Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

81–90 of 466 posts

Re: I found a vulnerability. they found a lawyer

#82

I think the problem is the process. Each country should have a reporting authority and it should be the one to deal with security issues. So you never report to actual organization but to the security organization, like you did. And they would be more equiped to deal with this, maybe also validate how serious this issue is. Assign a reward as well. So you are researcher, you report your thing and can't be sued or bul…

That’s almost what we already have with the CVE system, just without the legal protections. You report the vulnerability to the NSA, let them have their fun with it, then a fix is coordinated to be released much further down the line. Personally I don’t think it’s the best idea in the world, and entrenching it further seems like a net negative.

Yeah, something like that, nothing too much, just to exclude individual to deal with evil corps

Re: I found a vulnerability. they found a lawyer

#83
post #69

When you are acting in good faith and the person/organization on the other end isn't, you aren't having a productive discussion or negotiation, just wasting your own time. The only sensible approach here would have been to cease all correspondence after their very first email/threat. The nation of Malta would survive just fine without you looking out for them and their online security.

cynical. worst part? best one can do in this situation. can't imagine how I could continue any further interaction with such organization.

Re: I found a vulnerability. they found a lawyer

#85

This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.

You know I had a thoughtful comment written in response to this that wouldn’t post because your comment got flagged to death when I tried to submit it!

Your firebrand attitude is doing a disservice to everyone who takes vibe hunting vibecraft seriously!

The intended audience doesn’t even care that this is LLM-assisted writing. Whether the narrative is affected by AI is second to the technical details. This is technical documentation communicated through a narrative, not personal narrative about someone’s experience with a technical problem. There’s a difference!

What are you in this for?!

Re: I found a vulnerability. they found a lawyer

#86
This is extremely disappointing. The insurer in question has a very good reputation within the dive community for acting in good faith and for providing medical information free of charge to non-members.

This sounds like a cultural mismatch with their lawyers. Which is ironic, since the lawyers in question probably thought of themselves as being risk-averse and doing everything possible to protect the organisation's reputation.

Re: I found a vulnerability. they found a lawyer

#87
post #42

Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.

Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".

well, it is. quick search revealed a name of a certain big player, although there are some other local companies whose policies can be extended to "extreme sports"

https://www.reddit.com/r/scuba/comments/1r9fn7u/apparently_a...

Re: I found a vulnerability. they found a lawyer

#88

Earlier quoted context omitted.

Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".

I'm a diver, DAN is the only company I can name that specialises in diving insurance. Huh, apparently they're registered in Malta, what a coincidence...

checks out with both Perplexity[0] and top Google results

[0]: https://www.perplexity.ai/search/maltese-scuba-diving-insura...

Re: I found a vulnerability. they found a lawyer

#89
post #2

I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…

> These are the sort of things that are supposed to lead to commendations and promotions. Maybe I live in fantasyland. I had a bit of a feral journey into tech, poor upbringing => self taught college dropout waiting tables => founded iPad point of sale startup in 2011 => sold it => Google in 2016 to 2023 It was absolutely astounding to go to Google, and find out that all this work to ascend to an Ivy League-esque emp…

> A horrible design flaw that made ~50% of users take 20 seconds to get a query answered was buried, because a manager involved was the one who wrote the code.

Maybe not when it is as much as 20 seconds, but an old manager of mine would save fixing something like that for a “quick win” at some later time! He would even have artificial delays put in, enough to be noticeable and perhaps reported but not enough to be massively inconvenient, so we could take them out during the UAT process - it didn't change what the client finally got, but it seemed to work especially if they thought they'd forced us to spend time on performance issues (those talking to us at the client side could report this back up their chain as a win).

Re: I found a vulnerability. they found a lawyer

#90
post #2

I’ve worked in I.T. For nearly 3 decades, and I’m still astounded by the disconnect between security best practices, often with serious legal muscle behind them, and the reality of how companies operate. I came across a pretty serious security concern at my company this week. The ramifications are alarming. My education, training and experience tells me one thing: identify, notify, fix. Then when I bring it to leader…

> By even flagging the issue and the potential fallout, I’ve put my career at risk. Simple as. Not your company? not your problem? Notify, move on.

I read that post as him talking about their company, in the sense of the company they were working for. If that was the case, then an exploit of an unfixed security issue could very much affect them either just as part of the company if the fallout is enough to massively harm business, or specifically if they had not properly documented their concerns so “we didn't know” could be the excuse from above and they could be blamed for not adequately communicating the problem.

For an external company “not your company, not your problem” for security issues is not a good moral position IMO. “I can't risk the fallout in my direction that I'm pretty sure will result from this” is more understandable because of how often you see whistle-blowers getting black-listed, but I'd still have a major battle with the pernickety prick that is my conscience¹ and it would likely win out in the end.

[1] oh, the things I could do if it wasn't for conscience and empathy :)

Post reply on HN