction that was a credible enough threat they had to waste time investigating. Worst case they had a breach and someone is extorting or hacking them. Some grace on the part of the researcher is warranted IMO, despite the amateur handling by the CEO. No one looks good here.

The OP/researcher looks fine. They tried twice to help someone who would eventually prove they didn't deserve they help. They then, after being disrespected, still upheld all the ethical requirements from a security researcher, redacting sensitive information. The CEO looks like a twat waffle, but the researcher is clean, and just looks like someone intolerant of overt disrespect. Being willing to stand up to bullies is admirable, not disheartening.
Post reply on HN